Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Incidents: Re: Sub-7

Re: Sub-7

From: James Stevenson <mistral_at_STEVENSON.ZETNET.CO.UK>
Date: Thu, 8 Jun 2000 10:36:12 GMT

[This message has also been posted.]

Hi

it connects to an irc server and joing a room that the infector
chooses and then advestises your ip with the user / password to the tojan
i am about to try to create a fake Sub7 Trojan in c for linux if anyone would be
intrested to try i also think from what i have found out about the protocol
that it is possinble to crash the client and make it do horroble things in return :)

just so that you can waste peoples time trying to use it and also have them
on long enough to try and report them to there isp

cya
        James

On 8 Jun 2000 10:26:56 -0000, Khan, Mansoor <Mansoor.Khan_at_INVESTORSGROUP.COM> wrote:
>I was wondering if any one has any experience with this Trojan (Sub-7).
>I am interested in finding out if it sends info through a general
>broadcast to chat rooms. Additionally, what specific info does it send
>(from a w-95 machine) e.g. registry settings, user ids and passwords
>etc.
>
>Thanks,
>

--
---------------------------------------------
Check Out: http://www.users.zetnet.co.uk/james/
E-Mail: mistral_at_stevenson.zetnet.co.uk
 10:30am  up 3 days, 23:09,  3 users,  load average: 0.40, 1.35, 0.95
Received on Jun 08 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos