Vulnerability Development mailing list archives

Re: -= Unsek Tecnics =-


From: H D Moore <hdm () SECUREAUSTIN COM>
Date: Tue, 6 Mar 2001 22:22:04 -0600

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tuesday 06 March 2001 12:48 pm, H C wrote:
I run nc ... to open ports (services how backdoors)
in WinNT4.0+SP6 ... but
while i'm using it stay with a cmd.exe running... :/
How can i run nc.exe to open a port...without open a
cmd.exe on a screen??

Your point?  If you want something that hides from the
Task Manager, get Sub7.

Or modify the source to call the RegisterServiceProcess Win32 API call.
There is an open source VB trojan called 'Acid Shiver' which used this method
to hide.

- -HD
-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8

iQA/AwUBOqW3bDwRvqMPEDLhEQJd9gCg0UTPIHxgNVP7LHX4T6JH5DzVZiIAoJB/
4INjVMeMcQjZNOVWmIrgXMSX
=W/qr
-----END PGP SIGNATURE-----


Current thread: