well i know its lame, but i needed an ftp to test the exploit on, so why not pick a hacked 100mbit from someone I dislike...
The exploit works perfectly, gives you remote cmd.exe (remember to run it from a remote box, which has open incoming ports).
Now, I was quite surprised to find that the ftp has been so well hidden, that from a remote shell working through hxdef, I couldnt find the servu installation.
Eventually after using a file searching tool, i discovered some of the serv-u files, but what really surprised me, was that the UP and DOWN folders were apparently empty, yet the ftp was serving about 20gb of files.
I know hxdef wouldnt hide this from a remote shell, so what rootkit could this be??
Anyway, the exploit works frighteningly well, so im changing all my ftps to another less well known server.
Dont bother replying if only to flame me for rehacking.
The thread here is about what varieties of rootkit can hide files from remote shells and dameware (and how to remove them).
If you want to read more about my security research, visit Tibbar.org
Damn LAMERS! :angry:
How someone can resist replyin only to flame you?!
Respect the work that someone has done!U might be the next who will get rehacked.Would you like that?
i personally think rehacking is fair game. i have already secured all my ftps, by swapping to a non-public ftp server that i compiled myself.
this exploit has been around for a long time now (at least in public as dos), so if you are too lazy to update your ftps, then dont be surprised if you lose them.
[edit] you might as well have said, how would you like it if your webserver got hacked - that would be worse to me, than losing a stro i was too lazy to keep secure.
If you want to read more about my security research, visit Tibbar.org
No it's NOT ... it's basicaly the same like I steal U car or what ever...
Oh U not secure U car's door to the newest technics so it's U fault... :angry:
Think about !! anyway STROmakerz are all l4m3rz :D
lol, we are the ppl who STEAL innocent users bandwidth and diskspace because they are not security conscious enough to install updates to windows and programs.
so suddenly hackers / skiddies having a morality attack about ppl stealing their stolen bandwidth is laughable.
this is like you steal a car, and then i steal that car from you. the victim here is the poor person who lost his car initially.
and going back to point one. the ppl who get hacked are those who are not security wise enough to update software....now suddenly that has become you.
if you are too lazy to update your software on your vics, then it's fair play to take them from you... it's no different to me hacking a innocent security unaware pc user.
If you want to read more about my security research, visit Tibbar.org
oh and in my search for the rootkit on this box, here's the service list:
Service Name Display Name Status
----------------------------------------------------------------------------
alerter alerter (RUNNING)
alertManager Network Associates alert Manager (RUNNING)
lol, we are the ppl who STEAL innocent users bandwidth and diskspace because they are not security conscious enough to install updates to windows and programs.
tibbar i don't know who you are or what you do.But there are certain rules.
I can go find myself many excuses thing is if you follow or not the rules.
Play the fair game or play the "i'm so ing 1337 game!".
@ Steffan