RE: Creating a Custom Trojan after Social Engineering

From: Eric McCarty (eric_at_piteduncan.com)
Date: 01/13/05

  • Next message: Chris Buechler: "Re: Discovering users by RCPT TO"
    Date: Thu, 13 Jan 2005 10:29:45 -0800
    To: "Slider Slider" <0bscur3@gmail.com>, <pen-test@securityfocus.com>
    
    

    VNC offers the option to reverse connect using the -connect command
    line.

    Here is an example of using SSH and VNC. Not quite a remote access
    Trojan but very simple.

    http://faq.gotomyvnc.com/fom-serve/cache/128.html

     

    -----Original Message-----
    From: Slider Slider [mailto:0bscur3@gmail.com]
    Sent: Wednesday, January 12, 2005 3:34 PM
    To: pen-test@securityfocus.com
    Subject: Creating a Custom Trojan after Social Engineering

    In the middle of a pen test and I have sucessfully SE'd some employees
    to visit a website that I created to download a keylogger. I was able to
    get a lot of information. I am working on the firewall and there are no
    open ports or services running, strictly internet access....so the
    thought....

    I want to exchange the executable keylogger for a trojan that will
    connect to me from the client giving me remote access control. I have
    sampled a few, but can't find any custom programs where I can tell it
    what to do and when to uninstall.

    Has anyone tried this?

    0bscur3


  • Next message: Chris Buechler: "Re: Discovering users by RCPT TO"

    Relevant Pages

    • RE: Creating a Custom Trojan after Social Engineering
      ... Search for Rx.exe as well - Windows Universal Reverse Shell Trojan ... > Here is an example of using SSH and VNC. ...
      (Pen-Test)
    • Re: Privacy.LIE scamming you again!
      ... A trojan is a friendly looking object with a hidden malicious component. ... It is shorthand for 'trojan horse'. ... Remote access is irrelevent. ... erase the hard drive" into a word processor and you get a copy and proceed to ...
      (alt.computer.security)
    • MSIE vulnerability exploitable with IncrediMail
      ... possible to gain a remote access on a computer. ... (on Windows 2000 Professionnal) ... trojan in attachments, it will be save in this directory. ...
      (Bugtraq)
    • Re: win vnc
      ... I know it isn't a trojan - I've used it. ... I'm saying Deloder is known to ... install it without the user's knowledge. ... > Win VNC is not a trojan. ...
      (microsoft.public.security)