Penetration Testing mailing list archives

Re: [PEN-TEST] Auditing for Malicious Tools


From: Knowledgebase i-Net Security <knowledgebase () LYCOS COM>
Date: Tue, 22 Aug 2000 15:57:52 -0900

 Well actually ISS is good but i recommend u to use some tools like nmap and other perl scripts and a Customized ONE 
coz` it's really defines the problem and u would be able to discover one./.. one like any other commercial tools they 
are just have a broad knowledgebase w/c they rely... try to use some downloadble perl scripts for penetration testing 
and Vulnerability checking in Packetstorm... and try to modify one... it's very nice... thanks..

Abraham
Internet information security research engr

 ----------
--

On Mon, 21 Aug 2000 20:59:44
 Curphey, Mark (ISS Atlanta) wrote:
I don't know of any specific tools but It should be easy enough to do under
NT. Most software is installed under HKEY_LOCAL_MACHINE\SOFTWARE. I say most
'cause some things like Brutus for instance don't install a registry entry.
Of course you need to have remote registry access. Ideally you would check
both binaries, reg entries and dll's and correlate. If there is no reg entry
it is quite tough, without grepping the entire volume again Brutus as an
example could be anywhere, and hidden by renaming the binary I guess ? Again
you need file access. So I guess you can but not sure how confident you can
be of the results.

A simple Perl script should be able to check the reg, file existence and
values etc.

If you have an ISS scanner license we have some flex checks that will find
windows tools like l0pht crack, ISS Scanner, Retina, by doing exactly the
above, and I assume all other commercial tools you could do the same pretty
easily. Not supported or accurate (for the reasons mentioned above) but
sometimes useful.

-----Original Message-----
From: Netsecure [mailto:netsecure () NETSECURE NET NZ]
Sent: Sunday, August 20, 2000 5:54 PM
To: PEN-TEST () SECURITYFOCUS COM
Subject: Auditing for Malicious Tools


Hi Everyone

I am looking for an application that searches fo malicious tools. I believe
someone in the UK has written one but I am unable to find it on search
engines. Does anyone no of such tools ? They look for realeased hacking
tools this application should not just look for trojans (which virus
scanners already do) But complied and released tools like nessus, SMBgrind,
etc.

Cheers
Netsecure



Send your favorite photo with any online greeting!
http://www.whowhere.lycos.com/redirects/americangreetings.rdct


Current thread: