Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Knock, Knock, Knock
Kelly Martin, 2004-02-20

If hundreds of thousands of people are still blindly clicking on attachments in their email, is there any hope of mitigating the threat of hundreds of thousands of compromised systems with open backdoors?

Comments Mode:
Knock, Knock, Knock 2004-02-20
Dmitriy (1 replies)
Knock, Knock, Knock 2004-02-24
Keith (4 replies)
Knock, Knock, Knock 2004-02-26
Anonymous
Knock, Knock, Knock 2004-02-27
Farzad
Knock, Knock, Knock 2004-03-01
Anonymous
Knock, Knock, Knock 2004-03-01
www.mobasoft.com
Knock, Knock, Knock 2004-02-20
Anonymous (2 replies)
Knock, Knock, Knock 2004-02-25
Anonymous (1 replies)
Knock, Knock, Knock 2004-03-03
Anonymous
Knock, Knock, Knock 2004-02-21
Anonymous
Ok Double Sided Swords 2004-02-21
Anonymous
Knock, Knock, Knock 2004-02-24
Jack (1 replies)
Knock, Knock, Knock 2004-02-28
Anonymous
Knock, Knock, Knock 2004-02-25
Anonymous
Knock, Knock, Knock 2004-02-26
fndude@hotmail.com
Actually, would a port knocking trojan be more secure? The client side of the trojan would be distributed I am sure, and the ability to gain access to the trojan would be in place. Now a mass-rooter script would be wrote that would simply knock on each machine then try the port. Even if you used DES/blowfish knock sequence encrypting for greater control, the passprase would be the same as the original code, or viewable none the less. For example, if I wanted to be mean, I could go into kaza and search for the files that my.doom deposits in the download folder of my victim. I learned about this virus's habits from security sites detailing what the virus does, giving me enough information to gleem targets without port-scanning. I's sure with any mass viri, this would be the same senario.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/221/25191#25191
Knock, Knock, Knock 2004-02-27
Anonymous
Pretty easy solution 2004-02-27
Potato Head
Knock, Knock, Knock 2004-03-01
Robert Townley







 

Privacy Statement
Copyright 2008, SecurityFocus