Penetration Testing mailing list archives
Re: [PEN-TEST] penetrating trojan
From: Simon Waters <Simon () wretched demon co uk>
Date: Tue, 5 Dec 2000 01:53:06 +0000
"Randall, Mark (ISSCalifornia)" wrote:
Why did I never encounter such a trojan? Am I missing something ... has anybody heard of such attacks?Makes the attacker vulnerable. If the trojan made connections out, then the attacker would be known upon discovery of the trojan.
I vaguely recall a program that posted sensitive Windows information on affected machines to a newsgroup. I guess any broadcast or anonymous medium would do. https also has some advantages for this type of trojan - e.g. lack of proxies/intermediaries, whilst highly likely to be available. No one will bother looking/filtering the contents as it is suppose to be encrypted. I think DNS is least likely to be filtered, or require authentication to initiate. Of course there are less reasons with todays proxies why the end user PC need have unrestricted access to the Internet DNS, but people seem to have enough problem with configuring DNS to work correctly, let alone not configuring it to improve security. Dynamic DNS's could add another twist. Anyone know whether Lotus Notes usage of an seperate name service was a clever design decision, or just a result of historical accident?
Current thread:
- Re: [PEN-TEST] penetrating trojan, (continued)
- Re: [PEN-TEST] penetrating trojan Conor Crowley (Dec 02)
- Re: [PEN-TEST] penetrating trojan Arthur Clune (Dec 03)
- Re: [PEN-TEST] penetrating trojan Tom Vandepoel (Dec 03)
- Re: [PEN-TEST] penetrating trojan van der Kooij, Hugo (Dec 04)
- Re: [PEN-TEST] penetrating trojan Arthur Clune (Dec 03)
- Re: [PEN-TEST] penetrating trojan Conor Crowley (Dec 02)
- Re: [PEN-TEST] penetrating trojan Kazennov Vladimir (Dec 04)
- Re: [PEN-TEST] penetrating trojan Pierre Vandevenne (Dec 04)
- Re: [PEN-TEST] penetrating trojan Jean-Christophe Touvet (Dec 05)
- Re: [PEN-TEST] penetrating trojan Darbean (Dec 06)
- Re: [PEN-TEST] penetrating trojan Darbean (Dec 06)
- Re: [PEN-TEST] penetrating trojan Randall, Mark (ISSCalifornia) (Dec 05)
- Re: [PEN-TEST] penetrating trojan Simon Waters (Dec 06)
- Re: [PEN-TEST] OT: Lotus Notes name service (was: penetrating trojan) Michael Rowe (Dec 06)
- Re: [PEN-TEST] OT: Lotus Notes name service (was: penetratingtrojan) Simon Waters (Dec 07)
- Re: [PEN-TEST] penetrating trojan Simon Waters (Dec 06)
- Re: [PEN-TEST] penetrating trojan Sven Bruelisauer (Dec 07)
- Re: [PEN-TEST] penetrating trojan Guy Cohen (Dec 07)
- Re: [PEN-TEST] penetrating trojan C.E.Steiner (Dec 10)
- Re: [PEN-TEST] penetrating trojan David Knaack (Dec 07)
- Re: [PEN-TEST] penetrating trojan Robert van der Meulen (Dec 07)
- Re: [PEN-TEST] penetrating trojan Can Erkin Acar (Dec 10)
