Ir a contenido


Foto
- - - - -

Frozen-layer C2 Brute Force


  • Tema Cerrado Este tema está cerrado
61 replies to this topic

#1 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 04 February 2004 - 08:33 PM

This topic is open for disscusion on the C2 Brute force attack ( http://www.marumo.ne.../bf/status.html ), Every offtopic post will be deleted.


I've set this topic to make easier the communication between Team2ch board and Frozen-Layer. You do NOT need to register to reply to this topic.


We have already modified the UNIX version of c2bf to run it on the 390/S IBM Mainframe. Right now we are doing a dump of the last 2 millions of packets ( FFFFFF and bellow) and this saturday we will beging the testing.


Could someone make a good translation to english of yesterday news at http://www.marumo.ne.jp/db2004_2.htm ? It's hard to understand the babelfish translations and we don't know what is MOGI talking about when he mentions the Frozen-Layer mainframe.

I mailed MOGI yesterday offering our help with the mainframe but he has not replied, could someone ask him if he has received the mail?


Thanks a lot.

#2 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 04 February 2004 - 09:51 PM

buonas noches
I came from NewsDiscussionBoard@Team2ch.
http://news4.2ch.net...ews/1075462799/

Thank you for this topic.I can not read Espanol,sorry.
I think;
MARUMO probably read e-mail from frozen-layer.
He wrote the diary about frozen-layer's suggestion in feb.3 .

I am transrating "http://www.marumo.ne.../db2004_2.htm".
Wait few hours.

Sorry broken english.
Gracias.

#3 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 04 February 2004 - 09:55 PM

Don't worry about your english. If you want me to translate something writen in spanish over here or if you have any question just tell me.

I'm going to set up a mirror updated every 2 minutes to lessen the load of MARUMO's webserver because there's a lot of people over here that is constantly reloading the rank list.

#4 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 04 February 2004 - 11:05 PM

feb.2 mon.
Last Sunday and saturday,I could not update this diary.I was busy!!!
I searched the PC game "Fate/stay night".
Are you angry?
***
I thought about changing of a registration name and a password.
It was problem disclosure.
Some teams are already opening them.....Anyone able to change opend registration name.
I was considered.

I tested changing of a registration name and a password.I stoped that.
I will open to public changing ID.
***
If you hope to make Teams,As you like it.
I must make the server more faster.
But I have no ideas.I am sad.(ToT)
***
My server machine has celeon 1.7GHz cpu and 128Mbyte memories,
it is not cheep,though it is not gorgeous.
Backborn(internet speed) and electric energy line are perfect.
My server exist "sakura.ad.jp" of Osaka office.
Real server machine is far from my home.
Difficult to replace this.

I do not think this situation is good.
First,I am searching botlle neck,and tuning settings a little.

######
Notice
registration name:user name(ex.Frozen-Layer)
password:password
ID:Signed in "HKEY_CURRENT_USER\Software\marumo\c2bf.exe"
"sakura.ad.jp" is a company of web server hosting service.
"Fate/stay night" is no business on this c2bf project.

feb.3 and 4 diary transration,waaaaaaaaaait!
Sorry for broken english.
Gracias.

#5 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 04 February 2004 - 11:11 PM

thanks a lot, we are preparing an english and spanish version with tutorials, stats, news, and a mirror of the japanese site. We expect to have it ready in 30 hours.

If someone can help translating all the news related to C2 at narumo's site from japanese to english it would be greatly appreciated. We will then translate them to spanish, fix the broken english and put them at the site.

#6 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 04 February 2004 - 11:27 PM

Emergency,"www.marumone.jp" is bery busy.
Clients are so much.
Please exit your "c2bf.exe".

http://www.marumo.ne.jp/mrtg/cpu.html
Look this.

To Deadsunrise,
Thank you your kindness.
But please stop opening to public mirror/transration site.
Because MARUMO's server is very poor.
Right now,half dieing.

MARUMO said,
"I will replace the faster server for 10days."
Wait 10 days.
Before mirroring,Get permission from MARUMO.

Grasias.
###
Needlees to reply hurry.

Este tema ha sido editado por takasagi_k: 05 February 2004 - 12:19 AM


#7 AyamiWired

AyamiWired

    Leecher

  • Hentais
  • 24 Mensajes:

Escrito 05 February 2004 - 12:41 AM

Sorry, but I Think that has been a mistake, dead is offering to have a mirror in spanish/english, but I think he is offering to host it in his own server, not in marumeo's one ;)

If i have misunderstood please correct me.
I'm trying to find a way to go back home...

Imagen enviada

#8 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 05 February 2004 - 12:47 AM

The idea of the public mirror is to lessen the load of Marumo's server. With the mirror the people will make all the checkings of the ranks at our server and not at marumo's one. I'll ask for permission later. Basically the mirror will download a copy of the top 20 list every 5 minutes if it has been updated. All the spanish people will check the mirror and not marumo's server and that will make a HUGE difference on marumo's load.

We can also offer a Pentium 4, 2Ghz & 1Gb RAM that is only being used as an FTP to act as a server until he finds a replacement. The server is very stable with a very good uptime and its located at a 10Mbit connection.



About this:

191:Socket774 : 04/02/05 07:30 ID:BrOsBUV3
    11:30 PM is at the Spanish time.
    Clients probably will increase successively from now on.


It's more probably that the client number will decrease. Here in spain a lot of people shut down their computers at night.

#9 garmulan

garmulan

    Leecher

  • Hentais
  • 4 Mensajes:

Escrito 05 February 2004 - 12:58 AM

Hello,

actually i have one pc working with c2bf (ver. 2.1.1) and i can add 2 pc's more, but
i read that the server is very busy now.

Can i add these pc's? way 10 days?


P.D. : Deadsunrise, if you want i like help you with this

#10 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 05 February 2004 - 01:09 AM

Hello,

actually i have one pc working with c2bf (ver. 2.1.1) and i can add 2 pc's more, but
i read that the server is very busy now.

Can i add these pc's? way 10 days?


P.D. : Deadsunrise, if you want i like help you with this

thanks a lot garmulan, we'll talk tomorrow, you can mail me at deadsunrise@deadsunrise.com if you want to.


Right now is better NOT to open any new client and close the ones you are running. I've already told everybody at Frozen-Layer to do it but I guess that a lot of people is sleeping right now (1:08 AM in spain)

#11 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 05 February 2004 - 02:29 AM

feb.3 tue. (part1 of 2)
I started to tuning settings seriously.
I make changed to "http://www.marumo.ne...bf/current.png" refresh time as 60 sec.

Server automatically is deleting slleping clients' ID.
I set delete ID terms,
old settings (slleping clients:send no analysys reports for a week)
new settings (slleping clients:send no analysys reports for 24 hours)

Quiet effect.....Oh my goodness.

I checked up making my c2bf client to server.
I am using internet line in private,
This internet provider makes ciesta one hour every month.
Idea;Runnig the server at home was threw away.
***
Frozen-Layer makes offer using main flame computer,
How to join that start analysys from 0xffffff block to decrement number blocks.
If "answer" is finded,give me e-mail.
My idea is that's all.

For analysys,Need to reconstruction c2bf.exe.
Good luck.

####
Half of feb.3 diary was transrated.
My small brain wants green tea and onigiri(rice ball).
Next transration is next morning at esapnol time.
buonas noches
####

I understand that mirror site makes many merits.
MARUMO minds "c2bf clients" access better than www access in diary.

"www.marumo.ne.jp" is not mine.
I don't know how much percent is www access on "www.marumo.ne.jp".

If mirror site is made,I think a lot of c2bf clients access "www.marumo.ne.jp".

Please contact to MARUMO directly,about running miiror site.

191:Socket774 : 04/02/05 07:30 ID:BrOsBUV3
    11:30 PM is at the Spanish time.
  Clients probably will increase successively from now on.


Japanese geeks sat up midnight.
"191:Socket774" wrote in Japanese habit.
He is nervous about server down.

I want to talk many topics,I must go searching jobs.
GraCias!

#12 TKW

TKW

    Leecher

  • Hentais
  • 1 Mensajes:

Escrito 05 February 2004 - 02:54 AM

5 Feb - I temporarily removed all client download link. This is for making server load low. A new server machine is now under order and shift schedule is 14 Feb or 15 Feb.

http://www.marumo.ne.../bf/status.html

#13 marumo

marumo

    Leecher

  • Hentais
  • 6 Mensajes:

Escrito 05 February 2004 - 01:56 PM

I'm kazhiro@marumo.ne.jp, the webmaster of www.marumo.ne.jp

I read your mail and all posted message in this thread.

We have already modified the UNIX version of c2bf to run it on the 390/S IBM Mainframe. Right now we are doing a dump of the last 2 millions of packets ( FFFFFF and bellow) and this saturday we will beging the testing.


Thank you very match. This action gives me many help. Please use the following data. and prepare pre-calcurated test data for testing c2_enc() function.

plaintext=0x01c8be00131126d3
cyphertext=0x02ee91c0f2fe44d1
#other code=xxx entries in the c2bf.dat are dummy cyphertext for the client check.

As takasagi_k wrote, wait for a few days mirror & tutorial site creation. Today, I recieved mail from network center which notifies that the server setup was completed. I install required softwares and setup DNS, SMTP, etc at the next weakend.

