Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
New SubSeven Trojan unleashed
Kevin Poulsen, SecurityFocus 2001-03-13

SubSeven 2.2 makes Back Orifice look tame.

Comments Mode:
You are not 'safe' 2001-03-13
Anonymous
Behind of firewall. 2001-03-13
marceloreyes (at) netscape (dot) net [email concealed] (3 replies)
Behind of firewall. 2001-03-14
Someone (2 replies)
Behind of firewall. 2001-03-15
youps (at) hotmail (dot) com [email concealed] (1 replies)
Behind of firewall. 2001-03-16
mailsander (at) gmx.net (dot) no-s [email concealed]pam (1 replies)
Behind of firewall. 2001-03-16
Futien
Behind of firewall. 2001-03-25
Metallist
Behind of firewall. 2001-03-22
Karmic Resonance
Re: Behind of firewall. 2007-04-20
Anonymous
Safe? 2001-03-14
FS
Subseven 2.2 IS NOT A REMOTE ADMINISTRATION TOOL!!! 2001-03-14
David Mills (1 replies)
Subseven 2.2 IS NOT A REMOTE ADMINISTRATION TOOL!!! 2001-03-14
SilenceGold (2 replies)
MASTER PASSWORD? 2001-03-15
Concerned (1 replies)
MASTER PASSWORD? 2001-03-16
CL
not safe 2001-03-15
av
Subseven Startup 2001-03-15
Dark Avenue (4 replies)
Subseven Startup 2001-03-16
cPtHoWdY
Subseven Startup 2001-03-17
Anonymous
Subseven Startup 2001-03-22
dan
Subseven Startup 2001-03-22
Karmic Resonance
You appear a little confused. 2001-03-16
HeLLfiReZ Sub7 Developer
It appears there is much confusion here judging by the varied postings I have just read.

Yes SubSeven is a remote administration tool (legit or not legit) you decide. A gun or a hammer can be used for either legitimate purposes or illegitimate purposes and that decision lies with the end user. We supply a software product free of charge for anybody to download and use in whatever way they will.

This program represents hours of our free time developing, testing and coming up with new and radical ideas. Many of the ideas have made people sit up and think and yes we have a lot more even more radical ideas thought out and researched ready for implementation in our stable version 2.3 releasable in 2-3 weeks time with IRC Bot plugin and SDK.

You may also notice now that Sub7 hides from process managers and none DOS based netstat outputs. Nowhere yet have I seen any knowledgable security writer make any reference to this.

I tend to agree with SilenceGold on his summary of SubSeven as remote administration. With or without permission it is still remote administration whichever way you look at it.

As for file extensions you can use *.exe *.com *.bat *.pif *.scr *.hta *.vbs *.shs if created properly into a shell scrap file (a simple rename will not work) plus many others. Also note that a file can be joined to the server to make any extension executable. Its possible to name your server package *.ggg and have a small program associate *.ggg as executable. Obviously the joined file that made *.ggg executable would have to be an executable of some description in the first place.

Regards HeLLfiReZ for more information IRC subseven.mine.nu 6667 #subseven our realtime assistance channel or hellfirez65 (at) yahoo (dot) com [email concealed]

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/171/4949#4949
I think I got hit by it... tips for other victims. 2001-03-16
kilonad (at) hotmail (dot) com [email concealed]
however.. 2001-03-18
ahmed rhashad muhammed aleki
Using Sub7 legitimatly 2001-03-19
dafunks (1 replies)
Re: Using Sub7 legitimatly 2007-06-19
Anonymous
sub seven is tame 2001-03-20
The Achtzhen
Sub7 2001-03-21
surferUSA
SubSeven is the Powerhouse. 2001-03-21
C Y B E R C O N







 

Privacy Statement
Copyright 2009, SecurityFocus