Forums: I.e One More Time :d - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

I.e One More Time :d poc code for everyone to cuddle with

#1 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 30 September 2003 - 08:59 PM

http://illmob.netfirms.com/aim.html this will donwload and execute my new firewall / antivirus killer (only 4.87kb made in assembly) and it will execute it without norton picking up the script as a virus before the page is even opened :ph34r:
0

#2 Guest_clubfed_*

  • Group: Guests

Posted 01 October 2003 - 04:23 AM

I did something like this about two months ago - which is half of why I have had the most advanced owning technique -- I rooted several *dozen* well-known hackers with similar code (and I scored a great deal of unreleased 0day exploits this way)(ironically including an unreleased *new* IE exploit). I wrote my own AV/FW killer in win32asm that also downloads a larger more advanced egg. The advanced code can circumvent even application proxy gateways and some hardware firewalls (if you are familiar with configuring these, you know the _certain_ traffic I'm refering to that can't really be blocked and protocol inspecting is impossible).

However I think it's amoral and truly a *bad idea* to just spoon-feed others with less skill and give them this much power without them learning how to do it for themselves. Think of some malicious and angry person who comes here and grabs this code and goes and roots your mother, or other family members, or your friends, or some company/group/etc you like and care about. More skill doesn't always equate with more responsibility, but truly handing out packaged weapons to the uninitiated is just begging for disaster.

Illwill, please reconsider packaging bugtraq exploits for the masses. The problem is bad enough as it is. If people can't figure this stuff out, then thank goodness! This bug will last for years (in some cases) so let them catch the scraps!

For your consideration,
0

#3 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 01 October 2003 - 04:54 AM

ok well said. removed the page.
0

#4 User is offline   cartman 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 62
  • Joined: 16-August 03

Posted 01 October 2003 - 05:14 AM

stupid
0

#5 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 01 October 2003 - 03:29 PM

yes im so hurt by someone who names himself after a fat cartoon character
0

#6 User is offline   mortello 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 408
  • Joined: 25-August 03

Posted 01 October 2003 - 06:51 PM

I do not know how to do such app, but I must admit this is a great idea (to remove) since I don't think I should be able to use such powerful tool

Use it for you....at least you wont have lost it entirely :)
0

#7 Guest_zadium_*

  • Group: Guests

Post icon  Posted 01 October 2003 - 08:32 PM

can u kindly send the exploit this way :) send it to mumin786@hotmail.com cheers
0

#8 Guest_gravyboy_*

  • Group: Guests

Posted 01 October 2003 - 09:55 PM

Argh, what about us that understand it and want a look?! I got home from work looking forward to see what you had done and now its gone!

I thought this was the purpose of this forum.

Is there some kind of other way I can see it? is it the same as the Iexplorer windows media thing posted last week?.

I would appeciate a PM with another link or the code if its not to much trouble.

-gravyboy
0

#9 User is offline   illwill 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 540
  • Joined: 28-July 03

Posted 02 October 2003 - 05:36 AM

yea it was the media one
0

#10 Guest_gravyboy_*

  • Group: Guests

Posted 02 October 2003 - 08:58 AM

Thanks :)
0

#11 Guest_atf_*

  • Group: Guests

Posted 02 October 2003 - 11:36 AM

PM the info here too, i just dont want to go through 100post to see the gory details :)
0

#12 User is offline   Nick W 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,250
  • Joined: 12-August 03

Posted 02 October 2003 - 12:33 PM

Quote

yes im so hurt by someone who names himself after a fat cartoon character


well put. ;)

What ASM utilities do you use? And how big is it after UPX?
0

#13 Guest_clubfed_*

  • Group: Guests

Posted 02 October 2003 - 01:58 PM

To answer the question about size, I don't use upx, I use fsg:

08/23/2003 03:50 PM 3,664 avfrown_ieobject_2003_08_21.exe

The "large" size is because of all the strings for the various av/fw out there.

My killing technique is not amazing, it's pretty standard:
invoke CreateToolhelp32Snapshot, TH32CS_SNAPPROCESS, 0
...
invoke OpenProcess, PROCESS_TERMINATE, 0, Process.th32ProcessID
invoke TerminateProcess, eax, 0
0

#14 User is offline   toska 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 102
  • Joined: 01-September 03

Posted 02 October 2003 - 08:39 PM

can someone PM the info here too. Thanks
0

#15 User is offline   Nick W 

  • Master Sergeant
  • Icon
  • Group: Members
  • Posts: 1,250
  • Joined: 12-August 03

Posted 03 October 2003 - 05:25 AM

clubfed, on Oct 2 2003, 09:58 PM, said:

The "large" size is because of all the strings for the various av/fw out there.

The large size? I'm not knocking it at all. In fact, it's the smallest one I've seen so far. I was just wondering if you used UPX to compress it. FSG is nice for ASM code since it's already pretty small. I should get a hold of you about other changes you can make to be certain it's a LONG time before they get their AV and firewall software fixed.

It's a really interesting concept and would throw all the AV software companies into a frenzy over how to deal with it. A few others have done it before, but I still consider it new cause it's never been done *right*.
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting