Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
New SubSeven Trojan unleashed
Kevin Poulsen, SecurityFocus 2001-03-13

SubSeven 2.2 makes Back Orifice look tame.

Comments Mode:
You are not 'safe' 2001-03-13
Anonymous
Behind of firewall. 2001-03-13
marceloreyes (at) netscape (dot) net [email concealed] (3 replies)
Behind of firewall. 2001-03-14
Someone (2 replies)
Behind of firewall. 2001-03-15
youps (at) hotmail (dot) com [email concealed] (1 replies)
Behind of firewall. 2001-03-16
mailsander (at) gmx.net (dot) no-s [email concealed]pam (1 replies)
Behind of firewall. 2001-03-16
Futien
Behind of firewall. 2001-03-25
Metallist
Behind of firewall. 2001-03-22
Karmic Resonance
Re: Behind of firewall. 2007-04-20
Anonymous
Safe? 2001-03-14
FS
Subseven 2.2 IS NOT A REMOTE ADMINISTRATION TOOL!!! 2001-03-14
David Mills (1 replies)
Subseven 2.2 IS NOT A REMOTE ADMINISTRATION TOOL!!! 2001-03-14
SilenceGold (2 replies)
MASTER PASSWORD? 2001-03-15
Concerned (1 replies)
MASTER PASSWORD? 2001-03-16
CL
not safe 2001-03-15
av
Subseven Startup 2001-03-15
Dark Avenue (4 replies)
Subseven Startup 2001-03-16
cPtHoWdY
Subseven Startup 2001-03-17
Anonymous
Subseven Startup 2001-03-22
dan
Subseven Startup 2001-03-22
Karmic Resonance
You appear a little confused. 2001-03-16
HeLLfiReZ Sub7 Developer
I think I got hit by it... tips for other victims. 2001-03-16
kilonad (at) hotmail (dot) com [email concealed]
PLEASE stop referring to sub7 as if it were masterfully coded 2001-03-16
skweek
... because it isn't. Servers go down, servers fail to run on startup, even without a firewall any observant user will notice the extra traffic going through their connection, and the idea of ANY currently available trojan being undetectable is a joke: just run "netstat -a" from a command prompt and if you see any port listening that shouldn't be, investigate. The SubSeven client is ugly, the server is now quite small but the new plugin system unstable, the whole thing is just too hit-and-miss in terms of reliability to be user friendly. I actually think 2.1 was better because quite simply more of it worked well... although the forthcoming bugfixed 2.2 remains to be seen.

I'm also convinced that using the SubSeven client on my machine caused ICQ to malfunction; I get recurring DLL errors which I managed to fix once only to have them reappear, and SubSeven is the only third-party software which makes use of the ICQ API which I have used any time recently.

The professionalism of "mobman" is also a complete joke; he embedded a hard-drive killing program (which he did not himself write) into the 2.1 client and used it to literally sabotage the development of a promising rival trojan, Syphillis. The project was discontinued after sourcecode was lost; the website for the currently unreleased continuation, Revenant, has been down for some time now and I wouldn't be surprised if mobman was involved in that somehow.

There are more stable trojans out there with similar feature sets, smaller server sizes (often attained by similar but more reliable plugin systems), and some with more personally worrying and potentially damaging features: "711", for example, facilitates spying on phonecalls conducted over a victims' ISDN line.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/171/4971#4971
however.. 2001-03-18
ahmed rhashad muhammed aleki
Using Sub7 legitimatly 2001-03-19
dafunks (1 replies)
Re: Using Sub7 legitimatly 2007-06-19
Anonymous
sub seven is tame 2001-03-20
The Achtzhen
Sub7 2001-03-21
surferUSA
SubSeven is the Powerhouse. 2001-03-21
C Y B E R C O N







 

Privacy Statement
Copyright 2009, SecurityFocus