hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: Brain-irc-bot _ Beta
Pages: 1, 2, 3, 4, 5, 6
sevenvirtues
mcafee 8.o detected it..how can we make it undetectable..i tried repacking it w/ another packer but its not allowed..i used fsg..

tnx
jhd
look rbot source for add a baggle and radmin and ipc spreaders
Meads
Ver nice bot would love to see the auto spreading (hacking) function smile.gif
brainbuster
didn't find much time the last days....
gonna work on it tonight smile.gif

I'm planning following functions:



QUOTE

!bandwith
bandwith viewer

!connectback
gives you a connect back shell

!scan
advanced scanning functions

- ipc spreader..
Meads
QUOTE (brainbuster @ Jul 5 2004, 12:56 PM)
didn't find much time the last days....
gonna work on it tonight smile.gif

I'm planning following functions:



QUOTE

!bandwith
bandwith viewer

!connectback
gives you a connect back shell

!scan
advanced scanning functions

- ipc spreader..

Nice work look forward to the update wink.gif
WaZaa
Fewwy nice work & share dude!!! I almost missed this master piece of ART smile.gif,

nice share, .. let me try some stuff out wink.gif,

greetz WaZaa
brainbuster
i wont be online 4 a few days..
so here is the update... not big.. but i just wanted to make an update before i leave 4 a few days .

added :

QUOTE
-melt server function
-spread to lan function
chris105
Well I will check back next week, If you need any help I would be happy to try but it looks like you got most things covered!
sp00geD
maybe have a command to add commands?
Meads
Lan spread function sounds sweet wink.gif got find me a box on a lan and try it wink.gif
enemc
iam fooling around a little bit with your bot.. it works good to me..

thank you for your work smile.gif
prog
anyone having the bot not respond to the !login command?
i have tried in the channel, in a msg, the bot doesnt accept dcc chat or respond to the eggdrop /ctcp bot chat

ne help would be appreciated
sevenvirtues
maybe you should set your nick to the one you specified as bot master..
im not sure..just try it..i have no problems with the bot...the one w/o the melt server and lan spread..

tnx
Silent Bob
nice bot, like the way it works, and how you take the feedback....

could i request that you have a !stop command for the ping?
prog
It was actually a short password it wasnt 'accepting' or something
i went from a 4 character pass to an 8(with numbers) and it worked perfectly

wuts the details on the lan spreader. . .aka wut does it do when you activated it. . .etc

nice bot tho, great job. . .cant wait for the spreading to be added
h3llraz0r
nice bot, good options and getting better!! found a bug tho, the !free command will only display c:\ free space and not all drives on the machine, also when the bot was kicked for spam it wouldn't re-join the channel.
some ides for the bot, is it possible to specify the name for the keylogger text file

great work overall though!! its a great bot and keeps getting better
Dj_BaRt
great tool works good
brainbuster
Hi ,
i'm at home again and here is another update =)

QUOTE

!scan <Parameters>
scans with the nice Dfind version 0.7 coded by class101 ..
link

u can use any parameters u use with that Dfind
here all params:

-p    <Port> <IP IP> .......... Scan one port on iprange   
+p    <Port> <IP IP> .......... Scan iprange,+logs ok,refused connections
-p    <Port , Port> <IP IP> ... Scan two ports on iprange   
-p    <Port Port> <IP> ........ Scan a portrange on ip     
+p    <Port Port> <IP> ........ Scan portrange,+logs ok,refused connections
-ban  <Port Port> <IP> ........ Scan portbanners on ip     
-ban  <Port> <IP IP> .......... Scan portbanners on iprange 
-cgi  <IP> .................... Scan cgi hole               
+ipc  <IP IP> ................. Scan IPC$ null on 139 & 445 
-ipc  <IP IP> ................. Scan IPC$ null on 139       
-ipc2 <IP IP> ................. Scan IPC$ null on 445       
-iis  <IP IP> ................. Scan IIS webservers     
-apa  <IP IP> ................. Scan Apache webservers     
-wdv  <IP IP> ................. Scan WebDav on IIS5.0       
-hpj  <IP IP> ................. Scan HP Web JetAdmin     
-msa  <IP IP> ................. Scan MSADC on webservers   
-ccb  <IP IP> ................. Scan CCBill WhereAmi       
-med  <IP IP> ................. Scan WMedia on webservers   
-php  <IP IP> ................. Scan phpBB on webservers 
-php2 <IP IP> ................. Scan PHP-Nuke on webservers 
-fro  <IP IP> ................. Scan frontpage host         
-rea  <IP IP> ................. Scan RealServer component   
-htr  <IP IP> ................. Scan +.htr hole             
-pri  <IP IP> ................. Scan .printer host         
-uni  <IP IP> ................. Scan unicode hole           
-idq  <IP IP> ................. Scan .idq host             
-cod  <IP IP> ................. Scan codered virus hole     
-opx  <IP IP> ................. Scan OptixPRO v1.0 => 1.32(include) hole
-rad  <IP IP> ................. Scan Radmin 2.1 Auth,NTAuth,NULL session
-ftp  <IP> [-admin] ........... Scan file transfert protocol hole
-ftp  <IP IP> [-admin] ........ Scan file transfert protocol hole
-req  <REQ IP IP> ............. Scan File/Dir Request on webservers


!shell <commands>
will execute <commands> hidden on infected host
<commands> can be any dos command + parameters

!stopping
will stop a ping attack wich was started with !floodping before
QUOTE
wuts the details on the lan spreader. . .aka wut does it do when you activated it. . .etc


it'll just search for .exe files on LAN with write access... then It will replace them with itself and do a backup of old file in *file*.exe.bak.
when the replaced file is executed by the user the machine will be infected and *file*.exe.bak is renamed to *file*.exe and executed
sry 4 my bad english
prog
CODE
!shell <commands>
will execute <commands> hidden on infected host
<commands> can be any dos command + parameters


meaning it will execute a file on the scanbot you are using?

ne thoughts of adding sploits for all those goodies it scans for?


btw, Excellant choice on the scanner, very good
6066up9r
this is a great job well done here, thanks!
Ahmeket
I'm really impressed by your work and would just like to say, thank you for sharing it! Just one question, the -ipc scans, does it work remotely? I can't seem to get any results. Also it might be good if you added an option to clean the scanfilelog. wink.gif
Dj_BaRt
very great irc bot thx
prog
QUOTE (Ahmeket @ Jul 13 2004, 08:35 PM)
I'm really impressed by your work and would just like to say, thank you for sharing it! Just one question, the -ipc scans, does it work remotely? I can't seem to get any results. Also it might be good if you added an option to clean the scanfilelog. wink.gif

CODE
!shell del dfind


Will delete the scanfile


again great job with this
couple questions
any thoughts of adding an ftpd maybe even controled via mircbot
!ftp port username password
would add the account
!startftp
to start it
or even just a way to make the bot accept dcc send when its on mirc, that would still be ok

or maybe a ftp/ipc brute forcer, that you point a user.dic and pass.dic files when you 'compile' the exe file

just some thoughts

again great job. . .;]
-=[Romulus]=-
if you'd like i can translate it in french,i'm trying it aswell
thx a lot
enemc
found a bug...

the bot works great but when the server is offline and then online again.. the bot isn't in the channel.. could you check this?
Ahmeket
I was thinking of another feature which might be good to have. How about a feature which can send you the dfind file via dcc?
brainbuster
QUOTE
the bot works great but when the server is offline and then online again.. the bot isn't in the channel.. could you check this?


gonna have a look at that problem

and i'll look for a chance of sending the dfind ...
prog
Another quick suggestion, making it so the 'bots' it makes have a base nick
right now they are all random, and maybe a way to disable the msg on joining the server
Ahmeket
QUOTE (prog @ Jul 14 2004, 02:43 PM)
Another quick suggestion, making it so the 'bots' it makes have a base nick
right now they are all random, and maybe a way to disable the msg on joining the server

That can be done if you delete the box with text when making the exe.
prog
sweet, i figured it would at least send you a blank msg
sevenvirtues
guys i was just wondering what servers are your bots on?im on undernet. just looking for servers though, that way i can choose which is the best..

tnx
prog
efnet here
Flowby
Great job Brainbuster!! wink.gif
rolleyes.gif
Psyc0s
very gj!!!

!join <#channel> command plz??
enemc
QUOTE (Psyc0s @ Jul 16 2004, 07:24 PM)
very gj!!!

!join <#channel> command plz??

just do a raw command

!raw join #channel key rolleyes.gif
twistedps
this is very nice m8, im gonna need to look it over more!
ZoRRo_
hmm..
i can't get this bot started...
i don't know what to bind into my servu.ini and whic files i have to download!
can anybody write a little tut for a noob like me tongue.gif


thx
jaune
my bot does not arrive on IRC they is necessary a complement or right this prog sufi!
thank you for your reponses!

to forgive my very bad English!
sevenvirtues
guys i was able to download a bot , actually which i thinks is a bot but its only source codes..im not that good in vb programming yet so i hav problems..

can anyone help me with it.?im kinda interested in what the bot can do..

tnx
braini
QUOTE (ZoRRo_ @ Jul 17 2004, 04:15 AM)
hmm..
i can't get this bot started...
i don't know what to bind into my servu.ini and whic files i have to download!
can anybody write a little tut for a noob like me tongue.gif


thx

there is no need for servu
its stand-alone o_O


i justwonder why my firewall tells me it wants to connect to www.google.com via http *?*
night^man
exl job !
a+
BDaught
Thanks for this one.. Looks really good.. About to test it out locally for myself... I'll post again if i run into any problems... or to commend you more.. smile.gif
ZoRRo_
oh im such a noob lol!

i just wanna add that the !leave command doesnt work!

you have to use raw commands to let this bot leaves a chan!

how can i speak with this bot?

anything like !raw msg #chan test ?


and how can i start this bot remotely?
i tried to upload this generated exe file to a server and execute ist..
but it doesnt connect to the irc server and private msg me ..

can anybody help me?
globey
maybe the computer i try to running it for is blocked the connnection or somthing?

or he is got slow connection?

or is a probleme with the connection to the server?
ehm
but i think the scanning options suck ok scanning works well but when u have a 19kb scanfile and it comes ip per ip in the can it would better if u automaticly could download the scanlog per xdcc or something like this u know what iam thinking off at least nice nice programm

(meld dich mal bei mir per pm bitte!)
ZoRRo_
QUOTE (globey @ Jul 18 2004, 05:03 AM)
maybe the computer i try to running it for is blocked the connnection or somthing?

or he is got slow connection?

or is a probleme with the connection to the server?

i think the computer isn't blocking anything, because other bots join the network too!

and the connection should be very fast!


it is enough to upload my exe.file, which is in mein winroot?
sry for my bad english lol
simply-me
Hi,

If your bot could work on computers which have access to internet only through proxies it would be the perfect on for me.
globey
there is a way to choose other msg on the flood?
Pikamars
it will be great if the bot can join chan with password biggrin.gif
or if u can choose the nick of the bot in the conf file
and if it will be able to list process kill them and same for service
yeah i kno i'm asking a lot of stuff
oxydrine
the greatest one !!!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.