Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Kung-Fu with Debug.exe
Ethical Hacker Community Forums
August 30, 2008, 09:51:14 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Kung-Fu with Debug.exe  (Read 649 times)
0 Members and 1 Guest are viewing this topic.
oneeyedcarmen
Full Member
***
Offline Offline

Posts: 202

Klaatu, Borada,Necktie?


View Profile
« on: May 22, 2008, 10:53:02 AM »

There's a really cool article on Dark Reading by John Sawyer about using hex and debug to transfer files onto a locked down target machine.

Pretty bad-ass, me thinks.  Anyone else seen this before?  Or am I behind the curve as usual?  Roll Eyes

Quote
During a discussion with a friend about techniques for getting files onto a Windows system once you get a remote cmd.exe shell, I was listing all the ways that I’ve seen: tftp, ftp, ftp with script, vbscript (similar to wget), and pasting hex into a file to be processed by debug.exe.

It was the last technique that piqued his interest because he hadn’t heard of it -- and neither have most people I’ve asked. The last time I saw it in use was an incident in 2005. The admin of the hacked server had locked down the system pretty tight, preventing access to tftp, ftp, and vbscript.

What did the attacker do? He put his own ftp.exe on the server by converting it first into hex (including specific notation understood by debug.exe), and pasted it into the echo command in his shell, putting the copied text into a file on the server. Next, with “debug < ftp.hex”, his file of text was converted into an executable that he could use to download his toolkit.

Logged

MCP, Security+, Associate (ISC)2
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.039 seconds with 22 queries.
 
Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.