Forums: Sending File After Pinging To Someone? - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Sending File After Pinging To Someone? is this possible?

#1 Guest_Hag4r_*

  • Group: Guests

Posted 06 December 2003 - 10:12 AM

Hi,
I recently worked myself in problems. I was talking to a guy at irc, and he asked me to ping him with a command: /ctcp nickname PING, dumb and unsuspicous as i was, i did it, then he said something like: transferred winmgnt.exe in 2,33 sec. So i was wondering, if he could have send that file to my computer after i typed that command, pinged him ??
After that, i ve found a file called winmgnt.exe on my disc, in c:\RECYCLER\blabla.
And what does that file do? anyone knows it?

regards
0

#2 User is offline   mrBob 

  • Sergeant First Class
  • Icon
  • Group: Specialist
  • Posts: 321
  • Joined: 12-August 03

Post icon  Posted 06 December 2003 - 11:08 AM

winmgnt.exe usually is the hacked serv-u ftp server
so actually he has full control over your pc cuz he can upload/download and execute ANY file
and /ctcp [nick] PING means that you we're requesting a file from that nickname..
0

#3 User is offline   SLiM577 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 83
  • Joined: 30-November 03

Posted 06 December 2003 - 11:24 AM

yea wingmt.exe is most likely serv-u dude
0

#4 User is offline   mrBob 

  • Sergeant First Class
  • Icon
  • Group: Specialist
  • Posts: 321
  • Joined: 12-August 03

Posted 06 December 2003 - 11:31 AM

btw, also found a servudaemon.ini in there?
and servustartuplog.txt
0

#5 User is offline   UnDeRTaKeR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 143
  • Joined: 30-November 03

Posted 06 December 2003 - 01:13 PM

As my friend said mrBob

Quote

btw, also found a servudaemon.ini in there?
and servustartuplog.txt


i wondered if he could execute the file..
0

#6 User is offline   SlippyG 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 121
  • Joined: 30-November 03

Posted 06 December 2003 - 04:28 PM

First of all I'd like to thank the original poster for not referring to the Internet
Relay Chat service as 'mIRC' - Nice to know that some people still recognise
that IRC is an open protocol that predates the popular windows app. I still
shudder everytime someone asks about 'mIRC servers' ;)


mrBob, on Dec 6 2003, 07:08 PM, said:

winmgnt.exe usually is the hacked serv-u ftp server
so actually he has full control over your pc cuz he can upload/download and execute ANY file
and /ctcp [nick] PING means that you we're requesting a file from that nickname..


I'm not sure what you're trying to say here. The common command
/CTCP {nickname} PING|FINGER|VERSION|TIME|USERINFO|CLIENTINFO
is a well known IRC command despite not being documented in RFC1459.

I suggest you read the CTCP (Client to Client Protocol) specification which
will help clarify what these /CTCP messages mean, and how they are used.

To send these CTCP messages we (Or our IRC client) simply quotes them
into standard RFC1459 PRIVMSG's.

Heres what the CTCP specification says about its 'PING' messages:

Taken from CTCP documentation said:

PING
====
Ping is used to measure the time delay between clients on the IRC
network. A ping query is encoded in a privmsg, and has the form:

\001PING timestamp\001

where `timestamp' is the current time encoded in any form the querying
client finds convienent. The replying client sends back an identical
message inside a notice:

\001PING timestamp\001

The querying client can then subtract the recieved timestamp from the
current time to obtain the delay between clients over the IRC network.


To say that this 'means you we're requesting a file from' the user involved
doesn't make any kind of sense to me. Would you care to elaborate on
what you meant by this ?

Perhaps if you read RFC 1459 and the CTCP Spec it may remind you :rolleyes:

C'mon people - lets try to be accurate.


S.G.
0

#7 User is offline   Travis 

  • Specialist
  • Icon
  • Group: Specialist
  • Posts: 2,101
  • Joined: 26-February 03

Posted 06 December 2003 - 05:56 PM

I have a question.
What IRC Client were you using? What Version?
0

#8 User is offline   KoStIsTR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 01-December 03

Posted 07 December 2003 - 01:34 AM

I'll make a suggestion but i'm not to sure about it.... Maybe this guy had a xdcc bot and as trigger had this one : /ctcp nickname PING ?? so when Hag4r typed the xdcc bot send him the file. For happening all of this though Hag4r you must had dcc autoget-file and the target folder was c:\RECYCLER\blabla , Or maybe that was a file that gave him somehow control to your pc and then he moved to c:\recy.... . That's just a suggestion so if i'm wrong i want to here your corrections.

KoStIsTR
0

#9 Guest_Hag4r_*

  • Group: Guests

Posted 07 December 2003 - 07:34 AM

ty first for all the replies, I think( *hope* actually lol) it was a false, alarm. I installed a good firewall, so normally i could track in any malicious data is sent to outside.

Quote

What IRC Client were you using? What Version?
im using just mIRC, v 6.12

Quote

btw, also found a servudaemon.ini in there?
and servustartuplog.txt

i havent found any servudaemon.ini, servustartuplog in that folder, only a winmgnt.bat and winmgnt.dll

and i have autosend disabled, and there is certainly not the exstentions .dat .exe .dll
in the dcc unignore folder...

regards
0

#10 User is offline   KoStIsTR 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 01-December 03

Posted 08 December 2003 - 04:33 AM

lol so much replies for nothing :P Next time plz search a little bit more before asking something like that :)
0

#11 User is offline   jonfinley 

  • Private
  • Icon
  • Group: Members
  • Posts: 1
  • Joined: 29-January 04

Posted 29 January 2004 - 11:26 AM

If you check on Symantec's site, winmgnt "MAY" be the BackDoor.Hale trojan.

Symantec security responce

Jon
0

#12 Guest_KaZslo_*

  • Group: Guests

Posted 02 February 2004 - 08:04 PM

Or the Troj/PAdmin Trojan: http://www.sophos.co.../trojhalea.html

Also, check if port 1200 is now open on your computer.
0

#13 User is offline   x303 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 28
  • Joined: 04-February 04

Posted 23 February 2004 - 07:04 AM

Is it available to cut-off unwanted comands in mIRC?
So u can use it without worrieing about hacks, and so on?
0

#14 User is offline   jubbly 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 89
  • Joined: 08-September 03

Posted 12 March 2004 - 03:28 AM

winmgnt.exe could be whatever you want it to be if your in charge of renaming your file :(

I suggest you look into the bat and dll file using a text editor incase they are renamed files to fool you. They may be renamed ini files or it'll give you some clue as to what they are and how to get rid of whatever it done.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting