Ive heard of nc , winshell , and wolf ... anyone know which is best? i have tried nc but it wont passlock i did see a thread on nc with a password but just doesnt look great.. and one thats not detected by like av or something cuz wolf gets detected
Christian
Jan 19 2004, 01:07 AM
Im use Nc.
D0cSyS
Jan 19 2004, 05:00 AM
u looking for something to just get u a shell on the box or something more complex?
dmg
Jan 19 2004, 09:03 AM
Winshell is nice and configurable. It can be crypted by morphine (that's a big advantage for me).
Wollf is IMHO the best backdoor. Only problem is AntiVirus detection. Hex editing is needed to make it undetected by most AV.
As for nc.exe; who would install a backdoor without password protection? That is plain stupid if you ask me.
decline
Jan 19 2004, 10:22 AM
Why dont use a easy tool like radmin??
zero-maitimax
Jan 19 2004, 10:46 AM
these are the best i think
optixpro beast bionet
aTahualPa
Jan 19 2004, 12:15 PM
my favorite is shadow remote
aTa
BuzzDee
Jan 19 2004, 12:53 PM
yep shadow remote is gr8. thats also my favourite. the only thing which is really annoying is when u get error getting process list...
sub7, optix, ... have many functions and - if the server file is well encrypted - it cant be found by avs... so these backdoors are not that bad
greetz
Snatch
Jan 19 2004, 01:12 PM
QUOTE (BuzzDee @ Jan 19 2004, 12:53 PM)
yep shadow remote is gr8. thats also my favourite. the only thing which is really annoying is when u get error getting process list...
sub7, optix, ... have many functions and - if the server file is well encrypted - it cant be found by avs... so these backdoors are not that bad
greetz
Dito
Shadow is realy a great tool
GreeTz Snatch
Demoman
Jan 19 2004, 01:52 PM
I use radmin....It isn't a real backdoor, but i think thats a really great tool to observe the admin, you can transfer files and you can have a shell. Thats a very nice solution.
Greetz Demoman
Loxy
Jan 19 2004, 02:43 PM
I use an FTPd my bud Aphex coded, and allows exec (in case I need a shell) Installs as a system service on NT based OS, and doesn't display "FTP Server" as name, something more "hidden" ; ) It's very good imho.
silos
Jan 19 2004, 04:01 PM
PSEXEC is easier to use than NC i think.
Faceless Master
Jan 19 2004, 04:09 PM
I think the following are the best ones.
Lithium -Buy the newest server if you mean bussiness.
Y3k Pro (Great GUI + Trojan)
Regards ~Faceless Master
saetji
Jan 19 2004, 05:23 PM
i use 1)radmin 2) nc withpass protection
psexec u need ipc$ open which means that u cant secure the bot
LittleHacker
Jan 19 2004, 05:28 PM
I like NC the most too!
Sw0rdfish
Jan 19 2004, 06:01 PM
anyone knows a irc bassed backdoor?
TriHFH
Jan 20 2004, 12:38 AM
I use serv-u/WinShell/Optix Pro
FireAlwaysWorks
Jan 20 2004, 05:10 AM
I use my own code, it uses IRC btw. I like the added layer of anonymity as well as defeating NAT's and Proxies. If you are looking for one, I suggest netcat. AV's don't pick it up . As far as no pass goes, well you could always hide it in a high port or what I like to do is make it look like a system process . Anyway, well good luck. If you want an irc backdoor, I believe there is a butt-plug for B02k.
Peace
zero-maitimax
Jan 20 2004, 07:31 AM
QUOTE (Sw0rdfish @ Jan 19 2004, 06:01 PM)
anyone knows a irc bassed backdoor?
sdbot
Diablotic
Jan 20 2004, 07:49 AM
Umm I need sth undetected for AV. UPXing doesn't work. What do you suggest??!!
GhostCow
Jan 20 2004, 09:41 AM
id'e go with winshell. its small and highly configurable. with a upx or fsg + morphine combo, its really good. offers pass protection, file downloading, shutdown, restart, and remote uninstalling.
Svenno
Jan 20 2004, 04:06 PM
I use NC and don't got probs
billy1816
Jan 21 2004, 08:32 AM
I believe that sdbot is detected by av. I don't uses remtoe that much, but I think radmin is a stable one enough to play raound with.
Trojan^kid
Jan 22 2004, 11:04 PM
NRat 1.0 assasin 2
unknown00
Jan 23 2004, 12:53 AM
i use remote anything its kool...and jw anyone have link of shadow remote?
mRtWiStEr
Jan 23 2004, 12:54 PM
in my opinion nc is the beser
mfg tWisTa
MrRobot
Jan 25 2004, 06:01 AM
I'll have to say, the best of the cmd line tools is CryptCat. Its netcat but it use's encryption for data transmissions between host and target.
GUI: Dunno
flashb4ck
Jan 26 2004, 02:09 PM
i think netcat is the best solution
phaeton
Jan 28 2004, 01:27 AM
eternity from wineggdrop is the best imho, socks server, ddos, tcp redirector, dll injects itself and its tiny.
captainil
Jan 28 2004, 11:57 AM
wollf v1.6 is da best
Richie.666
Jan 31 2004, 09:55 PM
I use nc
nolimit
Jan 31 2004, 10:23 PM
Every non legit port open is more risk of discovery, I tend to try to use legit admin services as backdoors, such as termserv or ipc$. If you patch it right, ipc$ can be just as secure.
razeer
Feb 25 2004, 04:49 PM
Recub is great.
After the victim exec the server.. explorer.exe will be infected.
Just ping the victims and they will call back (great because can bypass firewalls)
results: command promt on victim machine.
Norton never alert if u can exec de server.
source code included..
THoRaX
Feb 25 2004, 05:08 PM
i was wollf, but in the process list it will show a wrm.exe, so it is pretty easy to see. now i am using netcat with password protection and it works good. i will try shadow remote now, because some here said that one is really good. So let's take a look!
sylver
Feb 25 2004, 11:25 PM
i dont know shadow remote ?anyone could tell me his experiences? wolf is cool-and also pass protected, and only some avīs detects it
cecrex
Feb 26 2004, 10:19 PM
QUOTE (THoRaX @ Feb 25 2004, 05:08 PM)
i was wollf, but in the process list it will show a wrm.exe, so it is pretty easy to see. now i am using netcat with password protection and it works good. i will try shadow remote now, because some here said that one is really good. So let's take a look!
you wanna tell me you didn't change the name of the file from 'wrm.exe' to some other name?
no wonder the admin will catch you..
3plx
Feb 27 2004, 05:39 AM
guyz i have a question how can irun nc.exe on port for example 666 that i can see th nc.exe working
how can i hide it i tired some things and it never worked for me so plz help me
white
Feb 27 2004, 02:55 PM
NC is the best ..
Joc00
Feb 27 2004, 03:15 PM
QUOTE (3plx @ Feb 27 2004, 05:39 AM)
guyz i have a question how can irun nc.exe on port for example 666 that i can see th nc.exe working
how can i hide it i tired some things and it never worked for me so plz help me
nc.exe -L -p 666 -t -d -e cmd.exe will run nc listening on port 666 hidden
prog
Feb 27 2004, 08:27 PM
I have found nc to be my best backup backdoor.
normally ill throw a mirc bot online that does all the remote commands. But incase that ever falls through I have nc open binded to cmd.exe
GhostCow
Feb 27 2004, 10:38 PM
nc is not for me... i use winshell... the problem with nc is that mostly it isnt pas protected...
Eldarion
Feb 27 2004, 10:45 PM
I use ProRAT/netcat/assasin 2...
prog
Feb 28 2004, 12:17 AM
I have been looking for a real good bat file that kills fw/av progs. I saw something like 450 but was unable to work it correctly from the instructions not translating correctly. Anyone know of one of these.
Normally after i get the mirc bot on there i kill the nc, theres no need for it. but ill keeep it there just incase i want the convenience.
Hawk12
Feb 28 2004, 12:44 AM
nc i think isn't good for me, my favourite is winshell you can configurate it easy and you can start many backdoors on one maschine
Trojan^kid
Feb 28 2004, 02:55 AM
NC ?? never used it cia 1.22b Beast 2.06 optix pro 1.32 are 3 of the best
prog
Feb 28 2004, 04:29 AM
It is a simple backdoor that opens a port to listen on. Allows you to bind itself to a file if wanted to. . .hint hint cmd.exe
NiteWorM
Feb 28 2004, 05:25 AM
i prefer winshell, u can download via the telnet all u got to do is enter in the url of the file u want to get downloaded from the box it gives u shell access and lots of other crazy stuff. its very small so it dont take alot of time to send across either via exploiting tftp or some other way and it gives u the feature to make it auto setup itself all u got to do is run the program
prog
Feb 28 2004, 05:57 AM
ehh, not really needed. I use custom bat files to do all my work. Sux tho sometimes it picks them up as virri.