PDA

View Full Version : [ANDROID] BSODroid - BSOD any Vista machine on your network!


iammorris
10th September 2009, 05:09 PM
Hi all,

BSODroid is my first Android application. It is a proof of concept implementation of a flaw in Windows Vista, which is so far unpatched (although Microsoft are due to start distributing the patch any moment now), that allows a user to send a Blue Screen of Death to that computer over the network.

To test your home, office or clients' machines, or even just to have some fun with your friends, all you need to do is connect to their network via WiFi, enter in their hostname (either IP or actual hostname will work), and press Execute!

Note: the target Vista machine must have network file / printer sharing turned on (though most people have it turned on these days)

This is a fun little application I created yesterday and have been having playing with my friends' computers on their home network and showing them the Windows flaw.

Video of it in action: http://www.youtube.com/watch?v=eIy_d94tDmQ

As I said, it will be patched soon, so anyone who has Windows Updates enabled will be immune to it within the next 72 hours or so.

BSODroid can be downloaded from the Android Market (just search for BSODroid!) or alternatively you can download the APK directly from my website: http://www.dereenigne.com/

http://img440.imageshack.us/img440/1494/bsodroid.png

As always, if you enjoy my software, please consider donating! http://www.dereenigne.com/donate.php

Minker17
10th September 2009, 05:30 PM
Well, it works. :)

Ather
10th September 2009, 05:53 PM
will try on win 7 :P

iammorris
10th September 2009, 05:56 PM
will try on win 7 :PFrom what I can tell, it works on most of the beta copies and some RC copies of Windows 7, but it doesn't work on the RTM version - what a shame! :D

Still, lots of fun!

Minker17
10th September 2009, 06:06 PM
Didn't work on my Win 7 RC machine. Maybe I'm up to date?

My boss and I just had some fun with one of our users on MO. (we are in TN)

iammorris
11th September 2009, 12:44 AM
Didn't work on my Win 7 RC machine. Maybe I'm up to date?Yeah, seems as though it works on some builds of Win 7, but not others.

It works on Win Server 2008 too. :)

I hope people are having their fun with it now, because Microsoft already have a patch in the works - I'm not sure if it's being pushed through Windows Updates yet, but if not then it will be quite soon!

Though, it will still always work on machines that don't run Windows Updates ;)

GreenLantern
11th September 2009, 02:17 AM
man, a winmo version would be awesome...

rogeriopcf
11th September 2009, 02:23 AM
man, a winmo version would be awesome...
That whould be consider a virus.

DaveTheTytnIIGuy
11th September 2009, 02:51 AM
That whould be consider a virus.


A computer virus is a computer program that can copy itself and infect a computer without the permission or knowledge of the owner.

It's being installed by the user, so it's not a virus at all. I personally think this is a neat little proof of concept program, and would love to have a copy for my WinMo device. Besides, if these proof of concept exploits weren't created, the software companies wouldn't have a reason to patch/fix their software until somebody with more malicious intents came along and used it. Hope there's a port to WinMo soon.

GreenLantern
11th September 2009, 05:23 AM
That whould be consider a virus.

why? there's ton's of stuff everyone at my office does that could be considered a 'virus' then...

even so, if you can do it from an android phone it's not a virus? somehow I don't understand that.

iammorris
12th September 2009, 03:46 AM
Quick video example: http://www.youtube.com/watch?v=eIy_d94tDmQ

ZzFDKzZ
12th September 2009, 04:08 AM
Ha cool...

nurre
12th September 2009, 02:48 PM
Could be fun to make a "one stop shop" for stuff like this.

There's the unpatched IIS flaw as well which is easy as hell to abuse.

Select exploit (or select all), select target ip (+port/username etc for stuff like an IIS exploit), execute (on an iis exploit that'd use default port, anonymous/anonymous).

Is there any interest in this? Think it could be rather interesting to code :P

GreenLantern
12th September 2009, 08:23 PM
Could be fun to make a "one stop shop" for stuff like this.

There's the unpatched IIS flaw as well which is easy as hell to abuse.

Select exploit (or select all), select target ip (+port/username etc for stuff like an IIS exploit), execute (on an iis exploit that'd use default port, anonymous/anonymous).

Is there any interest in this? Think it could be rather interesting to code :P

I"d be highly interested in that.

iammorris
1st October 2009, 07:28 AM
Have almost broken 1000 downloads! (Currently at 950)

If anyone's interested, go ahead and give it a try from the market! :D

antonis9891
2nd October 2009, 01:43 PM
Thank you. Great app, worked with my windows vista sp2.
Thanks!! I'm dying for this kind of apps :)

r0ck0
11th November 2009, 02:57 AM
If this had a way to find IP's in use on the network it would be perfect, or just a multicast mode. Go to starbucks and listen to everyone groan at the same time.