hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

tibbar
My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.

The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure: C:\WINNT\microsoftdrivers\etc\.

This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.

Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.

I found the xdcc channel, which had another 30 or so bots inside.

I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).

Now for the funny bit. After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.

Needless to say, overnight the room lost all its bots (i wont say where they live now).

The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).
saetji
y didn't u just set up a sniffer on ur comp and wait for the person to logon? You couldve gotten the pass that much easier wink.gif
TheAngel
QUOTE (saetji @ Feb 18 2004, 12:46 PM)
y didn't u just set up a sniffer on ur comp and wait for the person to logon? You couldve gotten the pass that much easier wink.gif

damn man, an hitler's avatar?
man thats too much
hitler is a sick guy
and also the ppl who think that he did good things to germany
(filtered) Hitler!
Thom
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever
BOMBARDiER
TheAngel is right.. ohmy.gif
Gotisch
isn't the avatar half hitler half bush ?
cram
Lol, sure. So can you explain us how did you bruteforce those MD5 Serv-U's hashes sooo fast? And how did you know ServU's MD5 salt format? biggrin.gif
Gotisch
MAybe it was serv-u 2.5 huh.gif
dr0zaxx
HAHA! Stealing XDCC Bots from people! You thief! I better keep a lookout for you in future! tongue.gif
EXPLOiTED
What packet sniffer did u use to setup on teir comp...
Double-=V=-
QUOTE (Thom @ Feb 18 2004, 01:31 PM)
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever

A hitler avatar means you're a nazi. Seriously there is no other conclusion, a normal person wouldn't joke about such things.
FiNaLBeTa
QUOTE (Double-=V=- @ Feb 18 2004, 05:24 PM)
QUOTE (Thom @ Feb 18 2004, 01:31 PM)
Ah man(theangel) dont take it that serious, a hitler avatar does not mean he is a nazi or whatsoever

A hitler avatar means you're a nazi. Seriously there is no other conclusion, a normal person wouldn't joke about such things.

Welcome to the internet.

free speach remember. No mather what it is, so stfu
int23h
please note that it is half hitler half bush so don't worry
jockel
QUOTE (dr0zaxx @ Feb 18 2004, 03:41 PM)
HAHA! Stealing XDCC Bots from people! You thief! I better keep a lookout for you in future!  tongue.gif

thief ??

i don't think he is the thief ..
the h4x0r was the thief who stole traffic from other people by installing irc bots on their boxes ...

and by the way i as an german am pissed off by nazi's too,
but i think this avatar isn't meant to glorify nazis..
i think it's meant in a way like .. compare hitler with bush ...
hey bush didn't kill millions of jews ..
but they both started war ....
think about it ..
but to get back to topic .. =)
nice trick =)
phaeton
Wtf!? A hitler avatar means you are nazi? Way to be narrowminded. Maybe he dislikes the Bush government and is trying to show his dislike. Maybe he's trying to be funny (I had a chuckle at it). Lighten the (filtered) up people.

Btw, to get the MD5 hash format just search this forum, its been discussed (2 letter then MD5 hash).
JDog45
QUOTE (tibbar @ Feb 18 2004, 12:37 PM)
My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.

The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure: C:\WINNT\microsoftdrivers\etc\.

This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.

Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.

I found the xdcc channel, which had another 30 or so bots inside.

I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).

Now for the funny bit. After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.

Needless to say, overnight the room lost all its bots (i wont say where they live now).

The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).

I recently had to reformat my PC and when browsing IRC I came across adsbegone or something similar to. It was about 4.7MB. I downloaded it and ran it. Nothing happened. That's when the flag went up.

Sure enough it was a root kit and made the same directory you were talking about with the same items.
Warlord_David
QUOTE (tibbar @ Feb 18 2004, 12:37 PM)
My honeypot got "r00ted" yesterday, and turned into a serv-u / iroffer drone.

The install kit used was quite interesting, it made a folder WINNT (my windows folder is \WINDOWS) on root, which was hidden from windows (had to dameware to it), and inside this was the following structure:  C:\WINNT\microsoftdrivers\etc\.

This contained the usual stuff like firedaemon, serv-u, iroffer and some scripts to secure the box.

Anyway, interestingly, it did not make a my.config file for iroffer, so to trace it, i just used a packet sniffer.

I found the xdcc channel, which had another 30 or so bots inside.

I then started brute forcing the servudaemon.ini hashes (it set up full execute priv accoutn on root c).

Now for the funny bit.  After resolving all the xdcc bot's ip addresses, it turns out they all use same autoroot install kit, and hence the same serv-u pwds.

Needless to say, overnight the room lost all its bots (i wont say where they live now).

The moral of this story, secure your pubstros properly, and dont use identical pwds on all (and avoid execute priv in servu).

HAHAHHA i actually know what that came from. It's from a so called "pop-up killer" called Abdolish. The asses setup a firedaemon, iroffer, and serv-u services.

err didnt see jdogs post tongue.gif
tibbar
heh, if im evil, what does that make the guy who fell for my honeypot (apart from stupid).

anyway, in case anyone here has been "rooted" (it annoys me this kiddie term being used for non rootkits), here's the install script and hence the services to kill:

@echo off
regedit /s fire.reg

SET MXHOME=c:\winnt\microsoftdrivers\etc\

SET MXBIN=c:\winnt\microsoftdrivers\etc\

FireDaemon -i ftp.xml
FireDaemon -i irof.xml
FireDaemon -i secure.xml
FireDaemon -i rserv.xml


net start indexing

net start wlogin

net start DNS

net start network

del c:\TEMP\install.bat
del c:\TEMP\help.exe
del c:\TEMP\hideapp.exe


@EXIT


i.e. simply stop indexing, wlogin, DNS and network to stop the pubstro installation.

(isn't it nice of the kiddies to leave me a uninstall guide).

The only bit of the 'kit' which surprised me, was the iroffer config has been patched to the .exe - i.e. no my.config file.

Anyways, my view is that there's nothing wrong with "stealing" other ppls bots, if they are too stupid to secure them.
Zekk
: 0 thats cool
Player
how would someone make their xdcc channel bot secure? i'm just curious
tibbar
well, had they not given execute rights to serv-u, i wouldnt have been able to steal them.
saetji
yes u could - if the account was system admin, u couldve connected to the bots ftp via serv-u software and changed ur priv to +exec
saetji
btw - this is hitler 2! not hitler - its george MONKEY bush dressed up as hitler and demanding oil! i am not a nazi and have no contacs with germany
arun0075
lol saetji dude are u the same from apna. are u the one who is king of apna smile.gif
if u are then i have heard a lot abt u hmmm.. nothing bad all good that u are a good programer and stuffs u got it naa hehe smile.gif
MattMannLT
QUOTE (tibbar @ Feb 18 2004, 11:33 PM)

The only bit of the 'kit' which surprised me, was the iroffer config has been patched to the .exe - i.e. no my.config file.

not so true he didn't patch anything all he did was change the file extension as long as the config file is written in NotePad (i dont know the exact term for the language but you get the point) you can change the file extension to anything you want and still be able to have iroffer read it.

you should open every file under about 100K up in notepad one of them will be the config file tongue.gif
D0cSyS
i am sorry saetji but if you are an american and proud of your country please get ride of that lame avatar, no matter if it's 2 fag halves. I am proud of my country the UNITED STATES OF AMERICA and you offend me by just having that icon.

You have the freedom i can't stop you but if you feel like rocking that avatar go to germany or some other country.


back on topic. That's nice you took his/her bots away now what are you going to do with them install ur own pack?

The rooter was using a very simple pack. When i was doing all of that stuff the only way u would be able to get any info on what was going on would be to use a sniffer like you did but it would of been hard for you to find all directories, pass the dummy 10 serv-u's, anal ftps, raidens, and get passed the ssl password protected irc server which binds to a real server once authenticated.

ahhh the fun i had.

I just feel bad i lost a 5000 botnet do to a dumb ass move in the dns assignments.
so nobody is perfect. this guy made the mistake of using a very simple rootpack.

btw: what exploit did he gain access threw
Black Flag
damn lol... just cause your american doesn't mean you have to be proud-or move to germany. keep your closed-minded comments to yourself and let him express his hate for bush tongue.gif as do i. he can't even eat a pretzel that damn retard *laughs*

back to topic:

what did you set up your honeypot as? or did you just leave your computer in the open.
tonikgin
serv-u uses an MD5 encryption for it's passwords stored in the ini file, it would had taken you somewhere around a few hundrend thousand years to brute force it using a typical pc. you didnt get the serv-u password, maybe the iroffer password, which only used DES encrpytion and can be cracked using very old school programs.
tibbar
lmao, someone here doesnt know about dictionary attacks on hashes, and had i been less lucky, and met a strong password, I would have simply downloaded a set of rainbow tables and still have found the password in under a few hours.

The honey pot setup was VMWare, running XP without SP1 and using default admin password.

oh and can we PLEASE get back on the topic of security and stop this stupid flame war.

I find this remark implicitly racist: "feel like rocking that avatar go to germany ". He would not be welcome in Germany either, this comment implies Nazi's are currently supported in Germany which is total F*CK*NG S*IT ok.
DiJiTooL
good job tibbar, very funny tongue.gif
tonikgin
99% of the people on this website are complete morons, this place is a haven for bored kids that dont know shit about security, and looking for a ./ or .exe to do the work for them.
tibbar
that's a pretty hash comment.

a lot of newbees have joined since the forum opened again, but there are many extremely experienced security experts here.

if you dont like it, go else where.
syiron
anybody can give me that honeyport i want to try steal xdcc bot.
phaeton
hmmm he said what he wrote. do you read the entire thread before posting? also, search on google (if it is within your knowledge how to) on honeypots.
Thom
syiron he just wrote on page 2 that he was using VMWare, on xp without sp1.... www.google.com.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.