Jump to content
Tuts 4 You

All Activity

This stream auto-updates

  1. Today
  2. Yesterday
  3. Last week
  4. Hi guys, what do you mean with life timer?The conditions of my HDDs are good so far. Question: I see a lot of infos about my HDDs in the hdsentinel (tiral) tool about features etc.Are there no info about the Spin down time of the HDD?Just asking because there are a lot of infos but found nothing about that Spin D/U there. Yes, maybe the enclosure I'am using now (controller) does manage it.Not sure about that but looks so.I think the controller does just accept the original HDD Spin Down time and goes into sleep mode after 10 minutes (in my case WD Blue) OR maybe the controller itself does just use the Spin down time after 10 minutes by itself etc.I don't know.If I remember right then my older enclosure case/device did not do any Spin Down with my WD Blue HDD and the LED light was always ON.Hhmm. So I just care about the life time of my HDDs and I heard much about Spin UP errors / failures after Spin Down and that its better to keep the HDDs running. I found a tool called "KeepAliveHD" where I can set HDDs to read / write on them after a specific time. https://github.com/stsrki/keepalivehd I did tried it out already just using the READ mode (not write) and it seems to WORK. Just entered to read all 8 minutes and the blue LED light on my enclosure keeps ON without to ON/OFF all 4 seconds after a Spin Down.I can use this little tool now to keep the HDD running. greetz
  5. Hi, i'm starting unpacking, can someone help me understand how to decipher it?
  6. Ralf

    Flare-On 8

    I have no idea for #4. I find a suspicious file and it was loaded. but I cannot understand what to do. please help me.
  7. whoknows

    whoknows News!

    Rich people problems vm.tiktok.com/ZMRpofse3/ Asynchronous Programming in C# github.com/davidfowl/AspNetCoreDiagnosticScenarios/blob/master/AsyncGuidance.md Mozilla Says Chrome’s Latest Feature Enables Surveillance www.howtogeek.com/756338/mozilla-says-chromes-latest-feature-enables-surveillance/ :dumb_with_linux: Google keeps records of everything you buy, even if you delete the email receipt :dumb_with_linux: mastodon.social/@gerowen/106978308085702358 Resume maker with no sign-up or subscription luckyresumemaker.com
  8. @LCF-ATif you searched all on OS settings then probably is the CASE (enclosure) firmware doing that... to be honest the same happening here., but is not bother me..
  9. predat0r

    Flare-On 8

    Can anyone help me with the nudge on challenge 5, to get it started? I believe i have to look for a binary that caused the encryption, where should i at least start looking? can't find anything out of the ordinary in snapshots dir
  10. Hi, If I right understand your question first check your HDD life timer with this tool https://www.hdsentinel.com/download.php
  11. r0ger

    GfX by r0ger

    new patch templates , no patch engines included. sorry if there are too much of these but i haven't been that active on tuts4you for a while because now i've started my new year at the college and you know... projects,essays and stuff. v2m by Dq&Biff, .IT by AdDe, v2m by Teo (third one), xm by graff. CrackTemp23.zip CrackTemp24.zip CrackTemp25.zip CrackTemp26.zip
  12. Hi guys, I have a new small question today about using extern HDDs drives in a Enclosure connected by USB port.I have a new Enclosure and put a WD Blue disk into and did setup all so far to make it ready to use.All seems to work fine with the disk (read/write good high values).The only thing I have seen is that the HDD seems to spin down after 10 minutes and the blue LED light on my Enclosure does shine for 4 seconds and turns off for 4 seocnds (loop) = Disk was spin down.Now I wanted to try to turn that spin down OFF but I don't find any setting for that in Windows 10 which could do that.In the Power management I have already set the HDD time to 0 (= do not turn off) and I also did now disable the USB Power thing (not sure what that really does etc). Somehow the disk just keeps spinning down after 10 minutes also with that settings above.On the Western Digital site I found a info that all external WDs have that feature... https://support-en.wd.com/app/answers/detail/a_id/16047 ....but I'am using a internal HDD in Enclosure.Anyway, so somehow I would like to turn that spin down OFF to prevent fails/errors etc.Is there a way how I can do that or any tools I can disable it etc?Otherwise I found a info that you just need to write anything onto that disk in that time (one txt file all 10 minutes or something). So what do you think?Should I keep the spin down like it is (all 10 minutes in no use) or turn it OFF (like I have with my internal Disk)?Whats better?Lets say you would prefer turning off the spin down (normaly I think that too) and I can not find any tool to do that....what should I do then?Is it also possible to access the HDD without to write on it (just in case to bypass spin down time)?I think I just need to code a small app with a timer to use CreateFile / read some etc and thats it or?Maybe you can tell me something how I should do that etc.Thank you. greetz
  13. Yeah, today i've discovered it when most of tPORt releases, even with v2m's in it (with libv2 1.0 mostly), don't work on Vista and higher, so if u wanna test these releases/having some experience with them but ur just lazy too open them up in XP (or simply you don't have it), here's how i did it : I firstly opened one of tPORt's releases with v2m in it i have in my collection with IDA pro , then i've analyzed the whole EXE file . The v2m initialization must start with DirectSoundCreate function most of it , from which it was called from this : sub_406E82 proc near ; CODE XREF: sub_403DEA+38^p PS_____:00406E82 PS_____:00406E82 var_9C = dword ptr -9Ch PS_____:00406E82 arg_0 = dword ptr 4 PS_____:00406E82 arg_4 = dword ptr 8 PS_____:00406E82 arg_8 = dword ptr 0Ch PS_____:00406E82 PS_____:00406E82 pusha PS_____:00406E83 mov ebx, offset dword_6722B4 PS_____:00406E88 mov ecx, 20082h PS_____:00406E8D mov edi, ebx PS_____:00406E8F xor eax, eax PS_____:00406E91 rep stosb PS_____:00406E93 mov esi, [esp+20h+arg_0] PS_____:00406E97 mov [ebx+0Ch], esi PS_____:00406E9A mov esi, [esp+20h+arg_4] PS_____:00406E9E mov [ebx+10h], esi PS_____:00406EA1 lea esi, [ebx+8] PS_____:00406EA4 mov [esi], eax PS_____:00406EA6 push eax ; pUnkOuter PS_____:00406EA7 push esi ; ppDS PS_____:00406EA8 push eax ; pcGuidDevice PS_____:00406EA9 call DirectSoundCreate PS_____:00406EAE mov esi, [esi] PS_____:00406EB0 or esi, esi PS_____:00406EB2 jz short loc_406ED5 PS_____:00406EB4 mov al, 2 PS_____:00406EB6 push eax PS_____:00406EB7 push [esp+24h+arg_8] PS_____:00406EBB push esi PS_____:00406EBC mov edi, [esi] PS_____:00406EBE call dword ptr [edi+18h] PS_____:00406EC1 or eax, eax PS_____:00406EC3 jnz short loc_406ED5 PS_____:00406EC5 push eax PS_____:00406EC6 lea ebp, [ebx+4] PS_____:00406EC9 push ebp PS_____:00406ECA push offset dword_407194 PS_____:00406ECF push esi PS_____:00406ED0 call dword ptr [edi+0Ch] PS_____:00406ED3 or eax, eax PS_____:00406ED5 PS_____:00406ED5 loc_406ED5: ; CODE XREF: sub_406E82+30^j PS_____:00406ED5 ; sub_406E82+41^j PS_____:00406ED5 jnz short loc_406EE6 PS_____:00406ED7 push eax PS_____:00406ED8 lea edx, [ebx] PS_____:00406EDA push edx PS_____:00406EDB push offset dword_407180 PS_____:00406EE0 push esi PS_____:00406EE1 call dword ptr [edi+0Ch] PS_____:00406EE4 or eax, eax PS_____:00406EE6 PS_____:00406EE6 loc_406EE6: ; CODE XREF: sub_406E82:loc_406ED5^j PS_____:00406EE6 ; sub_406E82+A6ˇj PS_____:00406EE6 jnz loc_406FB4 PS_____:00406EEC lea edi, [ebx+70h] PS_____:00406EEF push edi PS_____:00406EF0 lea esi, word_40716E PS_____:00406EF6 lea ecx, [eax+12h] PS_____:00406EF9 rep movsb PS_____:00406EFB mov esi, [ebp+0] PS_____:00406EFE push esi PS_____:00406EFF mov edi, [esi] PS_____:00406F01 call dword ptr [edi+38h] PS_____:00406F04 xor esi, esi PS_____:00406F06 push 2 PS_____:00406F0B lea edx, [ebx+2Ch] PS_____:00406F0E push edx PS_____:00406F0F lea edx, [ebx+28h] PS_____:00406F12 push edx PS_____:00406F13 lea edx, [ebx+24h] PS_____:00406F16 push edx PS_____:00406F17 lea edx, [ebx+20h] PS_____:00406F1A push edx PS_____:00406F1B push esi PS_____:00406F1C push esi PS_____:00406F1D mov ebp, [ebx] PS_____:00406F1F mov esi, [ebp+0] PS_____:00406F22 push ebp PS_____:00406F23 call dword ptr [esi+2Ch] PS_____:00406F26 or eax, eax PS_____:00406F28 jnz short loc_406EE6 PS_____:00406F2A mov ecx, [ebx+24h] PS_____:00406F2D mov edi, [ebx+20h] PS_____:00406F30 rep stosb PS_____:00406F32 mov ecx, [ebx+2Ch] PS_____:00406F35 mov edi, [ebx+28h] PS_____:00406F38 rep stosb PS_____:00406F3A push dword ptr [ebx+2Ch] PS_____:00406F3D push dword ptr [ebx+28h] PS_____:00406F40 push dword ptr [ebx+24h] PS_____:00406F43 push dword ptr [ebx+20h] PS_____:00406F46 push ebp PS_____:00406F47 call dword ptr [esi+4Ch] PS_____:00406F4A or eax, eax PS_____:00406F4C jnz short loc_406FB4 PS_____:00406F4E mov dword ptr [ebx+68h], 0FFFF0000h PS_____:00406F55 mov dword ptr [ebx+6Ch], 0FFFF0000h PS_____:00406F5C xor eax, eax PS_____:00406F5E push eax ; lpName PS_____:00406F5F push eax ; bInitialState PS_____:00406F60 push eax ; bManualReset PS_____:00406F61 push eax ; lpEventAttributes PS_____:00406F62 call CreateEventA PS_____:00406F67 mov [ebx+40h], eax PS_____:00406F6A lea eax, [ebx+48h] PS_____:00406F6D push eax ; lpCriticalSection PS_____:00406F6E call InitializeCriticalSection PS_____:00406F73 xor eax, eax PS_____:00406F75 inc al PS_____:00406F77 push eax PS_____:00406F78 push 1 PS_____:00406F7D dec al PS_____:00406F7F push eax PS_____:00406F80 push eax PS_____:00406F81 push ebp ; nPriority PS_____:00406F82 call dword ptr [esi+30h] PS_____:00406F85 or eax, eax PS_____:00406F87 jnz short loc_406FB4 PS_____:00406F89 fld flt_406E50 PS_____:00406F8F fstp dword ptr [ebx+14h] PS_____:00406F92 lea edx, [ebx+3Ch] PS_____:00406F95 push edx ; lpThreadId PS_____:00406F96 push eax ; dwCreationFlags PS_____:00406F97 push eax ; lpParameter PS_____:00406F98 push offset sub_407009 ; lpStartAddress PS_____:00406F9D push eax ; dwStackSize PS_____:00406F9E push eax ; lpThreadAttributes PS_____:00406F9F call CreateThread PS_____:00406FA4 mov [ebx+1Ch], eax PS_____:00406FA7 inc [esp+9Ch+var_9C] PS_____:00406FAA push eax ; hThread PS_____:00406FAB call SetThreadPriority PS_____:00406FB0 popa PS_____:00406FB1 stc PS_____:00406FB2 jmp short loc_406FBB PS_____:00406FB4 ; --------------------------------------------------------------------------- PS_____:00406FB4 PS_____:00406FB4 loc_406FB4: ; CODE XREF: sub_406E82:loc_406EE6^j PS_____:00406FB4 ; sub_406E82+CA^j ... PS_____:00406FB4 call sub_406FC0 PS_____:00406FB9 popa PS_____:00406FBA clc PS_____:00406FBB PS_____:00406FBB loc_406FBB: ; CODE XREF: sub_406E82+130^j PS_____:00406FBB sbb eax, eax PS_____:00406FBD retn 0Ch PS_____:00406FBD sub_406E82 endp .... then from this subroutine which was called in DialogFunc : sub_403DEA proc near PS_____:00403DEA PS_____:00403DEA var_4 = dword ptr -4 PS_____:00403DEA arg_0 = dword ptr 4 PS_____:00403DEA arg_4 = dword ptr 8 PS_____:00403DEA PS_____:00403DEA mov ecx, [esp+arg_0] PS_____:00403DEE mov edx, offset dword_40B160 PS_____:00403DF3 call sub_403558 PS_____:00403DF8 call sub_403666 PS_____:00403DFD push [esp+arg_4] PS_____:00403E01 xor eax, eax PS_____:00403E03 push eax PS_____:00403E04 push offset sub_403D0F PS_____:00403E09 mov dword_40B154, eax PS_____:00403E0E mov dword_40B150, eax PS_____:00403E13 mov dword_40A718, eax PS_____:00403E18 mov dword_40A71C, 1 PS_____:00403E22 call sub_406E82 PS_____:00403E27 fld1 PS_____:00403E29 push ecx PS_____:00403E2A fstp [esp+4+var_4] ; float PS_____:00403E2D call sub_407147 PS_____:00403E32 retn 8 PS_____:00403E32 sub_403DEA endp and this was the block of codes where the v2m playback was initiated : PS_____:00401AD4 call sub_403DEA PS_____:00401AD9 call sub_403E35 PS_____:00401ADE mov byte_409520, 1 So what i did was patching them with NOP's only so this would skip the whole V2M playback subroutine (yep, this will not play v2m anymore.) : Final result (for example i chose AutoRun_Pro_6.0.1.40.Keygen.ev1l^4.tPORt ) : Without patching (and with v2m playback called, and about to play in the keygen) may result in this error (which is manifested from Vista and higher - the keygen will run normally with v2m playback only on Windows XP) ...: other results : ObjectRescuePro_v3.0_Crack_by_M!H@N Drive_Discovery_v2.1.Keygen.LaZzy.tPORt MetaProducts Flash and Media Capture v1.2.43 SR1 by tPORt MOV_to_AVI_MPEG_WMV_Converter_v_1_8_4 X-NetStat_Pro_5.5.Keygen.tPORt Xilisoft_OGG_MP3_Converter_2.1.63.Keygen.tPORt But i know there was a patch solution for it i've found months ago in which can play the v2m's in windows 7 with libv2 1.0 , idk if it really is but if i see it and the patch solution getting to work even on 7 , maybe i'll post the solution. Anyway,this is how i fixed the releases using IDA only.
  14. Lamport

    Flare-On 8

    Thanks man, got unstuck and solved the challenge
  15. ECX

    Flare-On 8

    Hello guys, Can anyone confirm my thinking or give right direction with #CH-5. I decrypted a lot of stuff/hints and now i am stuck at SR**BE hint I am struggling with this hint, but i don't know if i am doing it correctly. I just put the string from the hint as a key and nothing decrypt to usable form. Should i just take the magic string from the hint and use it normally or i have to do some operations with it. Thank you for help.
  16. whoknows

    whoknows News!

    twitter.com/ForumCovid/status/1439893319048380419 Raspberry Pi gets $45M to meet demand for low-cost PCs and IoT techcrunch.com/2021/09/21/raspberry-pi-gets-45m-to-meet-demand-for-low-cost-pcs-and-iot/ Lithuanian government warns about secret censorship features in Xiaomi phones therecord.media/lithuanian-government-warns-about-secret-censorship-features-in-xiaomi-phones/ Distribution Of Global Wealth www.visualcapitalist.com/distribution-of-global-wealth-chart/ WHO global air quality guidelines 2021 apps.who.int/iris/handle/10665/345329 Reasons to Quit Social Media durmonski.com/life-advice/reasons-to-quit-social-media/ Why You Should Stop Reading News fs.blog/2013/12/stop-reading-news/ World War 3 To Be Fought Over Semiconductors? goldsilver.com/blog/world-war-3-to-be-fought-oversemiconductors-wealthion/ Waydroid – Run Android containers on Ubuntu waydro.id/ Authenticated Boot and Disk Encryption on Linux http://0pointer.net/blog/authenticated-boot-and-disk-encryption-on-linux.html EU proposes mandatory USB-C on all devices www.theverge.com/2021/9/23/22626723 FDA Vaccine Panel Comes Out Against Deadly Injections infowars.com/posts/bombshell-testimony-from-fda-vaccine-hearing-reveals-injections-killing-more-than-saving-driving-variants/
  17. pula3241

    Flare-On 8

    Could someone give me a hint on #7? I have no idea how to start reversing the challenge.
  18. whoknows

    Coronavirus (COVID-19)

    BlackRock and Vanguard - 16b Behind Vaccines (08MAR2021) - expansion.mx/mercados/2021/03/08/blackrock-y-vanguard-16-billones-de-dolares-detras-de-las-vacunas 20SEPT2021 - twitter.com/ForumCovid/status/1439893319048380419 Croatia - We Will Not Be Vaccinated Anymore greatgameindia.com/croatia-president-vaccine/ FDA Vaccine Panel Comes Out Against Deadly Injections infowars.com/posts/bombshell-testimony-from-fda-vaccine-hearing-reveals-injections-killing-more-than-saving-driving-variants/
  19. Oggy

    Flare-On 8

    could I DM somebody? I stuck on #7, I think I very very close flag :< Update: Nervermind, I got it
  20. Lamport

    Flare-On 8

    I'm kind of stuck on #5. I can't figure out the Reese hint. Can someone give me a hint or DM me. Thanks.
  21. confused_daily

    Flare-On 8

    Nvm, I'm dump
  22. Sp1d3rZ

    ASProtect 2.78

    easyone is unpacked and patched code: 1234 sssp_u1.zip
  1. Load more activity
×
×
  • Create New...