Vulnerability Development mailing list archives

Re: -= Unsek Tecnics =-


From: Nelson Brito <nelson () SECUNET COM BR>
Date: Thu, 9 Mar 2000 14:57:16 -0300

H C wrote:

And I note too, that while this is running...it
create a process in
taskmanager ...!!!
Anybody know a mode of put it in high ??

Use some NTRK's tools to do this. In NTRK you'll see
a lot of tools, actualy one, to do this. Try
"PVIEWER.EXE". Notice: you'll need Admin status. If
you do not have, forget it.

Nelson,

How would PVIEWER help hide nc from showing up as a
running process in Task Manager?

Forgive me, the "PVIEWER.EXE" don't hides the proccess. Take a look at the original message, the question was: Anybody 
know a mode of put it in high
??

To put the proccess in HIGH Priority you could use "PVIEWER.EXE" remotely and "TASKMRG.EXE" localy.

To hide a proccess you can use the power, read the ntrootkit's code, or read the HD Moore message.


__________________________________________________
Do You Yahoo!?
Get email at your own domain with Yahoo! Mail.
http://personal.mail.yahoo.com/

Sem mais,
--
Nelson Brito
"Windows NT can also be protected from nmap OS detection scans thanks
to *Nelson Brito* ..."
              Trecho do livro "Hack Proofing your Network", página 93


Current thread: