Re: Intrusec 55808 Trojan Analysis

From: Peter Busser (peter_at_trusteddebian.org)
Date: 06/25/03

  • Next message: Jerry Shenk: "RE: strange logs -- tcp port 16166"
    Date: Wed, 25 Jun 2003 09:02:04 +0200
    To: incidents@securityfocus.com
    
    

    Hi!

    > Since it can be delivered anywhere
    > on the subnet the trojan is listening promiscuously on, it is difficult
    > to figure out where the trojan is actually located even upon capturing
    > this command.

    But you can also use that command to your own advantage. Simply regularly
    inject messages which will make the trojan try to contact a machine you own.
    The trojan will then expose itself.

    Groetjes,
    Peter Busser

    -- 
    Adamantix - Taking high-security Linux out of the labs, and into the world.
    http://www.adamantix.org/
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Jerry Shenk: "RE: strange logs -- tcp port 16166"

    Relevant Pages

    • Re: Covert Channels
      ... Here is part of a paper I recently wrote talking about "rawIP" Trojans. ... "Q" trojan should be exactly what you are looking for in regards to a covert ... qs -C "command" server.com - Execute remote shell commands. ... sending control packet to 10.0.0.2 ...
      (Pen-Test)
    • Re: DNS hacked/hijacked by the "Delude.B" trojan
      ... The DNS addresses were: ... This trojan uses a bug> in Microsoft's Internet Explorer that allows web page> authors to write web pages that will cause Internet Explorer to ... The intent of the> attacker was clearly to run a proxy DNS service providing> name->address mappings of his/her choosing, in order to impersonate> services without your being any the wiser. ... Since running executables in Win32> cannot delete themselves, it does this by spawning a command> interpreter, passing it a command script containing commands to> delete both the executable and the script. ...
      (microsoft.public.win2000.security)
    • Re: [9fans] security
      ... and attempt to execute the magic command. ... How about forking off a server process that lets me execute arbitrary commands as you? ... How about placing trojan processes in your person bin directory? ... There are lots of irritating things that can happen even without setuid or a super user. ...
      (comp.os.plan9)
    • Cleaning Trojan virus off
      ... One of our workstations has a trojan on it. ... the file identified by the on-access scanner cannot be found ... by the windows explorer, command line dir command, or the Novell ndir ... I have tried to use system restore to get to a prior safe state, ...
      (microsoft.public.security.virus)
    • Re: chkrootkit found possible LKM trojan
      ... Debian, 2month ago, chkrootkit. ... You have 4 process hidden for ps command ... >Any idea what this Trojan is and what I should do? ... Best two popular LKM rootkit are adore and knark. ...
      (comp.os.linux.security)