New Tool - "SMTP Rootkit" for IIS 5/6 & EX2000/2003

SCInfo_at_SMTPCommander.com
Date: 08/27/05

  • Next message: Andres Riancho: "Re: Software Proxys Anonymous"
    Date: 27 Aug 2005 16:50:27 -0000
    To: pen-test@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is) I'd like to annouce a new tool that could be useful in pen testing, or for administration use for a server running SMTP via IIS 5.0, 6.0, including Exchange 2000/2003 and SBS 2000/2003.

    The tool won't help you get on a box, but once you are in installing it will help you stay on it or issue commands through SMTP email as the carrier.

    Free! Donations accepted.

    http://www.SMTPCommander.com

    Beta version ready to download.

    Basic overview:
    * runs with "system" privilages
    * input is normal email, results returned to send via email
    * single dll, must have admin rights to install and register
    * no service, no task will show (runs under IIS)
    * only known ways to detect it is find the actual DLL, or use script to examine events for SMTP
    * passes email thru unless trigger in subject given
    * allows shell commands as system acct
    * get/put files from/to server
    * reg read/write commands

    Example uses tested so far:
    * put pwdump2 on server, execute, return sam file
    * dump registry to file and return
    * explore drives using directory

    I'm interested in any feedback, post a reply or email me at SCInfo@SMTPCommander.com


  • Next message: Andres Riancho: "Re: Software Proxys Anonymous"

    Relevant Pages

    • RE: Cant connect in to server!
      ... Cant access remote web workplace from outside server, ... Installing RRAS returned OK ... > address 3389 on the command line and paste the results to the newsgroup. ... > Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • ANNOUNCE: UnixODBC 0.31
      ... UnixODBC provides a toolkit for writing Perl ODBC clients. ... - Installing and Configuring the Bridge Server ... UnixODBC.pm provides Perl programs with a subset of the X/Open ... Bridge Server," below. ...
      (comp.lang.perl.modules)
    • Re: IPSEC question
      ... The important issue is to get the server working properly first without ... I hit the SBS weblog and tried their stuff. ... Microsoft network client: Digitally sign communications: ... 898060 Installing security update MS05-019 or Windows Server 2003 Service ...
      (microsoft.public.windows.server.sbs)
    • Re: sql 2005 ctp install didnt go so well
      ... Mike Epprecht, Microsoft SQL Server MVP ... > Installing: sqlsupport on target: SERVER ...
      (microsoft.public.sqlserver.setup)
    • Re: VPN disconnection
      ... installing the hotfixes, there will be some problems with VPN. ... Therefore if you installed SP2 on the server, ... Acceleration (ISA) Server 2006 or ISA Server 2004 ... 'Microsoft Firewall' service. ...
      (microsoft.public.windows.server.sbs)