hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Beast Is Alive
Progressor
There is a new site, there you can download a new version of Beast:

http://www.beastdoor.com/
ehsan_sfd
really thanks my friends!
it is a nice and a full program and also has a really nice visual tutorial about the software

again thanx....

tataye
Thank you for promotion smile.gif

-tataye
Serhat
CODE
Beast 2.07 update :P

Heh, in the first package the server without injection was left uncompressed and you could encounter problems when compressing it, so I did a quick update. In the current downloadable Beast 2.07 the server without injection is compressed.

The first Beast 2.07 has the build date August 03, 2004 and the second August 04, 2004.

Thank you for your interest and for joining the forums :)

-tataye


So I assume you tateye wrote this trojan right? smile.gif

[EDIT]

CODE
Thank you and congratulations to tataye, for coding such a great RAT.


YUP tongue.gif

Serhat
sentinel777
thanky you, nice tool smile.gif
ganz2
basically the same as 2.06
(S)
i can't down huh.gif
please full link??
sorry, bad english
FLX
great work tataye!
you should be promoted!
FLX
dagg3r
Great , i like the "lamer stuff" nice work. btw i just wanted to know does this get detected by any AV??? so far nothing from my AV but im on norton and hasnt been updated for a while heh and also as i am a new member i read somewhere about a program called stealth tools or something that can change hex this should make the trojan undetectable right?
Pseudonym
Stealth Tools is a collection of tools designed to make a trojan etc undetected to an anti-virus/anti-trojan product.

You can just use any hex editor if you know what to do, it is not an automated process where you just push some buttons and it is done though.

Basically you have to find the string in the file which the anti-virus (av) detects then you just change it slightly with a hex editor, then save the file and rescan it with your av to make sure it is undetected.

Modifying the hex of a file can make it corrupt though. Also just because you have made the file undetected from one av does not mean it will be detected from another, different av`s usually choose different strings.
EVIL-INSIDE
YES I HAVE THE BEAST TROJAN
Daume
hey Great release :-)

I discover Beast , I was more Optix pro before

Mcafee detects both client and new servers ^^ need some hex work there :-p

When i use upx, first depack and repack randomley , the .exe file doesnt work anymore. bad repack ? did it affect the server.exe too much ?

i would appreciate your feedback



chris105
molebox my frend molebox the shit outta it !!
tianzhen
QUOTE (Daume @ Sep 22 2004, 11:55 AM)
hey Great release :-)

I discover Beast , I was more Optix pro before

Mcafee detects both client and new servers ^^ need some hex work there :-p

When i use upx, first depack and repack randomley , the .exe file doesnt work anymore. bad repack ? did it affect the server.exe too much ?

i would appreciate your feedback

cut the ending(config info) of the exe before packing
zero1952
wub.gif
The site of beast is gone can enione sent to me the beast 2.07
Thenks
tataye
Yes, I have some hosting problems.

Beast 2.07 download here
netxman
I used avdevil to edit the server.exe but failed.

I used more than twenty packers or encrypors to anti McAfee & Kaspersky but failed too.

I want to cry. sad.gif
michael
thx m8
tried it and works fine...1 question tho
it wont work on some servers...any idea why not ??
firewall perhaps

c:\winnt\system32 <--- most work
c:\windows\system32 <--- some probs with it
m1k4c
hmm, i tested this version on myself ofc, and bugs they claimed to be repaired r still there. Hard not to get noticed, ill never use it :/
tataye
QUOTE(michael @ Oct 15 2004, 12:09 AM)
thx m8
tried it and works fine...1 question tho
it wont work on some servers...any idea why not ??
AVs are detecting it...

QUOTE
c:\winnt\system32 <--- most work
c:\windows\system32 <--- some probs with it
*

There isn't any problem with the <system> path.

