Live data from Hacker News

Have you ever chatted with a hacker within a virus?

blogs.avg.com

1–10 of 106 posts

Re: Have you ever chatted with a hacker within a virus?

#2
Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker.

And, infamously, got DDOSed for it.

Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

Re: Have you ever chatted with a hacker within a virus?

#3

Steve Gibson (grc.com) famously used chatroom credentials in a trojan he reverse-engineered to get in and chat with the bot maker. And, infamously, got DDOSed for it. Can't find the transcript now, which is a shame; I think he took it offline to let the intertubes cool down.

http://www.crime-research.org/library/grcdos.pdf I think this is what you are talking about, really interesting read if I remember correctly.

Re: Have you ever chatted with a hacker within a virus?

#8
"I am sorry but AVG blogs are currently undergoing essential maintenance.

Normal service will be resumed shortly, in the meantime go to AVG.com for more information about AVG products or go to our Facebook page to join our thriving online community.

We apologise for any disruption this may have caused."

Re: Have you ever chatted with a hacker within a virus?

#9
Not the same, but similar story... 6-8 years ago, I chatted directly with the person responsible for breaking into a web server on the server itself. It's a strange feeling to ssh in and watch someone browsing through files. I did a 'echo "hello?" | wall', showed the guy how to answer me back, and we eventually moved the conversation to IRC. I was using some website to convert English to Portuguese.

Turns out it was a (young) teenager from Brazil. His compromise was that he wouldn't touch our files or deface our websites so long as he could remain in control of the server. I carelessly tried to kick him off, uninstall the rootkit and restart the server only to find out that he could continue to use the same exploit to get access. Then we just called our host and asked them to take down the box. Lost a whole day to it, but I walked away understanding a little bit more about motivation, and learned about an exploit that I hadn't known about previously.

Re: Have you ever chatted with a hacker within a virus?

#10
Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .exe file. You could also provide an ICQ account number that would get a message any time the client comes online, with the relevant IP:port to connect to. These were in the days before anti-virus or firewalls were prevalent, so it was pretty easy to trick people into opening an infected .exe.

I think I ended up having around 80 people infected, so there was always someone online. I never did anything malicious with it, just chatting and opening/closing CD-ROM drives mostly (and juvenile things like sending my friend's browser to bigboobs.com ... unfortunately his dad was standing behind him at the time). I had dial-up so the webcam viewing wasn't feasible. If someone was freaked out and wanted me to go away I could remotely destroy the trojan. Come to think of it, most people were just curious about what was going on and didn't seem to mind the chat very much (but obviously they usually wanted me to remove it / delete it afterward). Then again, I infected people by random selection on ICQ, so maybe they were just chatty people.

Post reply on HN