Site Statistics
 
Threads: 3,718
Posts: 16,702
Members: 2,844
Users Online: 12
Newest Member: Boydaysop


Go Back   PC101 > PC Software > PC Security

PC Security Stop Spyware, Hackers and Identity thieves. Info re: Viruses, trojans, removal, etc...

Reply
 
LinkBack Thread Tools Display Modes
Old 08-03-2006, 11:38 PM   #1
zentha
Junior Member
 
Join Date: Aug 2006
Posts: 5
Rep Power: 0 zentha is on a distinguished road
R.A.T. Hacking Tools

Guys beware of this, if your a hacker do nt use this! If your the victom, i want you to be careful, I want to warn you about being hacked, or dicipline of hacking!

Here's a short note:
Hacker: You'll get a trojan
Victom: Hacker has all control of your computer, dmaging.

Here's a basic info about ONE of the R.A.T.

Sub7 (also known as Backdoor-G and all of its variants) is the most well known Trojan / backdoor application available. As far as hacker tools go, this one is one of the best.

Sub7 arrives as a Trojan. According to Internet security firm Hackguard, these are the statistics for how one might come to be infected with a Trojan horse program:

# Download an infected email attachment: 20%
# Download an infected file from the Internet: 50%
# Get an infected file on a floppy disk, CD or network: 10%
# Download because of an exploited bug in Internet Explorer or Netscape: 10%
# Other: 10%

Because of its many uses, you may receive it from someone you would normally trust- a friend, spouse or co-worker. By virtue of being a Trojan horse program it comes hidden within a seemingly legitimate piece of software. Executing the software will do whatever the application is supposed to do while installing Sub7 in the background.

Upon installing Sub7 will open a backdoor (enabling a port that you are not aware is open) and contact the attacker to notify them that Sub7 is installed and ready to go. This

Once installed, Sub7 is essentially all-powerful. The hacker at the other end will be able to do any of the following and more:

# Add, delete or modify any files
# Log your keystrokes and capture things like your passwords and credit card numbers
# Add programs like other Trojan and backdoor programs or Distributed Denial-of-Service applications
# Anything you can do on your computer...

The Sub7.org site seems to be defunct. Many sites refer to the main Sub7.org web site for hackers to download the latest version of Sub7 as well as for finding the directions for how to use it. However, just because Sub7.org seems to be gone doesn't mean Sub7 is. A new release was introduced at the beginning of March, 2003.

Developers continue to modify, tweak and improve Sub7 and with each subsequent release it is often just different enough to evade the antivirus detection designed to pick up previous versions.

Often with Trojan horse programs like this the attacker will change the name of executable files to avoid detection. The executable can be named anything as long as the attacker knows what its called. Sometimes the Trojan may even have been hidden in a system file. The Trojan-infected system file will replace the real system file, but still work as it should. The impact of this is that you can't simply "delete" the Trojan-infected file without disabling the operating system.

Some of the "1337 h4x0rz" (elite hackers in "hacker-speak") frown upon Sub7 as a tool for novices and script-kiddies. That doesn't stop this utility from being a useful tool for hackers and a threat to you- it just means that the hacker using it will get no respect from you OR the 1337 h4x0rz.

To protect yourself, you should never download or install any program from any person or web site you don't implicitly trust. You should also have your operating system patched and be running updated antivirus software to narrow the possible methods of getting this Trojan into your system. Lastly, think twice about whether bizarre activity on your computer is a "fluke". You can use a tool like Ad-Aware to scan your system for known spyware if you think you may have something.
zentha is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-04-2006, 12:34 PM   #2
Lyte
Forum Staff
 
Lyte's Avatar
 
Join Date: Oct 2005
Location: Good ol' U.S. of A
Posts: 3,035
Rep Power: 6 Lyte is on a distinguished road
Send a message via MSN to Lyte Send a message via Yahoo to Lyte Send a message via Skype™ to Lyte
Quote:
Originally Posted by zentha
Often with Trojan horse programs like this the attacker will change the name of executable files to avoid detection.
Interesting post! One example of the above point is syhost.exe vs. svhost.exe. The former is a known virus while the later is a necessary part of your computer system. If you were looking through your system and not paying close attention to every character/detail you'd miss this infection!

Lyte
Lyte is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Five Tools To Bulletproof Firefox Will.Spencer The Internet 2 07-26-2006 04:51 PM
Spyware Removal Tools roadrage PC Security 1 03-24-2006 02:16 AM
Ethical hacking can ensure computer security... Lyte PC Security 0 01-23-2006 06:01 PM



Flex Development


Our partners:



All times are GMT -5. The time now is 10:16 PM.

Powered by vBulletin Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
Design by vBSkinworks

Copyright © PC101 and PC101.com Computer Forum. All rights reserved.