Security Incidents mailing list archives

"closed-port" backdoors


From: Andreas Hasenack <andreas () CONECTIVA COM BR>
Date: Wed, 21 Mar 2001 17:03:49 -0300

Has somebody seen in the wild a type of backdoor where
no ports are open until a specifig set of packets are sent
to the machine?
For example, the backdoor would only bind to port X if
the machine receives SYN packets to three other ports in
sequence. I've seen code to do this (and sorry if it's not
new), but I haven't seen rootkits using it.


Current thread: