Flag: Tornado! Hurricane!

 Forums >>  Target Specific - General  >>  Password Retrieval Ollydbg

Topic created on: November 10, 2011 15:02 CST by pmolson .

Hi guys,

Here my issue...

I purchased a monitoring software installed the agent on the target PC and the viewer on my PC.

I'm going to attempt to explain the way (I think) it works:

Background Info:

=======================

I install the viewer on my PC and activate it with a purchased (obtained) serial

I then generate an "agent installation" file and install it on the target PC

Once you install the agent on the target remote or LAN PC

You query your viewer (on my PC) for any PCs on LAN or WAN

It finds the target PC, click on it, and you're prompted for a password & port # to connect for that remote PC

You then have to go to the vendor's "password page" to retrieve the password and port #, which is needed to cnct to the target PC

You enter that info & Voila!

Everything worked fine until a few weeks a go when I realized that the vendors website is gone! they're out of biz...(I guess)

Luckily target PCs on which the agent is already installed still work fine, but I can no longer add new target PCs...Ok I stand corrected, "I CAN" but I cannot retrieve that specific agent password and port # from the vendor's "password page". Also if any of the already monitored PCs crash, I can re-install an new agent, but I would run to the same password and port retrieving problem!!!

=======================

I think the specific agent password is somewhere (installed & hidden) on target PC's hard drive. So I'm thinking of a two-prong strategy: short term & long term..

Short Term:

I'd like to be able to retrieve the pass and port #, since I have access to target PCs, as well as the actual agent installation file, since I generate it using the viewer, then install it on the target PC.

Long Term:

Ideally, it would be nice if we can change the actual code on the agent installation file so that it passes a fix password and port number to the PC it is installed on.

I've done some reading and I've downloaded ollydbg and tutorials, but I have no idea where to start?, what to look? for and how?

Any help is greatly appreciated!

Thank you in advance!

-Paul

No posts found under this topic.
Note: Registration is required to post to the forums.

There are 31,310 total registered users.


Recently Created Topics
[help] Unpacking VMP...
Mar/12
Reverse Engineering ...
Jul/06
hi!
Jul/01
let 'IDAPython' impo...
Sep/24
set 'IDAPython' as t...
Sep/24
GuessType return une...
Sep/20
About retrieving the...
Sep/07
How to find specific...
Aug/15
How to get data depe...
Jul/07
Identify RVA data in...
May/06


Recent Forum Posts
Finding the procedur...
rolEYder
Question about debbu...
rolEYder
Identify RVA data in...
sohlow
let 'IDAPython' impo...
sohlow
How to find specific...
hackgreti
Problem with ollydbg
sh3dow
How can I write olly...
sh3dow
New LoadMAP plugin v...
mefisto...
Intel pin in loaded ...
djnemo
OOP_RE tool available?
Bl4ckm4n


Recent Blog Entries
halsten
Mar/14
Breaking IonCUBE VM

oleavr
Oct/24
Anatomy of a code tracer

hasherezade
Sep/24
IAT Patcher - new tool for ...

oleavr
Aug/27
CryptoShark: code tracer ba...

oleavr
Jun/25
Build a debugger in 5 minutes

More ...


Recent Blog Comments
nieo on:
Mar/22
IAT Patcher - new tool for ...

djnemo on:
Nov/17
Kernel debugger vs user mod...

acel on:
Nov/14
Kernel debugger vs user mod...

pedram on:
Dec/21
frida.github.io: scriptable...

capadleman on:
Jun/19
Using NtCreateThreadEx for ...

More ...


Imagery
SoySauce Blueprint
Jun 6, 2008

[+] expand

View Gallery (11) / Submit