Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 14 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008s
chicagocon2008s_125x200.jpg
ChicagoCon 2008s
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow Kung-Fu with Debug.exe
Ethical Hacker Community Forums
July 04, 2008, 05:35:07 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Podcasts and slide decks from ChicagoCon 2008s talks coming soon! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Kung-Fu with Debug.exe  (Read 440 times)
0 Members and 1 Guest are viewing this topic.
oneeyedcarmen
Full Member
***
Offline Offline

Posts: 157

Klaatu, Borada,Necktie?


View Profile
« on: May 22, 2008, 10:53:02 AM »

There's a really cool article on Dark Reading by John Sawyer about using hex and debug to transfer files onto a locked down target machine.

Pretty bad-ass, me thinks.  Anyone else seen this before?  Or am I behind the curve as usual?  Roll Eyes

Quote
During a discussion with a friend about techniques for getting files onto a Windows system once you get a remote cmd.exe shell, I was listing all the ways that I’ve seen: tftp, ftp, ftp with script, vbscript (similar to wget), and pasting hex into a file to be processed by debug.exe.

It was the last technique that piqued his interest because he hadn’t heard of it -- and neither have most people I’ve asked. The last time I saw it in use was an incident in 2005. The admin of the hacked server had locked down the system pretty tight, preventing access to tftp, ftp, and vbscript.

What did the attacker do? He put his own ftp.exe on the server by converting it first into hex (including specific notation understood by debug.exe), and pasted it into the echo command in his shell, putting the copied text into a file on the server. Next, with “debug < ftp.hex”, his file of text was converted into an executable that he could use to download his toolkit.

Logged

MCP, Security+, Associate (ISC)2
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.043 seconds with 22 queries.
 
BackTrack2 VM w/ MSF3

Get it here NOW!

Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008s_125x200.jpg
ChicagoCon 2008s


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008s_125x200.jpg
ChicagoCon 2008s
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.