Penetration Testing mailing list archives

Re: [PEN-TEST] penetrating trojan


From: "Deus, Attonbitus" <Thor () HammerofGod Com>
Date: Fri, 1 Dec 2000 13:02:43 -0800


So all companies that have Network Address Translation enabled, are safe
from such trojans since the "master" never will be able to contact the
trojan (the victims IP will not be routed from the outside) !?


For this reason, I have been designing an app that 'phones home' at a
configurable interval via http (inherited proxy settings if available)
and checks for remote instructions to download additional files for
execution or to turn over control to my remote control app.  The data stream
is plain old innocuous-looking HTML with the commands steganographed within
the attribute tags (I'm still working on this part) so as to help avoid
suspicion.  So far its pretty cool, but I have a way to go yet.

Any suggestions for cool-O features are welcome.

---------------------------------------------------------
Attonbitus Deus
thor () hammerofgod com


Current thread: