ACK Tunneling Trojans

– Arne Vidstrom, arne.vidstrom@ntsecurity.nu
Summary

Trojans normally use ordinary TCP or UDP communication between their client and server parts. Any firewall between the attacker and the victim that blocks incoming traffic will usually stop all trojans from working. ICMP tunneling has existed for quite some time now, but if you block ICMP in the firewall you’ll be safe from that. This paper describes another concept, that I call ACK Tunneling. ACK Tunneling works through firewalls that don’t apply their rule sets on TCP ACK segments (ordinary packet filters belong to this class of firewalls).


Serve Cmd
This program is based off of netcat(thanks to Hobbit). This program allows multiple connections while netcat only allows one and is a bit easier to use. Run this program on any NT machine to open a remote shell on any port You can start the program hidden (/h) and also assign it what port to listen on(default is 2323). Type “srvcmd.exe /?” for help. Once the program is listening telnet into the computer on that port and you have a shell(cmd) environment waiting for you. The shell will have the same permissions as the user who started the program. If the shell is started with administrator access, you can do things like add users via the net command:


// Introduction

OK, this is just a little re-packaging of ‘RuX UPLOADER’ with a few
modifications to the batch file for clarity and so that the victim
can’t see any ftp activity once the uploader is run. Also, I have
included COM2EXE to convert the COM file created by BAT2COM into an
EXE file and a batch file to automate the process. If you want to
read the original readme, I’ve included it as readme.old.


——————————————————————————
FPipe v2.1 – Port redirector.
Copyright 2000 (c) by Foundstone, Inc.
http://www.foundstone.com
——————————————————————————

FPipe is a source port forwarder/redirector. It can create a TCP or UDP stream
with a source port of your choice. This is useful for getting past firewalls
that allow traffic with source ports of say 23, to connect with internal
servers.


..::MAXIMIZE & TURN ON WORD WRAP::.. ======================== - Sub 7 2.1.5 - - coded by mobman - _ ReaDMe/Tutorial _ - by FuX0reD - [ http://www.sub7.net ] ======================== Intro: In this tutorial I, FuX0reD, will try to do as much hand-holding and will try to be as THOROUGH as possible, AND IT WILL BE IN PLAIN ENGLISH (for those people who dont know, or dislike.....

_________________________________________________________________________ TCP\IP: A Mammoth Description By Ankit Fadia ankit@bol.net.in_________________________________________________________________________ TCP\IP or Transmission Control Protocol \ Internet Protocol is a stack or collection of various protocols. Aprotocol is basically the commands or instructions using which two computers within a local network or theInternet can exchange data or information and resources. Transmission Control Protocol \ Internet Protocol or the TCP\IP was developed around the time of theARPAnet......

.-‘____________|______
| |
| Your computer |
| is dead… |
| and it was so alive | Local Windows hacking for newbies
| _______ |
| |.—–.| | Written by MiggyX for the Black Sun Research Facility
| ||x . x|| |
| ||_.-._|| | Contact : miggyx@amicoders.demon.co.uk
| `–)-(–` |
| __[=== o]___ | Coming together is a beginning, Staying together is
| |:::::::::::|\ | progress, Working together is success!
| `-=========-`() |
| You shouldn’t have |
| installed: |
| |
| -= Win’95 =- |
`———————`

Old AOL Phishing Phrases

Hi, I'm with AOL's Online Security. We have found hackers trying to get into your MailBox. Please verify your password immediately to avoid account termination. Thank you. AOL Staff Hello. I am with AOL's billing department. Due to some invalid information, we need you to verify your log-on password to avoid account cancellation. Thank you, and continue to enjoy America Online. Good Evening. I am.....

This is a fairly simple modification that can be made to any phone. All

it does is allow you to take any 2 lines in your house and create a party
line. So far I have not heard of any problems with it from my friends that
have set one up and I have not had any either. There is one thing that you
will notice when you are one of the two people who is called by a person with
this box. The other person will sound a little bit faint. I could overcome
this with some amplifiers but then there wouldn’t be very many of these boxes
made. I think that the convenience of having two people on line at any one
time will make up for the minor volume loss.

(> Phone Modification Instructions <)


 

—————————————————————–
– The Marshals of Dynamic Discord –
– Present –
—————————————————————–
– The Chartreuse Box (or any other obnoxious color) –
—————————————————————–
– By: Wonko The Sane –
—————————————————————–

Intro
—–

The Chartreuse Box, so named because this is an obnoxious box
and chartreuse is an obnoxious color, is designed to take
advantage of the thousands of dollars Ma Bell pays to the electric
company each day. As you know, your telephone line is a constant
power source. The chart box is designed to allow you to tap that
power source for whatever sicko purposes you might have in mind.