QUOTE
hmm, i tested this version on myself ofc, and bugs they claimed to be repaired r still there. Hard not to get noticed, ill never use it :/
ROFL, this is the guy who said that Optix corrupted all exes on ChasenetBoard and was hyping ProRat rolleyes.gif What can I say, I'm devastated you'll never use it. Thx.

@all: BeastDoor will be back up today, see u there smile.gif
caboosetheblue
Nicely Done! Thanks Tataye laugh.gif
chris105
Your better off with going for a less well know one. AV are all over this one even if its morphined sad.gif
Progressor
When I launch the server, it starts listening on many ports, instead of one which I set in options. Actually it starts listening on almost all ports up to 5000. Is this a bug or am I doing something wrong?

BTW, there is absolutely no problem in making server undetectable to all AVs. Just use your brain, guys.
tataye
QUOTE(Progressor @ Oct 19 2004, 12:52 PM)
When I launch the server, it starts listening on many ports, instead of one which I set in options. Actually it starts listening on almost all ports up to 5000. Is this a bug or am I doing something wrong?
There's something wrong. Give me please more details: OS, server type, config.

QUOTE
BTW, there is absolutely no problem in making server undetectable to all AVs. Just use your brain, guys.
*
Very helpful idea, lol.
Progressor
QUOTE(tataye @ Oct 19 2004, 02:28 PM)
QUOTE(Progressor @ Oct 19 2004, 12:52 PM)
When I launch the server, it starts listening on many ports, instead of one which I set in options. Actually it starts listening on almost all ports up to 5000. Is this a bug or am I doing something wrong?
There's something wrong. Give me please more details: OS, server type, config.



OS: Windows 2000 or XP
Server type: Direct connection, no injection, port 7000, icq and email notifications are on. All types of startup enabled, no killing of AVs...

Neoankt
Seems you have to pay a hefty amount for the source
origa
I know something about making server undetectable, but I have problems with BeastDoor...so if someone can tell me how to change asm code with one hex editor....!!?? Plz, help me!!

Thx
cool_one
don't worry beast don't work. when it inject to explorer.exe it just jacks off and does nothing in SIN mode
tataye
QUOTE(Progressor @ Oct 21 2004, 12:17 AM)
QUOTE(tataye @ Oct 19 2004, 02:28 PM)
QUOTE(Progressor @ Oct 19 2004, 12:52 PM)
When I launch the server, it starts listening on many ports, instead of one which I set in options. Actually it starts listening on almost all ports up to 5000. Is this a bug or am I doing something wrong?
There's something wrong. Give me please more details: OS, server type, config.



OS: Windows 2000 or XP
Server type: Direct connection, no injection, port 7000, icq and email notifications are on. All types of startup enabled, no killing of AVs...
*

Sorry for the late reply. Very weird what happens to you. So you encountered that behavior on more systemss (2k, XP)? You are the only one who reported something like that. Did you test the server on yourself? Everytime you tested the server you see on the netstat the server is listenning on all those ports? I really don't know what could be :/

QUOTE
don't worry beast don't work. when it inject to explorer.exe it just jacks off and does nothing in SIN mode
shit, really? cool_one, i think you ain't cool enough
cool_one
oh your cool tataye, at least i know what i'm doing when i write a piece of code lamer.
tataye
QUOTE(cool_one @ Nov 20 2004, 04:56 AM)
oh your cool tataye, at least i know what i'm doing when i write a piece of code lamer.
*

your work is very impressive, keep it up smile.gif
ROFL
esteem
ROFL
tataye
News:

2 new domains were associated, so right now BeastDoor can be found at /http://beastdoor.org and /http://beastdoor.net

-tty
beardednose
Let's be nice. Don't start attacking each other or you'll face the conseq's.
tataye
QUOTE(beardednose @ Dec 17 2004, 06:41 PM)
Let's be nice. Don't start attacking each other or you'll face the conseq's.
*

1st, your reply is pretty late
2nd, I see only 1 attack
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.