[TOOL] TunnelShell, Tunneling Shell Access via TCP/UDP/Fraged/ICMP/RawIP Packets

From: support@securiteam.com
Date: 02/27/02


From: support@securiteam.com
To: list@securiteam.com
Date: Wed, 27 Feb 2002 06:47:34 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  TunnelShell, Tunneling Shell Access via TCP/UDP/Fraged/ICMP/RawIP Packets
------------------------------------------------------------------------

DETAILS

TunnelShell is a program written in C for Linux users that works with as
client-server application. The server opens a /bin/sh that clients can
access though a virtual tunnel. The following types of tunnels are
supported:

Frag: Using IPv4 fragmented packets to encapsulate data. When some routers
and firewalls (like Cisco routers and default Linux installation) receive
fragmented packets without headers for the fourth layer, they permit them
to pass along, even if they have a rule to deny it (You could select layer
four protocols with flag -o).

TCP: Establishing a virtual TCP connection without the use of the three
handshakes (useful when you have a router with ACL or a Linux server with
ipchains). It does not bind to any port, so you can use a port already
used by any another process.

UDP: Standard UDP packet. It does not bind any port, so you can use a port
already used by any another process.

ICMP: Standard ICMP packet (echo-reply/echo-request)

IP: Raw IPv4 packets, you can specify a layer four protocol with flag -o.
Useful if IPSec has been enabled between servers.

Because packets are not sequenced, you might want to use the -d flag to
make sure that they will be received in the right order. Lost packets are
not recovered at current version.

ADDITIONAL INFORMATION

The tool can be downloaded from:
 <http://www.geocities.com/fryxar/> http://www.geocities.com/fryxar/.

The information has been provided by <mailto:fryxar@yahoo.com.ar> fryxar
fryxar.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: What is going on with my Dialup?
    ... also forward it to an unused port, and have that port provide the ... verses the RST or ICMP 3,3. ... The lack of response causes the remote computer to make ... Others think that by not responding to unwanted packets, ...
    (comp.os.linux.networking)
  • Re: OT .. Road Warrior communications question
    ... The data on the Internet is sent in little packets. ... The packets addressed to port 80 ... Likewise, at the mail server receiving the packets, it knows the return ... Why would e-mail work on the web but not from your e-mail software? ...
    (alt.guitar.bass)
  • Re: Logs: Many hits with source port of 80
    ... The hits from source port 80 to dest port 37852 are IMHO almost ... you should probably see a couple other packets - perhaps ... packets if either you send the load balancer a packet, ... >>I have seen similar hits for the past three months. ...
    (Incidents)
  • Re: Error 720 connecting to server via VPN
    ... By default the router's firewall is configured to drop ICMP packets ... Select WAN Setup> Advanced> Respond to Ping on Internet Port. ... server and the Internet allow GRE packets. ... routers on the user's network are also configured to allow GRE packets. ...
    (microsoft.public.windows.server.sbs)
  • Re: WORM? ... server generating NBT-NS (port 137) traffic on WAN interface
    ... You have a concern about the outbound port 137 traffic in the SBS domain. ... The UDP 137 is related to the NetBIOS Over TCP/IP name service. ... I did run NETMON on the SBS2003 box, it did find the extraneous packets ... ... connected to the Internet (If the SBS server is the 2 NICs scenario). ...
    (microsoft.public.windows.server.sbs)