Advertise Here
Advertise Here
Advertise Here
Advertise Here
Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 24

Thread: Hellboy OneUpdater

  1. #11
    New Member
    Join Date
    03-01-2019
    Posts
    5
    Uploads
    0
    Likes
    2

    Re: Hellboy OneUpdater

    Hello, does anyone have an invitation for this forum?
    Thanks

  2. Advertise Here
  3. #12
    Junior Member
    Join Date
    04-11-2009
    Posts
    20
    Uploads
    1
    Likes
    3

    Re: Hellboy OneUpdater

    Avoid HB59+OneUpdater. It has a remote-control backdoor in the binaries and will give the HB board owner full access to your vps/server.

  4. #13
    New Member
    Join Date
    20-02-2009
    Posts
    6
    Uploads
    0
    Likes
    4

    Re: Hellboy OneUpdater

    Quote Originally Posted by m0scito View Post
    Avoid HB59+OneUpdater. It has a remote-control backdoor in the binaries and will give the HB board owner full access to your vps/server.
    thats is a member who is banned, and he cry now very hard


    who need a invitation code need write pm to me.

  5. #14
    Junior Member
    Join Date
    04-11-2009
    Posts
    20
    Uploads
    1
    Likes
    3

    Re: Hellboy OneUpdater

    No, I´m not a member, but it´s already well known that hb59 is a version with trojan built in and give remote access to these guys from hb59 forum. That version also collects all cache data from your local card and sends it to a huge payserver which is running by these guys. that´s why you need a local card to join that forum.

  6. #15
    Super Moderator turbopower's Avatar
    Join Date
    02-07-2011
    Location
    Somewhere between the Streams
    Posts
    4,016
    Uploads
    129
    Likes
    303

    Re: Hellboy OneUpdater

    Prove it with virusscan, and some network dumps which is stating for connection to this server.
    You have two days, to do it, otherwise all of your lies will be deleted and you will get an infraction.

  7. #16
    Junior Member
    Join Date
    04-11-2009
    Posts
    20
    Uploads
    1
    Likes
    3

    Re: Hellboy OneUpdater

    Irregular UPX compressed binary file, regular hex editor. No special magic required to check the content. hb59.jpg
    Attached Images Attached Images

  8. #17
    Super Moderator turbopower's Avatar
    Join Date
    02-07-2011
    Location
    Somewhere between the Streams
    Posts
    4,016
    Uploads
    129
    Likes
    303

    Re: Hellboy OneUpdater

    There is no special magic but you need to know what the code is doing.
    ONEupdater is available only to members of specific forum, so it is normal to have API call to check about your membership there.
    And to finish with this pointless discussion here is virus scan of hb59 and oneupdater
    https://www.virustotal.com/gui/file/...5c4b?nocache=1
    https://www.virustotal.com/gui/file/...bcd9/detection
    One of the virus provider detected ASP.Webshellce which incorrect since this vulnerability is for Microsoft software and this is Linux
    https://www.trendmicro.com/vinfo/us/....WEBSHELL.SMC/

    In other words nothing to be scared here, the rest is politics, because now payservers can't use and exchange HB anymore.
    To have access to it you must be located in Europe and have a local card from there, mainly a lot of people a pissed of this thing, for that reason spreading bad words, and false accusations.

  9. #18
    Junior Member
    Join Date
    04-11-2009
    Posts
    20
    Uploads
    1
    Likes
    3

    Re: Hellboy OneUpdater

    hb59unpacked.zip
    + included unpacked binary

    The reverse-connect shell is also included in the unpacked hb59 binary:
    https://www.virustotal.com/gui/file/...5fc9?nocache=1

  10. #19
    Super Moderator turbopower's Avatar
    Join Date
    02-07-2011
    Location
    Somewhere between the Streams
    Posts
    4,016
    Uploads
    129
    Likes
    303

    Re: Hellboy OneUpdater

    Sure and how can you use it?
    Here is multics source code if you know C you can build your own version https://github.com/multi-cs/multics

  11. #20
    Junior Member
    Join Date
    04-11-2009
    Posts
    20
    Uploads
    1
    Likes
    3

    Re: Hellboy OneUpdater

    Simply include a remote code (like from metasploit shellcode payload - https://docs.rapid7.com/metasploit/w...with-payloads/) in the http call and you have a remote shell running as root. btw. the hb59 demands to be started as root. It was also reported, the binaries and others files were deleted from users servers who were banned.

Page 2 of 3 FirstFirst 123 LastLast
Advertise Here

Similar Threads

  1. multics-r82-hellboy-V32
    By veros in forum MultiCS & CSP Exchange
    Replies: 1
    Last Post: 14-05-2021, 17:10:39
  2. Multics r82 Hellboy v42
    By ghost2020 in forum MultiCS
    Replies: 0
    Last Post: 28-06-2020, 20:09:37
  3. Replies: 0
    Last Post: 23-06-2020, 10:48:29
  4. multcs Hellboy V30
    By kekic in forum MultiCS Exchange: Lines
    Replies: 0
    Last Post: 30-05-2019, 23:59:56
  5. Update Looking for Sky DE Hellboy v27 + offering 1W, 16E, 19E, 28.2E, 39E
    By turbopower in forum MultiCS Exchange: Lines
    Replies: 4
    Last Post: 30-04-2019, 18:11:33

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •