Open jamiekarvans opened 8 months ago
Hi, thank you)
1) I was thinking about opening browsers back after shutdown, but tabs etc are not saved and you still have to click "Restore" button. But in principle it can be added.
2) Ok, I'll add that the email should contain the results of the collection.
3) By working directory do you mean where it saves the collected data? If yes, then nowhere, all collected data is stored in RAM, then it forms an archive in RAM and sends it to wherever it needs to go. stink
does not create any temporary files while working.
Preview of collected data added since version 4.6.0.
an amazing job, again.
there were a few thing i was facing:
edit: the script by default throws an error and on some os systems makes the error keep looping and hangs up the system , here is the error : error_crc: Data error (clynic redundancy check).
also in my tests stink crashes and exists if internet connection is not up during sending data, i think it would be nice to wait for internet connection before doing any internet related behaviors?
just an enhancement: the Crypto Wallets are password protected, i think it would be nice and also good practice to have an option to wait for an app or process to start and then start capturing KeyStrokes, (for wallets EXEs for example or certain websites)
and lastly one question, i'm just curious why not creating temp files? are you avoiding touching the disk for AV triggers or ...?
Thank you.
It's a fake error. I forgot to remove the auto power on. Now it will appear only if you specify it in the parameters. What do you mean by "error keeps looping and hangs up the system"?
Good idea, I'll add it.
This is usually done by other people who have the equipment and so on. It's already a keylogger, and the stealer job is just to collect the data and send it. If you want to, you can load a third-party keylogger via the built-in loader.
Initially it did, but I decided that it would be better to store everything in memory than to create a directory with files.
hey long time no see, how you've been doing? i was just testing around with the code and i realized it doesn't grab firefox passwords and cookies also do you think you can use the same system password to get the backup codes from authenticator extension files?
hey thanx for the updates, i really like how well you're expanding the application here are some suggestions i think would be nice to implant:
after Stink finished its job, open back all the closed browsers so make less suspicion and look more real
add some info and summery of what is grabbed to sender for example for email sender:
then add message.set_content(pmessage) to email class ps: i didn't know where is the working directory (where is it btw?) but would be nice to iterate over grabbed data also add the number of grabbed telegram sessions and wallets to the email as well to know if it's even added or not, for example: Telegram Sessions : 1 Wallets : 4 and if browser is not grabbed or any other data, it would be nicer to not even include that in the email text at all instead of showing 0 is grabbed (for easier indexing and searching through emails and finding the ones that include the searched data)
add grabbed Browser Passwords to grabbed info as plain text in email aswell to organize better the data and search easier through grabbed info without the need to open each zip file and look for if data is grabbed.
and again thanx and nice job on your new works.