Full Disclosure mailing list archives

Re: nmapbot: using instant messaging as a remote administration tool


From: 3APA3A <3APA3A () SECURITY NNOV RU>
Date: Tue, 5 Oct 2004 13:49:02 +0400

Dear Abe Usher,

There  is at least 1 Miranda plugin (nRemX) for remote command execution
via different IM protocols.

--Tuesday, October 5, 2004, 8:46:46 AM, you wrote to full-disclosure () lists netsys com:

AU> -----BEGIN PGP SIGNED MESSAGE-----
AU> Hash: SHA1

AU> I've created a small proof of concept named "nmapbot" that shows it is
AU> possible to use instant messaging as a platform for remote command and
AU> control of computer systems.

AU> Purpose:
AU> - --------
AU> To create a semi-intelligent security bot that uses instant messaging as
AU> a platform for receiving commands and returning results.

AU> Method:
AU> - -------
AU> Using Python, the AOL TOC protocol, Bayesian language processing, and
AU> nmap 3.70, I hacked together a little bot that can run nmap and ping.
AU> Future editions will include additional commands =)

AU> The nmapbot rests squarely on the shoulders of python and projects such
AU> as Py-AIML, AIMLBayes, GrokItBot, and Reverend.  Many thanks to fyodor
AU> et al. for the excellent tool suite in nmap 3.70.

AU> If you are interested, you can find source code and documentation for
AU> nmap bot at:
AU> http://www.sharp-ideas.net

AU> Cheers,
AU> Abe Usher, CISSP


AU> -----BEGIN PGP SIGNATURE-----
AU> Version: GnuPG v1.2.4 (MingW32)
AU> Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

AU> iD8DBQFBYic2T3X9miqOcSQRAtLuAJ9V6yH+aHzs4tRPvVIQhu9jGuDXkQCdEUCZ
AU> g33XB8OYyWljCuCNPr1fpe8=
AU> =Gg0O
AU> -----END PGP SIGNATURE-----

AU> _______________________________________________
AU> Full-Disclosure - We believe in it.
AU> Charter: http://lists.netsys.com/full-disclosure-charter.html


-- 
~/ZARAZA
Ну а теперь, Уильям, хорошенько поразмыслите над данным письмом. (Твен)

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: