+ Reply to Thread
Page 2 of 6 FirstFirst 1234 ... LastLast
Results 16 to 30 of 82

Thread: Critical Vulnerability Discovered in uTorrent

  1. #16

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    Quote Originally Posted by anon View Post
    Logitech's shellcode would run his favorite trojan when the torrent is loaded
    damn are u serious ? nah,dont want that secret bud,I give up
    Reply With QuoteReply With Quote
    Thanks

  2. #17

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Quote Originally Posted by anon View Post
    Logitech's shellcode would run his favorite trojan when the torrent is loaded
    Poison Ivy or ProRAT
    witch one should I choose?

    Wait a second let's open a poll
    Reply With QuoteReply With Quote
    Thanks

  3. #18
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Never tried Prorat, but I have had some good experiences with PI

    Spoiler _:
    I had agreed with my contact we were going to use a RAT, then solved some of his PC problems with it from my comp... what did you think?


    Also the server is 8kB and written in ASM

    But for me the best remote administration tool is RemotelyAnywhere: it takes having just a web browser to be able to control the remote PC (no "client" programs), and can get through firewalls. Too bad it isn't free.
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  4. #19

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    lets install RealVNC it's easy in use.
    You can even change how many bits colour(e.g. 8 bits) so you can even download and do things on that computer:).

    Spoiler psst anon:wink2::
    although VNC software is easier it's more likely that a torrent is +-8kb then 5mb.
    So what are we going to choose?
    Reply With QuoteReply With Quote
    Thanks

  5. #20
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Quote Originally Posted by Logitech View Post
    You can even change how many bits colour(e.g. 8 bits) so you can even download and do things on that computer:).
    In RA you can go as low as grayscale (for 56K connections )

    Spoiler _:
    "So what are we going to choose?"
    It's up to you
    ...
    RA is 12MB
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  6. #21

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Is RA already server file or does it need to be installed also?

    Spoiler AV:
    I have seen something about AV on uncle Mil page so It won't be hard to make a RAT tool undetectable
    Reply With QuoteReply With Quote
    Thanks

  7. #22
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Quote Originally Posted by Logitech View Post
    Is RA already server file or does it need to be installed also?
    Needs to be installed, licenced, configurated, and installs a mirror driver. Not what you'd call undetectable

    Spoiler _:
    "I have seen something about AV on uncle Mil page so It won't be hard to make a RAT tool undetectable"

    If you mean Themida forget it It can make the smallest EXE megabytes big
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  8. #23

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    Spoiler Top Secret:
    There is somthing that called editing the byte that contains the detection.
    And themida is recognized by nod32 and some other anti-virus, because it's used for the things where we are talking about
    Reply With QuoteReply With Quote
    Thanks

  9. #24
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    Spoiler _:
    "There is somthing that called editing the byte that contains the detection."



    "And themida is recognized by nod32 and some other anti-virus, because it's used for the things where we are talking about"

    Even after editing the section name?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  10. #25

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    hey Logitech !! u still thinking of picking up ur next victim ?? hehe anyway,try that RA app,its amazing u know (anon was playing chess in my PC 1 week ago ),its just as simple as digging up a PC for injecting ur server file
    Reply With QuoteReply With Quote
    Thanks

  11. #26
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451


    But how can he inject a 12MB msi in a .torrent? You also need to know who to connect to [IP address], and his Windows username and password, remember?
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  12. #27

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    OK now im getting some new ideas !! Hey Logitech,can you compress that shellcode a little bit ? I mean to minimize its actuall running size to less than 1mb,that way it would be reasonable if linked to a pack sized @ 20GB+ (u know once u see a 900KB torrent file,you won't be shocked since you already know you are l33ching alot here),maybe Im having a day dream since I don't know how that shellcode works anyway,but I do know that everything's possible lately,if you could do that with ur shellcode then it would be such a piece of art
    Reply With QuoteReply With Quote
    Thanks

  13. #28

    Join Date
    16.07.08
    P2P Client
    Vuze SB-I 3.1.1.1
    Posts
    147
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss147
    compressing 12mb to 1mb is some hard compress technique.
    Reply With QuoteReply With Quote
    Thanks

  14. #29
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,451
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39451
    @Reppy: that'd mean modifying the .torrent, which changes its infohash = tracker won't recognize it, 0 peers and seeds as its hash is different, also other peers won't have that torrent. Pretty impossible :/

    @Logitech: KGB archiver But it takes A LOT of time to unpack
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  15. #30

    Join Date
    22.05.08
    Location
    SB-RepubliC
    P2P Client
    SB Invention !!
    Posts
    2,899
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2899
    Well,I don't know the parameters of it to tell if it could be done or not but I was wondering since it sounds Cool to inject such a shellcode into a .torrent file without getting it to be Huge !! Anyway,I believe that some one else already discussed such a process before somewhere so lets see if we can find such a modified torrent file someday

    P.S: Yeah KGB is a Monster compressor/decompressor regarding large sized files
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread
Page 2 of 6 FirstFirst 1234 ... LastLast

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •