hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

THoRaX
easy to use wink.gif
as soon as i get the 1.4 versaion with diffirent offset's i'll use that one wink.gif
haven't tested it totally, but i guess it will work smile.gif
if there are any bugs, PM me

you can chose if you want a reverse shell or a bind shell, and what offset you want to use

1 download= 1 reply
i know this won't happen, but the one that have the respect, thanks wink.gif
PacMan03
I think you are supposed to scan for port 1023 not port 5554
shii
lol is it port 1 or 65335 to scan for ?


laugh.gif
BeNiNuK
this and the 1.4 has allready been posted , about 4000 times and its getting annoying NOW
THoRaX
QUOTE (PacMan03 @ May 10 2004, 09:39 PM)
I think you are supposed to scan for port 1023 not port 5554

you have to scan port 5554.. (atleast i did.. and i had pretty much shells)

caca
thanks you very much it's a good work tongue.gif;)
toska
Thanks mate!
toska
I scan port port 5554 mostly but you can also scan 1023 which for variant of the sasser worm
Milka
hmmz lemme take a look at this one, is it not the same as the other one?
ducky
thanks m8 good work gonna test my local with this one smile.gif
jead99
Thanks for sharing your tools with the community m8, good work smile.gif
Mouse
cool smile.gif

nice work biggrin.gif

rscience
grate work i will take this.
soundslider
thx, 4 work.

perhaps i might have more luck with this
Ecko
hi nice work...it's now a bit easier then before thx!
SecureD
tnx m8 will check it out
Sinister
tks m8 will give it a try wink.gif
The Storm
thank ya gonna test it!
warzoux
thx for that very useful smile.gif
Helloman
Boar yeah thats nice big thx
hidden
thx ok for try it
SuperG
Thanks for your contribution ! Will have a look at that.
F34R
Thanks for the autohacker. Hopefully it'll work... seems as if this sploit is kinda dead... or n00bed rather tongue.gif Nonetheless, I'll try.
DaywalkerX
Thanks for the autohaxor.I will test it biggrin.gif
ctv
thank you wink.gif
LiquidIce
thnx for this works perfect wink.gif
sattete
thx
sattete
smile.gif thx 2 times
F34R
QUOTE (sattete @ May 12 2004, 09:49 AM)
thx

Better watch tiny posts like that. Could get yourself reset.
Just a warning. And dont post 2 meaningless posts like that. 1 well thought out one will do.
Rtyp3
nice work !! ;-)
elbarto95
sound good thank you for the public sharing

rgds

elbarto
chaos.comt
nice work ... keep it on ;-)
Thebox
IŽll try it. Many thanks
Nexcess
auto'hackers' are such crap, if you cant be bothered to work on one system at a time you shouldnt even be allowed to use the exploit. dry.gif
tonikgin
^^^ this is true. however, many people use them in conjunction w/ scannets, to search for vulnerable machines faster, and get them before someone else might.

however, most of the autohackers on this site are not actual autohackers (those from back in the day), and just people using scripting languages to create a very havoc process.
pollux
thx i will test ph34r.gif
xoro
Hi !

it don't works for me .... sad.gif
Certox
securing this... ?? Anyone know...
brOmstar
removing sasser? lol what a question
Certox
I meant close the ports or something, to make it not expoiltable
brOmstar
ur funny why close ports if can remove the reason for the open ports ?

you can install a firewall on port 1023 or 5554 but why should u do this remove the damn worm and there is no exploitable ftpd...
Certox
ok... how? ... why is this so hard for u to understand? It sounds like u know what to do... so please tell us, we are here to learn.
brOmstar
[niceBoymodeOn]

Ok the program u r exploiting is the ftpd of sasser this is a worm that takes the lsass vuln to spread over the net(port 445)

This worm opens a ftpd on port 5554 sasser.a-e or port 1023 sasser.f so to 'secure' the vulnerability u have to remove this ftpd.

If u want to remove the ftpd u have to remove the worm - kill the task sasser is running.

Looking at some antivir-descriptions u will find out that the sasser-task calls mostly avserve.exe or avserve2.exe(sometimes other names but this is rare). Use some tool to view running tasks and kill this tasks.

At the end u have to modify the registry at -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run - remove the entry to the wormfile.

That's all.
[/niceBoymodeOn]

And if u don't know how to do that ..lol rolleyes.gif
Killaloop
lol how much fun it always is.
people downloading the l33t autohaxxers and then asking "what to scan", "how to secure".
thats for all of you:
maybe it would be a good think to read about the exploit and its vulnerability?
you would safe us all some time

[eatScriptkidModeON]
Certox
Thanks to he dude who explained it, the rest of u smartass little kidz can suck a c**k tongue.gif
Feanor
thanks for sharing this one, will be testing it for some days.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.