Re: Trojan Horses Popular To The Malicious Hackers

From: Me (no_address_for_stinking_spammers_to_abuse@x-ray.gs)
Date: 11/19/02


From: Me <no_address_for_stinking_spammers_to_abuse@x-ray.gs>
Date: Tue, 19 Nov 2002 17:35:21 -0500

On Tue, 19 Nov 2002 14:17:12 -0500, "Karl Levinson [x y] mvp"
<levinson_k@excite.com> wrote:

>There are some known trojan tools which can disable your personal firewall
>software while making it appear to continue working.
>
>For firewalls like Zone Alarm and Sygate which can block certain .EXE file
>names from accessing the network, there are known trojans and methods which
>can make the communication appear to come from a generally trusted
>executable such as IEXPLORE.EXE Other firewalls don't watch the name of
>the file generating the traffic, so as long as the trojan is not using a
>restricted port, these firewalls would let the trojan right out.

Excellent. There's one more trick that can be useful. Ever notice how
Zone Alarm request permission to allow an un-approved process to
access the WAN? You just write the bug to activate the "OK" button
before the alert window ever has a chance to pop up, LOL. Oldami
posted a proof of concept on it a while back.

<repost of achived oldami post>

Message-ID:
<b2xkYW1p.f844da76d77d79428e14e820e0915ee6@1026002686.cotse.net>
Date: Sat, 6 Jul 2002 20:44:46 -0400 (EDT)
Newsgroups: alt.hackers.malicious
Subject: how to bypass zone alarm
From: "oldami" <oldami-no-spam-no-spam@cotse.org>

Probably nobody cares, but here it is anyway

  ZAdodge.c Zone Alarm Dodge by oldami

  Proof of concept to demonstrate one of the weaknesses of
  host based firewalls.

  This is for educational purposes only.
  I will not be responsible for any mis-use of this information.
 
  Concept: Zone alarm will prompt the user before allowing an unknown
  program to make an outgoing connection to the internet. All a
program
  needs to do is make the zone alarm program think the user has
pressed
  some keys to respond to the prompt.

  note: The SendInput function only works in Win98 and later.
         This was developed and tested on WinNT 4.0 SP6a but should
                 work on anything later than Win98.

  Author: oldami@cotse.net

complete source at
http://www.cotse.net/users/oldami/zadodge.c

-oldami

</repost of achived oldami post>



Relevant Pages

  • Re: Trojan Horses Popular To The Malicious Hackers
    ... >There are some known trojan tools which can disable your personal firewall ... >For firewalls like Zone Alarm and Sygate which can block certain .EXE file ... Zone Alarm request permission to allow an un-approved process to ... Zone alarm will prompt the user before allowing an unknown ...
    (microsoft.public.security)
  • Re: Trojan Horses Popular To The Malicious Hackers
    ... >There are some known trojan tools which can disable your personal firewall ... >For firewalls like Zone Alarm and Sygate which can block certain .EXE file ... Zone Alarm request permission to allow an un-approved process to ... Zone alarm will prompt the user before allowing an unknown ...
    (comp.security.firewalls)
  • Re: New Microsoft Security scare?
    ... >> from what i can gather all the AV products, spyware and trojan ... >> scanners and firewalls in the world is not enough to protect you if ... >insecurities in OE (and the built in ignorance of the average computer ... >I am speaking of the single home user, not those running a network, or who ...
    (alt.computer.security)
  • Re: Hello Microsoft. Your site or phony Trojan?
    ... It could be that your "firewalls" were ... the Microsoft web site to hide what was going on. ... Microsoft is involved in putting Trojan software on your computer. ...
    (microsoft.public.security)
  • Re: Sind zwei Firewalls ausreichend ?
    ... > Erst dank Zone Alarm ist mir endlich klar geworden, wie oft man so im Netz ... die beiden Firewalls zu deinstallieren??? ... Prev by Date: ... Next by Date: ...
    (de.comp.security.firewall)