Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Toolsarrow ServifyThis
Ethical Hacker Community Forums
December 01, 2008, 07:53:47 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: ServifyThis  (Read 2389 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: October 01, 2008, 09:46:58 AM »

Quote

Windows machines run services in the background, letting admins manage them via the Services Control panel (services.msc) or the sc command. Penetration testers sometimes want to create a Windows service that will allow them to gain and maintain remote access of a Windows machine, possibly a persistent listener offering up shell access on a given port. Unfortunately, while the Windows sc command can be used to run any .exe as a service, Windows waits 30 seconds for the given program to throw a given API call to indicate that the service has started successfully. If Windows doesn't hear back from the service, it kills the program, thinking that the service failed to start. Thus, with sc, you can make your service, but you'll only get 30 seconds of access.

Previously, various commercial and shareware programs were available that would wrap provided executables inside of code that makes the appropriate calls so that Windows would let the executable run as a service and avoid the 30-second kill rule. But, such programs were only available for a fee... until now.

InGuardians' ServifyThis program takes any Windows executable and converts it into a form suitable for use as a Windows service.


Get it here:
http://www.inguardians.com/servifythis.html

Have fun and use wisely,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
RoleReversal
Sr. Member
****
Offline Offline

Posts: 469


View Profile WWW
« Reply #1 on: October 01, 2008, 09:51:49 AM »

Don,

nice heads up, my brains boggling with ideas

(all of them ethical of course Wink ....)
Logged

A little bit of sanity:
http://www.infosanity.co.uk
$w33p3R
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #2 on: October 01, 2008, 09:48:20 PM »

Holy smokes this could be dangerous, VERY DANGEROUS.  Another tool for the script kiddie to wreck havoc with.  Just what we need, another tool that takes no brains to run...sheesh
Logged

MCP, CEH
$w33p3R
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #3 on: October 01, 2008, 10:15:30 PM »

Sorry for the double post, in my previous post, I guess I was thinking out loud as a network security guy...lol  I didn't mean to take away from how awesome that FREE tool really is.  I can just see one of our "I think I'm a hacker" employees getting a hold of this and giving me hell.
Logged

MCP, CEH
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #4 on: October 01, 2008, 11:01:59 PM »

Holy smokes this could be dangerous, VERY DANGEROUS.  Another tool for the script kiddie to wreck havoc with.  Just what we need, another tool that takes no brains to run...sheesh

that argument is tiresome.  how bout we do a better job keeping them of the box in the first place and you dont have to worry about them exploiting "features" of windows.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
$w33p3R
Newbie
*
Offline Offline

Posts: 30


View Profile
« Reply #5 on: October 02, 2008, 08:23:28 AM »

Holy smokes this could be dangerous, VERY DANGEROUS.  Another tool for the script kiddie to wreck havoc with.  Just what we need, another tool that takes no brains to run...sheesh

that argument is tiresome.  how bout we do a better job keeping them of the box in the first place and you dont have to worry about them exploiting "features" of windows.

Great advise ChrisG, I will remove the 2000 employee computers we have in our orginization and let them use pencil and paper.  I don't guess you bothered reading my second post, you just wanted to be a smartass.
Logged

MCP, CEH
vijay2
Full Member
***
Offline Offline

Posts: 126


View Profile
« Reply #6 on: October 02, 2008, 08:47:00 AM »

I think to use this tool and servify an executable you would need some sort of user access on the machine. I work with a very large environment (10,000 +) users and have not seen many users who would wanna play with this kinda tool. Agreed there are always a few who are smarter than others but hey thats why we follow the concept of "Defense in Depth". rather than "Security by obscurity"

VJ
Logged

GPEN GCIH CISSP GSEC OSCP C|EH MCSE CNE Security+
apollo
Newbie
*
Online Online

Posts: 43


View Profile WWW
« Reply #7 on: October 02, 2008, 09:11:30 AM »

Personally, I think that if a script kiddie is going to own a box, for the owner of the box it is probably better if they used servifythis in order to create their back door.  It can uninstall itself, which is awesome.  I'd much rather have that than some of the other stuff out there.  Aside from the fact it can be handy for a pen tester, it has some great uses for other people too.  Microsoft already has a tool called SRVANY.EXE which will let you do something similar, but it's more complex to use. It definitely lowers the bar for people who want to run netcat as a service, but at least you know it is going to go in and out of your machine cleanly instead of worrying about registry keys and such with the current tools out there. 
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #8 on: October 03, 2008, 11:42:38 PM »


Great advise ChrisG, I will remove the 2000 employee computers we have in our orginization and let them use pencil and paper.  I don't guess you bothered reading my second post, you just wanted to be a smartass.

nope i wanted to make the point that the "think of the children!" kneejerk reaction to every security tool being released is tiresome.  If the threat you are trying to protect against is the script kiddie level, then your main focus should be just what i said keeping them off the box in the first place. 

If its your network users you are worried about who are generally NOT script kiddies there are other things you can do to keep them from running those sorts of tools.  its all about what you are trying to protect against.

« Last Edit: October 04, 2008, 12:12:59 AM by ChrisG » Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.