hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Port 20168?
Feanor
have seen this posted somewhere else:
CODE
Hey guys scan port 20168 its a new hole and its wery good!!

Greetz

you checking them witch program scanline or SL.exe(ist the same program) and you need to type

sl.exe -bhpt 20168 -f scan.txt -o vulnerable.txt

And then you got something like this!!!

PATH: -------------------------------------------------------------------------------
*.*.*.*
Responds with ICMP unreachable: No
TCP ports: 20168


TCP 20168:
[Microsoft Windows 2000 [Version 5.00.2195] (C) Copyright 1985-1999 Microsoft Corp. C:\WINNT\system32>]

if there is Windows XP its good to!!!



Anybody knows something about that? This one sounds really interesting, and looks that there is no need to exploit it, cause this gives shell immidiately.

So, anybody knows something more?
I'm going to scan it, will be back when have some results.
philipnorth
hmm
sounds interesting, but am curious whats behind it (what exploit etc)

Would like to see some more info on it

quick search gave me this:

http://securityresponse.symantec.com/avcen...vgate.j@mm.html

old worm
ducky
http://securityresponse.symantec.com/avcen...vgate.j@mm.html

It's some worm...
more info in that URL i gave smile.gif
jockel
yeah it's the lovegate worm

http://www.rz.uni-karlsruhe.de/Uni/RZ/Netz...V_LovgateI.html
philipnorth
LOL

well that settles it smile.gif
it's a worm biggrin.gif

an old one even.
Feanor
a worm is bummer, cause AV's will propably detect it.

Although if AV does not detect Lovegate, then it will not detect my stuff *evil smile*
jead99
Did anyone try this with any luck?
mdk
Some of my "friends" playd around with this.
Scanned for open Port and tryt to connect via nc... But only some US Server seemed to be infected. So don't know if it is good.
Leonnetje
This is NOT an exploit, cause you need no tools for this 'virus'

You scan on port 20168 and check the scans like mentioned in the start-posting.

then you simply connect to that IP with telnet...

It's NOT a new exploit, it's old (september 2003) and it's called after the virusses name --> LoveGate.
Pgame
old but very interesting... wink.gif
Alien
this is virus ;] to connect use netcat:

nc -vv IP 20168
MysteryMan
yep lovesun roxxxxx.....

hax hax hax ....

very good hole biggrin.gif
WaZa
i used this a while ago and i remember rooting quite a few servers with this, but now its pretty much useless. it has very low odds
oYost
Huh, this worm is a benediction for us, very nice smile.gif
adenek
looks really great thx for the info m8
mathofaka
blink.gif blink.gif i tried it and no luck i think its too old or maybe im doing it wrong


[QUOTE]Technology is dominated by two types of people: those who understand what they do not manage, and those who manage what they do not understand. ph34r.gif
t00sTr0nG
i have tested it yesterday and get 2 shells of !
I connect with telnet and it works fine biggrin.gif

THX
t00sTr0nG
jeroen
it's not new anymore, knew like 2 weeks ago. Not much results with it anymore.

Greetz, Jeroen
Feanor
I've found many results with it.

And 99% of them gave shell.
Alien
here is scanline

http://www.foundstone.com/resources/freetools/scanline.zip? PHPSESSID=4a36e39e7ce238c7d58fde8f39eef5cc
Planquadrat
yes it's works , but ... i don't think that's so possible to scan for it. i've testing this hole over one week and i got lots of results with shell but the most of them were not faster than 2-3 mbit about 80% of my results were simple ADSL lines and home PCs. if you're happy with hacking adsl lines than try it. but tell me if i'm wrong

good luck
Acid-Burn
ok M8
i will try
jeroen
QUOTE (Planquadrat @ Feb 16 2004, 06:54 PM)
yes it's works , but ... i don't think that's so possible to scan for it. i've testing this hole over one week and i got lots of results with shell but the most of them were not faster than 2-3 mbit about 80% of my results were simple ADSL lines and home PCs. if you're happy with hacking adsl lines than try it. but tell me if i'm wrong

good luck

Lol..that's becoz you too late. Two weeks ago already did a lot with it and yes I did did have some 100 mbit with it. If you connect with telnet now and it says winsock ready, then it could be mine tongue.gif

Gr, Jeroen
firefox
haha
now i don't scan ipc$,i can 20168! laugh.gif
adenek
I have test it but don't find 20168 open port
Acid-Burn
i found some but just adsl
fre4k
what is that? biggrin.gif

CODE
C:\>nc.exe -vv 69.12.81.13 20168
69.12.81.13: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [69.12.81.13] 20168 (?) open


       RPC-3 Telnet Host
   Revision F 5.01, (C) 2001
   Bay Technical Associates
   Unit ID: Chicago-69-12-81-13

   Enter username>



You can try it also!

/edit:

Or That shit ;D

CODE
C:\>nc.exe -vv 69.18.40.14 20168
69.18.40.14: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [69.18.40.14] 20168 (?) open


       RPC-3 Telnet Host
   Revision F 2.00, (C) 1997
   Bay Technical Associates
   Unit ID: BURL-RPC-1

   RPC-3 Menu:

     1)...Outlet Control
     2)...Configuration
     3)...Unit Status
     4)...Reset Unit
     5)...Logout

   Enter Selection:


But when I enter something it kick me......... mad.gif

-fre4k
D3ADLiN3
lol thats not the shell your ment to get, looks like some sort of adsl/cable router console
fre4k
I DON´T think it is a shell LOL biggrin.gif
wizy
That RPC-3 telnet console is a power management system. For controlling big UPS's like for entire racks at colocation facilities, or something else along that size.
D3ADLiN3
QUOTE (fre4k @ Feb 18 2004, 12:04 PM)
I DON´T think it is a shell LOL biggrin.gif

shell command prompt same thing wink.gif
jeroen
QUOTE (fre4k @ Feb 17 2004, 08:26 PM)
what is that? biggrin.gif

CODE
C:\>nc.exe -vv 69.12.81.13 20168
69.12.81.13: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [69.12.81.13] 20168 (?) open


       RPC-3 Telnet Host
   Revision F 5.01, (C) 2001
   Bay Technical Associates
   Unit ID: Chicago-69-12-81-13

   Enter username>



You can try it also!

/edit:

Or That shit ;D

CODE
C:\>nc.exe -vv 69.18.40.14 20168
69.18.40.14: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [69.18.40.14] 20168 (?) open


       RPC-3 Telnet Host
   Revision F 2.00, (C) 1997
   Bay Technical Associates
   Unit ID: BURL-RPC-1

   RPC-3 Menu:

     1)...Outlet Control
     2)...Configuration
     3)...Unit Status
     4)...Reset Unit
     5)...Logout

   Enter Selection:


But when I enter something it kick me......... mad.gif

-fre4k

probaly someone hacked trhe server already and started this service on port 20168 so you won't get shell anymore tongue.gif
Steffan
I found a lot of these !!!! Be careful !!!

After I test several Hosts/Ports it was listening on ALL PORTS !!!!
(so port 80 110 139 8181 9191 all the same shit....)

so from my point of view it could be a honeypot too... I not check further... unsure.gif

may someone knows more... unsure.gif

C'ya
Steven
Pro21
hehe shell Work but not lot of smile.gif
and much script kiddies use this port tongue.gif
SuRFieR
hey
now i can understand why pplz scanned my computer for this port
lol
thnkx u guys
now i'll be the one who do da scan not only the one got scanned
biggrin.gif
SuRFieR
i scanned mah friend's computer and i got this message in file called vulnerable.txt
QUOTE

Scan of 1 IP started at Thu Feb 19 07:08:40 2004

-------------------------------------------------------------------------------

Scan finished at Thu Feb 19 07:08:46 2004

what does this mean?
huh.gif
DrDoc
LOL nice question.. hmm that means (at the first line) You have started to scan one IP @ Thu Feb 19 07:08:40 2004

this line means Nothing biggrin.gif

-------------------------------------------------------------------------------

but now a very very very important line

Scan finished at Thu Feb 19 07:08:46 2004

YES your scanner is done to scan your ONE IP tongue.gif

And the Scanner found nothing.. sad.gif ohmy.gif

Thinking before asking because

Cya Doc.

OKOK My english is not perfect.. but i have to answer of this st... question wink.gif *sorry* smile.gif
SuRFieR
lol
thnkz Dr
i asked myself if the scanner will till if this port is open or not
so
i asked u in the forum
i know what every line means but i just needed to know if the scanner have to tell me any more infos about this port like if this port is open or not
that's all
thnkx again for ur help
peace
smile.gif
dongfangshuo
it's very cool
but the shell is not very perfect
such as in the c:\winnt\system32 can't excute regedit
if you want you must change to c:\winnt
smitterz
haven't found any server yet still exploitable on port 20168.. maybe more luck in the future but not yet..
dongfangshuo
i found most victim in our university's lan
MysteryMan
i found very much ip in my cable :] ...
but we have slow connection so i dont hack them smile.gif ...

lovesun is very good hole and easy to learn smile.gif
try mayby you will success :]
Erra
This one is mostly only on Dynamic IP accounts or slow broadband accounts now. Not much use really.
Feanor
Now, i have found a few good server with 10-50 Mbit.

They are rare, but all other vulns too usually give you slow servers.
arn0ld
edited :
my mistake the lsass just moved to another port and i can't find the lovegate.worm ... ? wink.gif

edited:

kk found it it's called FixlGate.com / FixlGate.exe
(by Symantec)
ducky
the only thing i get is :

CODE
x.x.x.x: inverse host lookup failed: h_errno 11004: NO_DATA
(UNKNOWN) [x.x.x.x] 20168 (?) open


and can't do nothing with it... unsure.gif
cjsarette
ducky, you can't do anything withit cause that one wont work.

Just keep scanning and then check them like in the first thread, you'll only get a shell if it comes up with C:\WINNT\system32 orC:\WINDOWS\system32

This virus is still working for me tongue.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.