Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
Jan 2009 Free Giveaway Sponsor - Black Hat DC
Scooby Doo and the Crypto Caper - Answers and Winners
Daemon - A Contest Revealed
Nov 2008 Free Giveaway - Winners
Hacking: The Art of Exploitation 2nd Edition
Dec 2008 Free Giveaway Sponsor - SANS
Santa Claus is Hacking to Town
Plug-N-Play Network Hacking
Nov 2008 Free Giveaway Sponsor - CWNP
Daemon - A Contest Begins Now
It Happened One Friday - Answers and Winners
Daemon - A Contest
Scooby Doo and the Crypto Caper
MS Blue Hat Hackers Headline Chicago Security Con
The Pen Testing Perfect Storm Webcast Series with Skoudis, Wright, Johnson
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 17 guests and 1 member online
EH-Net Donations
Enter Amount:
$
CAD
USD
GBP
AUD
JPY
EUR
Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations
You are here:
Home
Forum
Resources
Tools
ServifyThis
Ethical Hacker Community Forums
January 08, 2009, 03:27:45 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100!
www.chicagocon.com/content/view/103/51/
Home
Help
Calendar
Login
Register
Ethical Hacker Community Forums
>
Resources
>
Tools
(Moderator:
don
) >
ServifyThis
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: ServifyThis (Read 2745 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
Offline
Posts: 2435
Editor-In-Chief
ServifyThis
«
on:
October 01, 2008, 09:46:58 AM »
Quote
Windows machines run services in the background, letting admins manage them via the Services Control panel (services.msc) or the sc command. Penetration testers sometimes want to create a Windows service that will allow them to gain and maintain remote access of a Windows machine, possibly a persistent listener offering up shell access on a given port. Unfortunately, while the Windows sc command can be used to run any .exe as a service, Windows waits 30 seconds for the given program to throw a given API call to indicate that the service has started successfully. If Windows doesn't hear back from the service, it kills the program, thinking that the service failed to start. Thus, with sc, you can make your service, but you'll only get 30 seconds of access.
Previously, various commercial and shareware programs were available that would wrap provided executables inside of code that makes the appropriate calls so that Windows would let the executable run as a service and avoid the 30-second kill rule. But, such programs were only available for a fee... until now.
InGuardians' ServifyThis program takes any Windows executable and converts it into a form suitable for use as a Windows service.
Get it here:
http://www.inguardians.com/servifythis.html
Have fun and use wisely,
Don
Logged
CISSP, MCSE, CEH, Security+ SME
RoleReversal
Hero Member
Offline
Posts: 507
Re: ServifyThis
«
Reply #1 on:
October 01, 2008, 09:51:49 AM »
Don,
nice heads up, my brains boggling with ideas
(all of them ethical of course
....)
Logged
A little bit of sanity:
http://www.infosanity.co.uk
$w33p3R
Newbie
Offline
Posts: 30
Re: ServifyThis
«
Reply #2 on:
October 01, 2008, 09:48:20 PM »
Holy smokes this could be dangerous, VERY DANGEROUS. Another tool for the script kiddie to wreck havoc with. Just what we need, another tool that takes no brains to run...sheesh
Logged
MCP, CEH
$w33p3R
Newbie
Offline
Posts: 30
Re: ServifyThis
«
Reply #3 on:
October 01, 2008, 10:15:30 PM »
Sorry for the double post, in my previous post, I guess I was thinking out loud as a network security guy...lol I didn't mean to take away from how awesome that FREE tool really is. I can just see one of our "I think I'm a hacker" employees getting a hold of this and giving me hell.
Logged
MCP, CEH
ChrisG
EH-Net Columnist
Hero Member
Offline
Posts: 1049
Re: ServifyThis
«
Reply #4 on:
October 01, 2008, 11:01:59 PM »
Quote from: $w33p3R on October 01, 2008, 09:48:20 PM
Holy smokes this could be dangerous, VERY DANGEROUS. Another tool for the script kiddie to wreck havoc with. Just what we need, another tool that takes no brains to run...sheesh
that argument is tiresome. how bout we do a better job keeping them of the box in the first place and you dont have to worry about them exploiting "features" of windows.
Logged
...tests i took go here...
http://carnal0wnage.blogspot.com/
$w33p3R
Newbie
Offline
Posts: 30
Re: ServifyThis
«
Reply #5 on:
October 02, 2008, 08:23:28 AM »
Quote from: ChrisG on October 01, 2008, 11:01:59 PM
Quote from: $w33p3R on October 01, 2008, 09:48:20 PM
Holy smokes this could be dangerous, VERY DANGEROUS. Another tool for the script kiddie to wreck havoc with. Just what we need, another tool that takes no brains to run...sheesh
that argument is tiresome. how bout we do a better job keeping them of the box in the first place and you dont have to worry about them exploiting "features" of windows.
Great advise ChrisG, I will remove the 2000 employee computers we have in our orginization and let them use pencil and paper. I don't guess you bothered reading my second post, you just wanted to be a smartass.
Logged
MCP, CEH
vijay2
Full Member
Offline
Posts: 134
Re: ServifyThis
«
Reply #6 on:
October 02, 2008, 08:47:00 AM »
I think to use this tool and servify an executable you would need some sort of user access on the machine. I work with a very large environment (10,000 +) users and have not seen many users who would wanna play with this kinda tool. Agreed there are always a few who are smarter than others but hey thats why we follow the concept of "Defense in Depth". rather than "Security by obscurity"
VJ
Logged
GPEN GCIH CISSP CISA GSEC OSCP C|EH Security+
apollo
Jr. Member
Offline
Posts: 51
Re: ServifyThis
«
Reply #7 on:
October 02, 2008, 09:11:30 AM »
Personally, I think that if a script kiddie is going to own a box, for the owner of the box it is probably better if they used servifythis in order to create their back door. It can uninstall itself, which is awesome. I'd much rather have that than some of the other stuff out there. Aside from the fact it can be handy for a pen tester, it has some great uses for other people too. Microsoft already has a tool called SRVANY.EXE which will let you do something similar, but it's more complex to use. It definitely lowers the bar for people who want to run netcat as a service, but at least you know it is going to go in and out of your machine cleanly instead of worrying about registry keys and such with the current tools out there.
Logged
ChrisG
EH-Net Columnist
Hero Member
Offline
Posts: 1049
Re: ServifyThis
«
Reply #8 on:
October 03, 2008, 11:42:38 PM »
Quote from: $w33p3R on October 02, 2008, 08:23:28 AM
Great advise ChrisG, I will remove the 2000 employee computers we have in our orginization and let them use pencil and paper. I don't guess you bothered reading my second post, you just wanted to be a smartass.
nope i wanted to make the point that the "think of the children!" kneejerk reaction to every security tool being released is tiresome. If the threat you are trying to protect against is the script kiddie level, then your main focus should be just what i said keeping them off the box in the first place.
If its your network users you are worried about who are generally NOT script kiddies there are other things you can do to keep them from running those sorts of tools. its all about what you are trying to protect against.
«
Last Edit: October 04, 2008, 12:12:59 AM by ChrisG
»
Logged
...tests i took go here...
http://carnal0wnage.blogspot.com/
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Special Events
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009
=> News Items and General Discussion About EH-Net
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> Certification
===> The Charter Study Group - Pen Test
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
=====> CEH - Official Course Modules v4
=====> CEH - Official Course Modules v5
=====> CEH - Official Course Modules v6
===> CPTS - Certified Pen Testing Specialist
=====> CPTS - Official Course Modules v5
===> CPTE - Certified Pen Testing Expert
=====> CPTE - Official Course Modules v1
===> ECSA - EC-Council Certified Security Analyst
=====> ECSA - Official Course Modules v1.2
=====> ECSA / LPT - Official Course Modules v3
===> OSCP - Offensive Security Certified Professional
===> GPEN - GIAC Certified Penetration Tester
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
=====> CHFI - Official Course Modules v2
===> EnCE - EnCase® Certified Examiner
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Hardware
=> Malware
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Gates
=> Heffner
=> Hoffman
=> RichM
=> Murray
=> J. Peltier
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
Loading...
Sponsors
Polls
How many security events including conferences and training do you attend a year:
1 - 2
3 - 4
5 - 6
7+
None - But want to
None - Choose not to
Support EH-Net
Support EH-Net by
Buying all of your
Amazon items using
the search bar above.
Try CBT Nuggets Free!
Recent Forum Topics
CEH - Certified Ethical Hacker
: Helow... help some tutorials...
(7) by
K3lV1n
CEH - Certified Ethical Hacker
: CEH is a scam
(20) by
K3lV1n
Malware
: uninstall trend mciro officescan clients
(0) by
Hack_80
Mass Media
: Daniel Suarez Interview
(9) by
blackazarro
Malware
: Security Forecast for 2009
(5) by
jason
News from the Outside World
: Is this acceptable?
(9) by
jason
Wireless
: Wireless Pen Testing Cards
(6) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Technical
(1) by
jason
Gates
: Oracle version module for metasploit
(2) by
BillV
Book Reviews
: [Article]-Mitnick - The Art Of Intrusion: Ch 1 - Hacking The Casinos For A Million Bu...
(5) by
jason
Links to cool sites.
: Free Computer Engineering Classes From Stanford
(3) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: Skillz October 08 Winning Entry - Creative
(1) by
jason
Oct 2008 - Scooby Doo and the Crypto Caper
: [Article]-Scooby Doo and the Crypto Caper - Answers and Winners
(2) by
jason
News Items and General Discussion About EH-Net
: [Article]-Jan 2009 Free Giveaway Sponsor - Black Hat DC
(1) by
jason
Book Reviews
: Need a book suggestion!
(2) by
jason
News Items and General Discussion About EH-Net
: EH-Net Milestone - 2 Articles Cross 1 Million Page Views
(3) by
BillV
Other
: What kind of lab, machines you have for your security testing?
(12) by
charlottebandit
Malware
: Network Virus Problem
(9) by
RoleReversal
Wireless
: WUSB600N good usb ?
(2) by
nap191
Other
: FBI code cracking challenge
(3) by
jimbob
Calendar Of Events
: RSA 2009
(0) by
don
Forensics
: Network Forensic tools/practice/techniques
(2) by
jimbob
Malware
: Autoplay when i try to open the drive.
(4) by
jimbob
Physical Security
: Magnetic stripe card spoofing
(4) by
jimbob
Malware
: THe website is Evil but what to do??
(1) by
jimbob
Other
: Insanity?
(3) by
jason
CEH - Certified Ethical Hacker
: Any Practice Environment for learning tool for CEH?
(15) by
don
Wireless
: a petri-dish bridge
(2) by
don
CEH - Certified Ethical Hacker
: TFTP Tranfer time out
(5) by
jason
Tools
: tool to trace users
(8) by
pseud0
Malware
: Malware Challenge 2008 Analysis
(0) by
blackazarro
Programming
: Python 3.0 Released
(0) by
don
Forensics
: SANS SIFT Forensic toolkit
(1) by
don
Links to cool sites.
: Omgili Hacking - Another Search Engine dedicated to Hacking Related Forums
(2) by
RoleReversal
Tools
: Insecure.org's 2006 Top 100 Security Tools List Released
(10) by
shednik
Other
: Happy New Year!
(8) by
vijay2
CEH - Official Course Modules v6
: Community-built CEH Wiki
(2) by
yehg
Vote For EH-Net
progenic.com
binarica.com
technorati fave
Privacy Notice
for TDCC & All Properties
© 2009 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.