Big in China

From: Chris McNab (chris.mcnab@trustmatta.com)
Date: 12/05/02

  • Next message: Curt Wilson: "Windows XP remote access methods for pen test"
    From: "Chris McNab" <chris.mcnab@trustmatta.com>
    To: <pen-test@securityfocus.com>
    Date: Thu, 5 Dec 2002 00:58:29 -0000
    
    

    Gents,

    I was just checking back through recent pen-test posts and I've seen a lot
    of talk about Windows command-line sniffers, and some other tools. Recently
    I have been investigating Chinese programming and security groups, and I
    have come across a very prolific group of Windows programmers - netXeyes /
    Banyet Soft Labs.

    In particular they have released the following tools:

    * ARPsniffer.exe, a very effective Winpcap ARP redirect & sniffer program
    based on dsniff
    * FsSniffer.exe, a Windows NT / 2000 sniffer that runs as a service with a
    listening control port for log retrieval and sniffer configuration
    * WMIcracker.exe, a utility to brute force Administrative user passwords
    via. TCP port 135

    Which can be accessed with their other releases from:

    http://www.netxeyes.org/fssniffer.html
    http://www.netxeyes.org/2002.html

    They have a central GUI-based client/server system called Fluxay that seems
    to combine these technologies - worth checking out also ;]

    Regards,

    Chris

    Chris McNab
    Technical Director
    Matta Security Limited

    Web http://www.trustmatta.com
    Tel +44 (0)8700 77 11 00
    Fax +44 (0)8700 77 11 01

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • Re: The Myth of the secure Mac
      ... OEM Windows XP Home goes for a bit under $100. ... Though this really has nothing to do with security. ... > Microsoft itself would have to bear the brunt of all the programming ... All the more reason to avoid their products. ...
      (comp.sys.mac.advocacy)
    • Re: windows programming
      ... At Amazon this search immediately hit several: ... The .NET Developer's Guide to Windows Security (Microsoft Net Development ... Programming .NET Security ...
      (microsoft.public.win2000.security)
    • Re: Someone got into my system
      ... Please remember that 99.99999% of all 'bot nets are Windows PCs. ... it is good to keep up with Windows security issues. ... information and advise for Microsoft products. ... things you're taught in programming are "1) 80% to 90% of what you do is ...
      (microsoft.public.security)
    • Re: programming windows security
      ... security within application programming, or programming of ... Microsoft MVP (Windows Server System: Security) ... sites so that it helps me in coding ref. ...
      (microsoft.public.win2000.security)
    • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
      ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
      (Securiteam)