Double MetaRefresh Generator v1

Sorry imma noob lol
But lemme get this str8, all i do is enter my affiliate links , press generate and then the links cant be traced ? meaning my manager cant see where the signup came from? thx for any clarification

Can anyone answer this>?
 
well i had some problems with the second one you made (v2)

it just didn't work for me :(
and i really needed more then 3 links so i coded this real quick
witch is basically the same,
1. you enter as many links as you want (1 or 1,000).
2. you click the button and chose a directory for the two files to be created in
3. that's it the files are generated for you.


I used your php code hope you don't mind .


enjoy.
 
ok so after i do that i can use the link and my manager cant see where its comin from..?
 
Glad it's working out for everybody...

Barbacamanitu - Knew there were a few of us around...I don't know how to fake the referer (yet...;)) I'll see if I can dig anything up and will let you know.

dudeisbroke - Well, I hope that's what it does...otherwise, it's kinda just mental masturbation...:o On the plus side, if it doesn't blank it, your visitors would just be in a loop, so at least you won't get booted from the network for it...

razohad - If you get a chance, let me know what didn't work...got a good idea why it didn't but if you'll give me the symptoms, it'll tell me one way or the other...using the code is cool, I picked up 90 percent of it here from other posts...the other 10 came from a search for random PHP...nothing top secret...

Anyway, if there's anything else you think it should do...let me know and I'll work on dropping it in...

Later,
ND
 
when I click create php files it doesnt do anything?

Is it sposed to popup a new windows or......
 
It should just write out the 2 files wherever you saved the program...it creates rd1.php and randompage.php...

ND
 
Most refreshing!:icecream1
Nice work indeed and further shows what a giving community this is. Hope I have something to share soon but a whitehat has been on my head an awful long time. Learning a lot here that is helping me back up the ladder.
 
I must be a complete idiot because I can't see to figure out how to download the file from Laun*chFile.c0m. Any help would be greatly appreciated.


In case you haven't worked it out yet, there is a captcha code towards the bottom of the page. Fill that in and send and you will get the download:)
 
any chance of someone posting the raw php output files? macs are the best but right now they suck!

TIA
 
Hey razohad,

What type of file is the "blankreferer" file suppose to be?? When I open the zip its just a "file" and has NO extension. I thought this would be some sort of exe file like nesterdwarf posted. Please let me know.....
 
Hey razohad,

What type of file is the "blankreferer" file suppose to be?? When I open the zip its just a "file" and has NO extension. I thought this would be some sort of exe file like nesterdwarf posted. Please let me know.....

I just downloaded myself to see that every thing is working fine and it is working fine,
the file is an exe file and if you have .NET framework it should run just fine,
so your problem is either you dont have .NET framework or your zip file extractor is not good.

let me know.
razohad.
 
ok....well thats good to know then. Guess I'll be installing .NET framework.
 
Guys, just download the file and AV detected:

File: doublemetarefreshgenerator_v2.141.exe
Status: INFECTED/MALWARE
MD5: c2dbaccd1c21c00273820d0ffabe23e8
Packers detected: UPX

CPsecure Found Generic.Malware.sp

Any explanation? Maybe it's the code itself not a really trojan
 
Code:
Antivirus Version Last Update Result   AhnLab-V3 2008.9.4.2 2008.09.04 -   AntiVir 7.8.1.28 2008.09.04 -   Authentium 5.1.0.4 2008.09.03 -   Avast 4.8.1195.0 2008.09.04 -   AVG 8.0.0.161 2008.09.04 -   BitDefender 7.2 2008.09.04 -   CAT-QuickHeal 9.50 2008.09.02 -   ClamAV 0.93.1 2008.09.04 -   DrWeb 4.44.0.09170 2008.09.04 -   eSafe 7.0.17.0 2008.09.03 Suspicious File   eTrust-Vet 31.6.6069 2008.09.04 -   Ewido 4.0 2008.09.03 -   F-Prot 4.4.4.56 2008.09.03 -   F-Secure 8.0.14332.0 2008.09.04 -   Fortinet 3.14.0.0 2008.09.03 -   GData 19 2008.09.04 -   Ikarus T3.1.1.34.0 2008.09.04 -   K7AntiVirus 7.10.441 2008.09.04 -   Kaspersky 7.0.0.125 2008.09.04 -   McAfee 5376 2008.09.03 -   Microsoft 1.3903 2008.09.04 -   NOD32v2 3415 2008.09.04 -   Norman 5.80.02 2008.09.04 -   Panda 9.0.0.4 2008.09.03 -   PCTools 4.4.2.0 2008.09.04 -   Prevx1 V2 2008.09.04 -   Rising 20.60.31.00 2008.09.04 -   Sophos 4.33.0 2008.09.04 -   Sunbelt 3.1.1582.1 2008.09.02 -   Symantec 10 2008.09.04 -   TheHacker 6.3.0.8.072 2008.09.04 -   TrendMicro 8.700.0.1004 2008.09.04 -   VBA32 3.12.8.5 2008.09.04 -   ViRobot 2008.9.4.1363 2008.09.04 -   VirusBuster 4.5.11.0 2008.09.04 -   Webwasher-Gateway 6.6.2 2008.09.04 -      Additional information   File size: 1288188 bytes   MD5...: c2dbaccd1c21c00273820d0ffabe23e8   SHA1..: 3ad052244c5c1dbf350334f7be2bc926f89fa5f9   SHA256: 63d7b28386c77c55cc312ec6876472f9e209fc57341a8352a36f9e43d4169af8   SHA512: 9a07b64ad99694ea78e17f22efdcd32b876edbbc045e63e6f244e5c079ed15b8
29e14329fe795d9d5629e7ba58aa2acd44a1b6a7d4ab773ea7310f0dc2a15879   PEiD..: -   TrID..: File type identification
UPX compressed Win32 Executable (38.5%)
Win32 EXE Yoda's Crypter (33.4%)
Win32 Executable Generic (10.7%)
Win32 Dynamic Link Library (generic) (9.5%)
Win16/32 Executable Delphi generic (2.6%)   PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x7df0f0
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)

( 3 sections )
name        viradd    virsiz   rawdsiz  ntrpy  md5
UPX0        0x1000  0x2b3000       0x0   0.00  d41d8cd98f00b204e9800998ecf8427e
UPX1      0x2b4000  0x12c000  0x12b400   7.91  413731c157e07b76a8b8f3c0aab109c4
.rsrc     0x3e0000    0x8000    0x7c00   3.86  f058e6c0458ca444d22898dab2092395

( 16 imports )  
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> advapi32.dll: FreeSid
> comctl32.dll: ImageList_Add
> comdlg32.dll: PrintDlgA
> gdi32.dll: SaveDC
> icmp.dll: IcmpSendEcho
> ole32.dll: OleRun
> oleaut32.dll: VarNot
> shell32.dll: DragFinish
> URLMON.DLL: HlinkNavigateString
> user32.dll: GetDC
> version.dll: VerQueryValueA
> wininet.dll: InternetOpenA
> winmm.dll: mmioSeek
> winspool.drv: OpenPrinterA
> wsock32.dll: send

( 0 exports ) 
  packers (Kaspersky): UPX   packers (F-Prot): UPX
 
If you're referring to my file, does use the UPX packer for compression...

Here's the VirusTotal link...

hxxp://www.virustotal.com/analisis/84afd14a8fd8e097c6a1e8066008dfcb

Nothing extra in there...

ND
 
Yup... I was pointing out what was in it, from VirusTotal as well. I guess I should have been a bit more clear.
 
Back
Top