Intrusion Detection Systems mailing list archives
Re: strings in backdoor binaries
From: achuvaki () ic sunysb edu (Anton Chuvakin)
Date: Fri, 28 Apr 2000 10:22:30 -0400
Archive: http://msgs.securepoint.com/ids FAQ: http://www.ticm.com/kb/faq/idsfaq.html IDS: http://www-rnks.informatik.tu-cottbus.de/~sobirey/ids.html UNSUBSCRIBE: email "unsubscribe ids" to majordomo () uow edu au Hi all!
When an intruder has penetrated a system and installed trojan binaries, when a "strings" command is executed what text strings will appear in trojaned files (aside from "letmein" or "satori", or course) that will (probably) not show up in a non-trajaned binary?
I recently analyzed some files left by the attacker (who was using
somthing similar to lrk4 rootkit, but not quite). In some binaries having
"/bin/sh" or just "sh" is definitely inappropriate (like, regular Linux
"in.fingerd" doesn't contain it and the trojaned did).
Regards,
--
Anton A. Chuvakin
Where is a will there is a way. <<
http://www.chuvakin.org licq: 29034084
Current thread:
- IDS Focus Area at SecurityFocus.com, (continued)
- IDS Focus Area at SecurityFocus.com Jensenne Roculan (Apr 24)
- intruder clues Meritt, Jim (Apr 24)
- Re: intruder clues flynngn () jmu edu (Apr 24)
- Re: intruder clues Philippe Bourgeois (Apr 25)
- Re: intruder clues Lance Spitzner (Apr 25)
- Scanning on tcp port 27374 Benninghoff, John (Apr 26)
- Re: Scanning on tcp port 27374 Gary Flynn (Apr 27)
- Re: Scanning on tcp port 27374 DPG (Apr 27)
- Re: Part 2 Scanning on tcp port 27374 DPG (Apr 27)
- strings in backdoor binaries Meritt, Jim (Apr 27)
- Re: strings in backdoor binaries Anton Chuvakin (Apr 28)
- Re: strings in backdoor binaries Gary Flynn (Apr 28)
- Re: strings in backdoor binaries DPG (Apr 28)
- Re: strings in backdoor binaries Jonas Eriksson (Apr 29)
- Re: strings in backdoor binaries Jonas Eriksson (Apr 29)
- Sniffing.... SatyaNarayana ANV (Apr 29)
- Re: intruder clues flynngn () jmu edu (Apr 24)
- RE: Scanning on tcp port 27374 Thomas J. Arseneault (Apr 27)
- Re: Scanning on tcp port 27374 Talisker (Apr 27)
- Fwd: Re: Part 2 Scanning on tcp port 27374 Lachlan Cranswick (Apr 27)
- Re: Fwd: Re: Part 2 Scanning on tcp port 27374 DPG (Apr 28)
- RE: Scanning on tcp port 27374 Benninghoff, John (Apr 27)
