My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.
The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure: C:\WINNT\microsoftdrivers\etc\.
This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.
Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.
I found the xdcc channel, which had another 30 or so bots inside.
I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).
Now for the funny bit. After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.
Needless to say, overnight the room lost all its bots (i wont say where they live now).
The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).
saetji
Feb 18 2004, 12:46 PM
y didn't u just set up a sniffer on ur comp and wait for the person to logon? You couldve gotten the pass that much easier
TheAngel
Feb 18 2004, 12:59 PM
QUOTE (saetji @ Feb 18 2004, 12:46 PM)
y didn't u just set up a sniffer on ur comp and wait for the person to logon? You couldve gotten the pass that much easier
damn man, an hitler's avatar? man thats too much hitler is a sick guy and also the ppl who think that he did good things to germany (filtered) Hitler!
Thom
Feb 18 2004, 01:31 PM
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever
BOMBARDiER
Feb 18 2004, 03:02 PM
TheAngel is right..
Gotisch
Feb 18 2004, 03:24 PM
isn't the avatar half hitler half bush ?
cram
Feb 18 2004, 03:30 PM
Lol, sure. So can you explain us how did you bruteforce those MD5 Serv-U's hashes sooo fast? And how did you know ServU's MD5 salt format?
Gotisch
Feb 18 2004, 03:40 PM
MAybe it was serv-u 2.5
dr0zaxx
Feb 18 2004, 03:41 PM
HAHA! Stealing XDCC Bots from people! You thief! I better keep a lookout for you in future!
EXPLOiTED
Feb 18 2004, 04:14 PM
What packet sniffer did u use to setup on teir comp...
Double-=V=-
Feb 18 2004, 05:24 PM
QUOTE (Thom @ Feb 18 2004, 01:31 PM)
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever
A hitler avatar means you're a nazi. Seriously there is no other conclusion, a normal person wouldn't joke about such things.
FiNaLBeTa
Feb 18 2004, 05:55 PM
QUOTE (Double-=V=- @ Feb 18 2004, 05:24 PM)
QUOTE (Thom @ Feb 18 2004, 01:31 PM)
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever
A hitler avatar means you're a nazi. Seriously there is no other conclusion, a normal person wouldn't joke about such things.
Welcome to the internet.
free speach remember. No mather what it is, so stfu
int23h
Feb 18 2004, 06:23 PM
please note that it is half hitler half bush so don't worry
jockel
Feb 18 2004, 06:31 PM
QUOTE (dr0zaxx @ Feb 18 2004, 03:41 PM)
HAHA! Stealing XDCC Bots from people! You thief! I better keep a lookout for you in future!
thief ??
i don't think he is the thief .. the h4x0r was the thief who stole traffic from other people by installing irc bots on their boxes ...
and by the way i as an german am pissed off by nazi's too, but i think this avatar isn't meant to glorify nazis.. i think it's meant in a way like .. compare hitler with bush ... hey bush didn't kill millions of jews .. but they both started war .... think about it .. but to get back to topic .. =) nice trick =)
phaeton
Feb 18 2004, 07:28 PM
Wtf!? A hitler avatar means you are nazi? Way to be narrowminded. Maybe he dislikes the Bush government and is trying to show his dislike. Maybe he's trying to be funny (I had a chuckle at it). Lighten the (filtered) up people.
Btw, to get the MD5 hash format just search this forum, its been discussed (2 letter then MD5 hash).
JDog45
Feb 18 2004, 08:42 PM
QUOTE (tibbar @ Feb 18 2004, 12:37 PM)
My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.
The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure: C:\WINNT\microsoftdrivers\etc\.
This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.
Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.
I found the xdcc channel, which had another 30 or so bots inside.
I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).
Now for the funny bit. After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.
Needless to say, overnight the room lost all its bots (i wont say where they live now).
The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).
I recently had to reformat my PC and when browsing IRC I came across adsbegone or something similar to. It was about 4.7MB. I downloaded it and ran it. Nothing happened. That's when the flag went up.
Sure enough it was a root kit and made the same directory you were talking about with the same items.
Warlord_David
Feb 18 2004, 09:27 PM
QUOTE (tibbar @ Feb 18 2004, 12:37 PM)
My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.
The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure: C:\WINNT\microsoftdrivers\etc\.
This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.
Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.
I found the xdcc channel, which had another 30 or so bots inside.
I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).
Now for the funny bit. After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.
Needless to say, overnight the room lost all its bots (i wont say where they live now).
The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).
HAHAHHA i actually know what that came from. It's from a so called "pop-up killer" called Abdolish. The asses setup a firedaemon, iroffer, and serv-u services.
err didnt see jdogs post
tibbar
Feb 18 2004, 11:33 PM
heh, if im evil, what does that make the guy who fell for my honeypot (apart from stupid).
anyway, in case anyone here has been "rooted" (it annoys me this kiddie term being used for non rootkits), here's the install script and hence the services to kill:
del c:\TEMP\install.bat del c:\TEMP\help.exe del c:\TEMP\hideapp.exe
@EXIT
i.e. simply stop indexing, wlogin, DNS and network to stop the pubstro installation.
(isn't it nice of the kiddies to leave me a uninstall guide).
The only bit of the 'kit' which surprised me, was the iroffer config has been patched to the .exe - i.e. no my.config file.
Anyways, my view is that there's nothing wrong with "stealing" other ppls bots, if they are too stupid to secure them.
Zekk
Feb 19 2004, 12:41 AM
: 0 thats cool
Player
Feb 19 2004, 01:21 AM
how would someone make their xdcc channel bot secure? i'm just curious
tibbar
Feb 19 2004, 01:43 AM
well, had they not given execute rights to serv-u, i wouldnt have been able to steal them.
saetji
Feb 19 2004, 01:46 AM
yes u could - if the account was system admin, u couldve connected to the bots ftp via serv-u software and changed ur priv to +exec
saetji
Feb 19 2004, 02:06 AM
btw - this is hitler 2! not hitler - its george MONKEY bush dressed up as hitler and demanding oil! i am not a nazi and have no contacs with germany
arun0075
Feb 19 2004, 02:26 AM
lol saetji dude are u the same from apna. are u the one who is king of apna if u are then i have heard a lot abt u hmmm.. nothing bad all good that u are a good programer and stuffs u got it naa hehe
MattMannLT
Feb 19 2004, 03:00 AM
QUOTE (tibbar @ Feb 18 2004, 11:33 PM)
The only bit of the 'kit' which surprised me, was the iroffer config has been patched to the .exe - i.e. no my.config file.
not so true he didn't patch anything all he did was change the file extension as long as the config file is written in NotePad (i dont know the exact term for the language but you get the point) you can change the file extension to anything you want and still be able to have iroffer read it.
you should open every file under about 100K up in notepad one of them will be the config file
D0cSyS
Feb 19 2004, 04:02 AM
i am sorry saetji but if you are an american and proud of your country please get ride of that lame avatar, no matter if it's 2 fag halves. I am proud of my country the UNITED STATES OF AMERICA and you offend me by just having that icon.
You have the freedom i can't stop you but if you feel like rocking that avatar go to germany or some other country.
back on topic. That's nice you took his/her bots away now what are you going to do with them install ur own pack?
The rooter was using a very simple pack. When i was doing all of that stuff the only way u would be able to get any info on what was going on would be to use a sniffer like you did but it would of been hard for you to find all directories, pass the dummy 10 serv-u's, anal ftps, raidens, and get passed the ssl password protected irc server which binds to a real server once authenticated.
ahhh the fun i had.
I just feel bad i lost a 5000 botnet do to a dumb ass move in the dns assignments. so nobody is perfect. this guy made the mistake of using a very simple rootpack.
btw: what exploit did he gain access threw
Black Flag
Feb 19 2004, 04:36 AM
damn lol... just cause your american doesn't mean you have to be proud-or move to germany. keep your closed-minded comments to yourself and let him express his hate for bush as do i. he can't even eat a pretzel that damn retard *laughs*
back to topic:
what did you set up your honeypot as? or did you just leave your computer in the open.
tonikgin
Feb 19 2004, 05:04 AM
serv-u uses an MD5 encryption for it's passwords stored in the ini file, it would had taken you somewhere around a few hundrend thousand years to brute force it using a typical pc. you didnt get the serv-u password, maybe the iroffer password, which only used DES encrpytion and can be cracked using very old school programs.
tibbar
Feb 19 2004, 09:09 AM
lmao, someone here doesnt know about dictionary attacks on hashes, and had i been less lucky, and met a strong password, I would have simply downloaded a set of rainbow tables and still have found the password in under a few hours.
The honey pot setup was VMWare, running XP without SP1 and using default admin password.
oh and can we PLEASE get back on the topic of security and stop this stupid flame war.
I find this remark implicitly racist: "feel like rocking that avatar go to germany ". He would not be welcome in Germany either, this comment implies Nazi's are currently supported in Germany which is total F*CK*NG S*IT ok.
DiJiTooL
Feb 19 2004, 11:53 AM
good job tibbar, very funny
tonikgin
Feb 19 2004, 08:27 PM
99% of the people on this website are complete morons, this place is a haven for bored kids that dont know shit about security, and looking for a ./ or .exe to do the work for them.
tibbar
Feb 20 2004, 01:27 AM
that's a pretty hash comment.
a lot of newbees have joined since the forum opened again, but there are many extremely experienced security experts here.
if you dont like it, go else where.
syiron
Feb 20 2004, 04:23 AM
anybody can give me that honeyport i want to try steal xdcc bot.
phaeton
Feb 20 2004, 04:35 AM
hmmm he said what he wrote. do you read the entire thread before posting? also, search on google (if it is within your knowledge how to) on honeypots.
Thom
Feb 20 2004, 10:26 AM
syiron he just wrote on page 2 that he was using VMWare, on xp without sp1.... www.google.com.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.