Este tema ha sido editado por marumo: 05 February 2004 - 02:00 PM


#14 Bad_CRC

Bad_CRC

    Lost in space

  • Admin
  • 13042 Mensajes:

Escrito 05 February 2004 - 02:14 PM

Hi, that plaintext & code is from ffffff rigth?

well, so we can make the blocks like this?

plaintext=01c8be00131126d3
ka=ffffff {
  status=0
  kb=00000000
  code=02ee91c0f2fe44d1 {
    key=0000000000000000
    find=0
  }
}
...

and don't care about others?

thanks in advance.
"NO SE LO QUE SIGNIFICA PERO SEGURO QUE PEGA CON ESTA SITUACION. Y SINO PUES OS LO IMAGINAS."

#15 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 05 February 2004 - 04:42 PM

buonas tardes
I am late for transtarion. :vaca:

feb.3 tue (part2 of 2)
I noticed the clients logged "body[0] = ng" and "error - failed on report()". stopped analysys.
If you tune upped cpu en-overclock,stop that.
If you did'nt,report me your haedware spec and network environment.(see notices#1)
***
Please ignore your c2bf client's log "body[0] = ng" on and after feb 3 14:00PM(JST).
Server soothed clients retry every 15 secconds quiet.Clients have no ploblems!

This braking down caused by thinkless settings the clients software interval of retry,
and increasing server's jobs from c2bf clients' request.

I MUST get more faster server.
If I order that right now,New machine comes 10 days later.
It is too late.
****
I will release new clients software fixed interval of retry longer(olds:15 secconds).
Client software for UNIX have bugs about PROXY setting.
(bugs:UNIX clients software needs ".c2bffrc" file for using PROXY setting)
I will fix this UNIX client software bugs.

Tomorrow,I explain ditales about ordering new server.
Please save runnig c2bf clients every one person.

###
notice
#1 Errored client was declared.
His registration name was AMD MAHORO.

There are 3 Team2ch.
DIY_PCBoard@Team2ch
DownloadBoard@Team2ch
NewsDiscussionBoard@Team2ch.
####

Sorry for broken English.
Gracias.

Este tema ha sido editado por takasagi_k: 06 February 2004 - 06:03 PM


#16 marumo

marumo

    Leecher

  • Hentais
  • 6 Mensajes:

Escrito 05 February 2004 - 05:27 PM

well, so we can make the blocks like this?


right. but more simple, in the pseudo code.

// code, key, plaintext are 64bit unsigned integer
plaintext = 0x01c8be00131126d3;
for(ka=0xffffff;ka>=0xe00000;ka--){
  for(i=0;i<65536;i++){
    for(j=0;j<65536;j++){
      key = ka << 32;
      key |= i<<16;
      key |= j;
      code = c2_enc(plaintext, key);
      if(code == 0x02ee91c0f2fe44d1){ // cyphertext
         // jackpot!!
         save_current_key(key);
      }
    }
  }
}

for more detail, other "code=XXX" entries are generated by server in following code.

ka = 0xXXXXXX; // client recieve block;
kb = (rand() << 16) | rand();
code[0:6] = c2_enc(plaintext, (ka<<32)|kb);

clients program report all finding keys, and server check "reported key" and "used key". It's for rejecting invalid client.

#17 Bad_CRC

Bad_CRC

    Lost in space

  • Admin
  • 13042 Mensajes:

Escrito 05 February 2004 - 05:35 PM

ok, I will try to make a standalone program with that.

After processed, just send to you the file with found keys rigth?
"NO SE LO QUE SIGNIFICA PERO SEGURO QUE PEGA CON ESTA SITUACION. Y SINO PUES OS LO IMAGINAS."

#18 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 05 February 2004 - 07:52 PM

I watched Area88 on TV.
This sentence is tansration from http://www.marumo.ne.jp/db2004_2.htm

feb 4 wed AVHDD crack [39]

I released new client software.
By updating,My server's jobs will decrese.
Cooprate please!

The new client was added MENU "copy ID to clip board" (Windows client only).
That was changed clients settings about retry interval on access error occured.
Details are;
Server alive:Clients works same behavior with older version.
Server dead:Clients wait 15 seconds,and challenge to retry access.
If retry access failed,wait 30 seconds,and retry access.
Next failed,wait 60 seconds,
Next,wait 120 seconds......
Wait 240 seconds.......
Maximum waiting time is 1 hour.

(Server dead:Old clients wait 15 seconds,and challenge to retry access.
If access failed,wait 15 seconds,and retrying access,and repeat that.)

This update makes possibility to half dieing server gets up.
I know that to get faster machine is right answer,sure.
****
I misunderstood my server spec.
That was celeron 400MHz.
I decided to buy new server machine.

By reworking server programs,"Load Acerage" was down.
I had to do that yesterday.

