easy to use as soon as i get the 1.4 versaion with diffirent offset's i'll use that one haven't tested it totally, but i guess it will work if there are any bugs, PM me
you can chose if you want a reverse shell or a bind shell, and what offset you want to use
1 download= 1 reply i know this won't happen, but the one that have the respect, thanks
PacMan03
May 10 2004, 09:39 PM
I think you are supposed to scan for port 1023 not port 5554
shii
May 10 2004, 09:40 PM
lol is it port 1 or 65335 to scan for ?
BeNiNuK
May 10 2004, 09:42 PM
this and the 1.4 has allready been posted , about 4000 times and its getting annoying NOW
THoRaX
May 10 2004, 10:14 PM
QUOTE (PacMan03 @ May 10 2004, 09:39 PM)
I think you are supposed to scan for port 1023 not port 5554
you have to scan port 5554.. (atleast i did.. and i had pretty much shells)
caca
May 10 2004, 10:23 PM
thanks you very much it's a good work ;)
toska
May 10 2004, 11:12 PM
Thanks mate!
toska
May 10 2004, 11:13 PM
I scan port port 5554 mostly but you can also scan 1023 which for variant of the sasser worm
Milka
May 10 2004, 11:45 PM
hmmz lemme take a look at this one, is it not the same as the other one?
ducky
May 11 2004, 04:45 AM
thanks m8 good work gonna test my local with this one
jead99
May 11 2004, 05:56 AM
Thanks for sharing your tools with the community m8, good work
Mouse
May 11 2004, 07:18 AM
cool
nice work
rscience
May 11 2004, 07:26 AM
grate work i will take this.
soundslider
May 11 2004, 12:35 PM
thx, 4 work.
perhaps i might have more luck with this
Ecko
May 11 2004, 01:22 PM
hi nice work...it's now a bit easier then before thx!
SecureD
May 11 2004, 01:26 PM
tnx m8 will check it out
Sinister
May 11 2004, 01:29 PM
tks m8 will give it a try
The Storm
May 11 2004, 01:44 PM
thank ya gonna test it!
warzoux
May 11 2004, 04:42 PM
thx for that very useful
Helloman
May 11 2004, 06:22 PM
Boar yeah thats nice big thx
hidden
May 11 2004, 08:09 PM
thx ok for try it
SuperG
May 11 2004, 09:23 PM
Thanks for your contribution ! Will have a look at that.
F34R
May 11 2004, 09:56 PM
Thanks for the autohacker. Hopefully it'll work... seems as if this sploit is kinda dead... or n00bed rather Nonetheless, I'll try.
DaywalkerX
May 11 2004, 10:08 PM
Thanks for the autohaxor.I will test it
ctv
May 12 2004, 02:27 AM
thank you
LiquidIce
May 12 2004, 08:55 AM
thnx for this works perfect
sattete
May 12 2004, 09:49 AM
thx
sattete
May 12 2004, 09:49 AM
thx 2 times
F34R
May 12 2004, 01:12 PM
QUOTE (sattete @ May 12 2004, 09:49 AM)
thx
Better watch tiny posts like that. Could get yourself reset. Just a warning. And dont post 2 meaningless posts like that. 1 well thought out one will do.
Rtyp3
May 12 2004, 02:11 PM
nice work !! ;-)
elbarto95
May 12 2004, 07:40 PM
sound good thank you for the public sharing
rgds
elbarto
chaos.comt
May 13 2004, 11:13 AM
nice work ... keep it on ;-)
Thebox
May 14 2004, 10:05 PM
IŽll try it. Many thanks
Nexcess
May 14 2004, 10:11 PM
auto'hackers' are such crap, if you cant be bothered to work on one system at a time you shouldnt even be allowed to use the exploit.
tonikgin
May 14 2004, 11:13 PM
^^^ this is true. however, many people use them in conjunction w/ scannets, to search for vulnerable machines faster, and get them before someone else might.
however, most of the autohackers on this site are not actual autohackers (those from back in the day), and just people using scripting languages to create a very havoc process.
pollux
May 15 2004, 07:58 AM
thx i will test
xoro
May 16 2004, 01:14 PM
Hi !
it don't works for me ....
Certox
May 23 2004, 04:55 PM
securing this... ?? Anyone know...
brOmstar
May 23 2004, 05:00 PM
removing sasser? lol what a question
Certox
May 23 2004, 06:00 PM
I meant close the ports or something, to make it not expoiltable
brOmstar
May 23 2004, 06:13 PM
ur funny why close ports if can remove the reason for the open ports ?
you can install a firewall on port 1023 or 5554 but why should u do this remove the damn worm and there is no exploitable ftpd...
Certox
May 23 2004, 06:44 PM
ok... how? ... why is this so hard for u to understand? It sounds like u know what to do... so please tell us, we are here to learn.
brOmstar
May 23 2004, 11:25 PM
[niceBoymodeOn]
Ok the program u r exploiting is the ftpd of sasser this is a worm that takes the lsass vuln to spread over the net(port 445)
This worm opens a ftpd on port 5554 sasser.a-e or port 1023 sasser.f so to 'secure' the vulnerability u have to remove this ftpd.
If u want to remove the ftpd u have to remove the worm - kill the task sasser is running.
Looking at some antivir-descriptions u will find out that the sasser-task calls mostly avserve.exe or avserve2.exe(sometimes other names but this is rare). Use some tool to view running tasks and kill this tasks.
At the end u have to modify the registry at -HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\ CurrentVersion\Run - remove the entry to the wormfile.
That's all. [/niceBoymodeOn]
And if u don't know how to do that ..lol
Killaloop
May 24 2004, 11:49 AM
lol how much fun it always is. people downloading the l33t autohaxxers and then asking "what to scan", "how to secure". thats for all of you: maybe it would be a good think to read about the exploit and its vulnerability? you would safe us all some time
[eatScriptkidModeON]
Certox
May 24 2004, 05:51 PM
Thanks to he dude who explained it, the rest of u smartass little kidz can suck a c**k
Feanor
May 25 2004, 07:34 PM
thanks for sharing this one, will be testing it for some days.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.