perl/php connect-back backdoor?

From: Victor Pereira (vpereira_at_modulo.com.br)
Date: 07/29/03

  • Next message: Victor Pereira: "is it even possible for a worm with dcom vuln?"
    To: <vuln-dev@securityfocus.com>
    Date: Tue, 29 Jul 2003 16:33:13 -0300
    
    

    Hi, you can use the reverse shell from THC (
    http://www.thc.org/releases/rwwwshell-2.0.pl.gz)

    <cut>
    Well, a program is run on the internal host, which spawns a child every day
    at a special time. For the firewall, this child acts like a user, using his
    netscape client to surf on the internet. In reality, this child executes a
    local shell and connects to the www server owned by the hacker on the
    internet via a legitimate looking http request and sends it ready signal.
    The legitimate looking answer of the www server owned by the hacker are in
    reality the commands the child will execute on it's machine it the local
    shell. All traffic will be converted (I'll not call this "encrypted", I'm
    not Micro$oft) in a Base64 like structure and given as a value for a
    cgi-string to prevent caching.
    </cut>

    You can use netcat compiled with the execute option and run with a time
    option to connect to your machine either.

    Reguards,

    VP
    ______________________________________________
    Victor Pereira - LPI, CCSA, CCSE - Security Analyst

    http://www.modulo.com.br
    http://getdata.codigolivre.org.br


  • Next message: Victor Pereira: "is it even possible for a worm with dcom vuln?"

    Relevant Pages

    • Re: Question about pipes and terminals
      ... the user should be able to use the shell normally. ... > that the child has finished directly it all worked well. ... > process through a pipe. ... Now when i execute a shell, ...
      (comp.os.linux.development.system)
    • Re: Question about pipes and terminals
      ... the user should be able to use the shell normally. ... > that the child has finished directly it all worked well. ... > process through a pipe. ... Now when i execute a shell, ...
      (comp.os.linux.development.system)
    • Question about pipes and terminals
      ... the user should be able to use the shell normally. ... that the child has finished directly it all worked well. ... pipes to redirect stdin/stdout/stderr to the executable. ... Now when i execute a shell, ...
      (comp.os.linux.development.system)
    • Re: Probelm with using UNIX source command with exec
      ... > it and make all my other commands to execute within that shell or as ... > child of that shell. ...
      (comp.lang.tcl)
    • Remarks By John McCain on His Vision for Defending the Freedom and Dignity of the Worlds Vulnerable
      ... signaling the end of slavery in the United States. ... We can retain our own freedom when ... While the Internet has brought many benefits to our society in the ... Recent years have seen an explosion both in the proliferation of child ...
      (rec.outdoors.rv-travel)