See this,
Reference:access counts by c2bf clients in feb. 4
06:00-06:59 8192
07:00-07:59 8177
09:00-09:59 7991
10:00-10:59 8039

Compare acess count with "http://www.marumo.ne...mrtg/cpu.html".
I guess you are noticed "Load Acerage" downed at 09:00-1059.
I solved this bottle neck.

Until I get new server machine,I can sleep well.:-)

By optimizing of server programs,Server's ability is up to 10-20%.
Although persent working clients(2100) is approach to dead line.(See Notice#1)
Replacement server machine is feb 14 or 15.
Take a branch with your client computers.

###
feb.4 wed diary is all.
Notice#1,2100clients means in feb 4 at night present(JST).
Sorry for broken English.
gracias mucho

Este tema ha sido editado por takasagi_k: 05 February 2004 - 08:13 PM


#19 Deadsunrise

Deadsunrise

    Speunaigh

  • Admin
  • 27632 Mensajes:

Escrito 05 February 2004 - 08:10 PM

I watched Area88 on TV.
This sentence is tansration from http://www.marumo.ne.jp/db2004_2.htm

feb 4 wed AVHDD crack [39]

I released new client software.
By updating,My server's jobs will decrese.
Cooprate please!

The new client was added MENU "copy ID to clip board" (Windows client only).
That was changed clients settings about retry interval on access error occured.
Details are;
Server alive:Clients works same behavior with older version.
Server dead:Clients wait 15 seconds,and challenge to retry access.
If retry access failed,wait 30 seconds,and retry access.
Next failed,wait 60 seconds,
Next,wait 120 seconds......
Wait 240 seconds.......
Maximum waiting time is 1 hour.

(Server dead:Old clients wait 15 seconds,and challenge to retry access.
If access failed,wait 15 seconds,and retrying access,and repeat that.)

This update makes possibility to half dieing server gets up.
I know that to get faster machine is right answer,sure.
****
I misunderstood my server spec.
That was celeron 400MHz.
I decided to buy new server machine.

By reworking server programs,"Load Acerage" was down.
I had to do that yesterday.

See this,
Reference:access counts by c2bf clients in feb. 4
06:00-06:59 8192
07:00-07:59 8177
09:00-09:59 7991
10:00-10:59 8039

Compare acess count with "http://www.marumo.ne.jp/mrtg/cpu.html".
I guess you are noticed "Load Acerage" downed at 09:00-1059.
I solved this bottle neck.

Until I get new server machine,I can sleep well.:-)

By optimizing of server programs,Server's limit is up 10-20%.
Although persent working clients(2100) is approach to dead line.
Replacement server machine is feb 14 or 15.
Take a branch with your client computers.

###
feb.4 wed diary is all.
Sorry for broken English.
gracias mucho

Thanks a lot, We'll try to finish tonight the spanish/english site we are preparing.


On sunday we'll post pictures of the Mainframe running c2bf if we don't have problems compiling it.

#20 takasagi_k

takasagi_k

    Leecher

  • Hentais
  • 18 Mensajes:

Escrito 05 February 2004 - 09:17 PM

This sentence is transration from http://www.marumo.ne.jp/db2004_2.htm

feb 5 thu.AVHDD crack [40]
I temporaly deleted download link of c2bf clients software,
To stop increasing c2bf clients.
You can download the software after replacing new Marumo server.

For people intrested in server jobs,
I opend to public surce code of server software(3rd.cgi source code).
http://www.marumo.ne...rver0204.tar.gz
This is feb.4 release version.
****
I got e-mail from "sakura.ad.jp" about IP adress information of new server.
They did setup for one business day.
I guess they spend 5 business days on setup,I am very happy!

Next weekend,I will do setup server software.
New server machine has Pentium4 2.8GHz cpu.
I already got e-mail from frozen-layer's webmaster.
I will write reply e-mail.

####
feb 5 thu. diary is all.
Notice
"sakura.ad.jp" is a company of web hosting service.
####
To admin and all members,take care!
gacias mucho

Este tema ha sido editado por takasagi_k: 05 February 2004 - 09:27 PM


#21 TrAnS

TrAnS

    Leecher

  • Hentais
  • 30 Mensajes:

Escrito 06 February 2004 - 12:42 AM

Hi minna-sama...

I have question about the personal info page...
I mean the one you get when you login into marumo's web.

There are 4 textboxes:
First one is the Memo.
Bellow there are the ID and two more I don't know the meaning (I only understand User and Password)

I supose is some kind of individual registration inside the group... I dunno.

Question: What's the meaning of that textboxes and which is their purpose?

Lots of thanks and keep that good work, I will do my best with c2bf.

Cya.

No cuesta nada escribir los mensajes con "comas", "puntos" y demas...
Los acentos si quieres te los comes, tampoco es un examen...
Pero al menos que se te entienda, porque para eso escribes, no?





1 usuarios están leyendo este tema

0 miembros, 1 invitados, 0 usuarios anónimos