General
Information
Russell Kaiser:
|
PRESENTATION
Here is a brief description of my presentation
to the network managers. I intend to demonstrate
the tools hackers use, in particular the Subseven
trojan.
I will detail how hackers get the Subseven backdoor
onto peoples computer, by use of either enticing
email attachments or by IIS web vulnerabilities
which will let a person drop it onto the machine.
I will show how you can identify the Subseven
backdoor whether you have antivirus software on the
machine or not. In particular I will point out
registry entries that Subseven, and many other
backdoors use to start up the server, and how to
identify it using common Windows tools (netstat, etc.).
I will then give a demonstration of the Subseven
backdoor itself, both from the view of the hackers
eye view and the victims view. Subseven has a
number of utilities built into it to harass the
victim of this program. Here is a list of a few
of them:
Key stroke recorders
Built in packet filters
Screen Capture
Take pictures with victims webcam
Record audio with victims microphone
Send sounds
Remove desktop items like start button, taskbar, icons,
etc..
Tic-Tac-Toe - screen becomes tictactoe board game
Matrix - screen goes black, you can send text to victim
ala The Matrix
Loud beeps
Flip the person screen upside down and sideways
Customized popup error messages
Open and close CD-ROM drive
Browse victims network neighborhood
open a telnet shell on the machine
redirect traffic from the victims machine
And much much more!
|