Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Backdoor program gets backdoored
Kevin Poulsen, SecurityFocus 2004-06-11

The author of a free Trojan horse program favored by amateur computer intruders found himself with some explaining to do to the underground last month, after his users discovered he'd slipped a secret backdoor password into his popular malware, potentially allowing him to re-hack compromised hosts.

Comments Mode:
And are we surprised...? 2004-06-12
Anonymous
Backdoor program gets backdoored 2004-06-14
Anonymous
Backdoor program gets backdoored 2004-06-14
Anonymous (1 replies)
Backdoor program gets backdoored 2004-06-17
X-HUMANATION (2 replies)
I only made the fragmentation grenades... 2004-06-22
We are not 455H0L3Z?
Backdoor program gets backdoored 2004-06-16
Anonymous
supported versions? 2004-06-16
jim
Backdoor program gets backdoored 2004-06-18
xum '\x40 (1 replies)
As the author stated, it's not that he wants to connect to these infected hosts, he wants to have leverage over the authorities. "If they give me shit, I'll release the master pass" ... as many hosts as there are that are infected with this, that would make a fairly decent sized Distributed Denial of Service network, under the control of whomever, and unless the person who uses the master password removes the malware, all of these computers could in theory be running many instances of DDoS utilities, from many different individuals who connected via the master password. I think he covered himself well, but if someone were to get this master pass, it would be very trivial to write a program to scan for these hosts, and automate the process of infection for DDoS. DDoS isn't the worst that could be done, but I don't want to give anyone any ideas that would do such things.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/8893/26790#26790
Backdoor program gets backdoored 2004-06-18
Anonymous (1 replies)
Backdoor program gets backdoored 2004-06-20
Anonymous (1 replies)
Backdoor program gets backdoored 2004-06-24
dazzler/darkt3ch







 

Privacy Statement
Copyright 2009, SecurityFocus