Live data from Hacker News

Have you ever chatted with a hacker within a virus?

blogs.avg.com

71–80 of 106 posts

Re: Have you ever chatted with a hacker within a virus?

#71
post #15

When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security. One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~1…

It's funny you should say this. I practically did the same thing, from a different perspective.

I ran my own little IRC server when I was a teenager, and one day I noticed a lot of my friends were being disconnected from the server. After some more investigation, it seemed like they were actually being disconnected completely from the Internet. Bit odd.

Upon more investigation, I found an acquaintance had something like 10,000 bots (spybot/rxbot) going through my server (yes, a simple /list could have sufficed...) and when I looked at the topic of his channels, and noticed they consisted primarily of commands to control to the botnet. "startkeylogger" sort of thing.

A few more pokes, I realised it was Norton Antivirus that was listening to port 6667 for any "bad" commands, and then disconnecting the user from the internet. I thought this was hilarious, and went to Efnet, tried it in a large channel and watched 400 people disconnect. Then I felt quite bad, so I emailed Norton, and received no reply.

Something like two years later, I notice the same exploit on the main page of Slashdot, and chaos ensured. It did make me feel pretty cool, "ha! I knew something before all you big uber leet haxxors!" :]

Sadly, my acquaintance didn't mature like the rest of us and decided to use his knowledge and skills to do naughty things, and the FBI got him. Good riddance.

Re: Have you ever chatted with a hacker within a virus?

#72

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

Does anyone know if all webcams have the activity light hardwired in-line with the webcam itself. I have always wondered if the light is a definitive indicator whether the cam is on, or if the light can be deactivated. Sorry, I guess this only applies to non-Mac, mostly Win, machines as something so plebeian as an indicator light would never make it into a Mac.

Re: Have you ever chatted with a hacker within a virus?

#73
post #71
post #15

When I was a teenager I found it fun to intentionally infect myself with malware and try to study it. I know realize this wasn't the most responsible thing to do, as I wasn't in a sandboxed environment, but it was a great learning experience and taught me a lot about networking and security. One of the biggest malwares I ever managed to infect myself with was a bot, which caused my computer to become a zombie on a ~1…

It's funny you should say this. I practically did the same thing, from a different perspective. I ran my own little IRC server when I was a teenager, and one day I noticed a lot of my friends were being disconnected from the server. After some more investigation, it seemed like they were actually being disconnected completely from the Internet. Bit odd. Upon more investigation, I found an acquaintance had something l…

That's a neat variation on the old PING +++ATH0 trick.

Re: Have you ever chatted with a hacker within a virus?

#74
post #72

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

Does anyone know if all webcams have the activity light hardwired in-line with the webcam itself. I have always wondered if the light is a definitive indicator whether the cam is on, or if the light can be deactivated. Sorry, I guess this only applies to non-Mac, mostly Win, machines as something so plebeian as an indicator light would never make it into a Mac.

The idea is for the light to be definitive, but I am not sure how secure they are. Also, as far as I can tell/remember all Macs have indicator lights on their cameras.

Re: Have you ever chatted with a hacker within a virus?

#75
post #55

Back in 2000, when I was in high school, I developed a trojan similar to netbus and sub7, but just to use it in the school comp labs. The objective was only to have fun. Telling my friends their login passwords, controling their pcs, (screen streaming, key logging, file management, mouse and kb control, some nice screen effects like making the screen move like ocean waves, launch programs, it was fun, lol). There wer…

Most of the time those moments of getting caught turn into great opportunities to get out of trouble by going white hat for them. I figure if they threatened him with any real punishment, just offer some free security consulting.

In a perfect world that might happen. Sadly people are not happy, if you point their mistakes at them and they can get very agressive against you, especially when their job or their public reputation might be at stake. Add some age difference of over 20 years and an IT education that started with punching holes into cards and you are fd. Then going to offer them your assistence wouldn't be the smart thing to do, don't u think?

Re: Have you ever chatted with a hacker within a virus?

#76
Reminds me of all the fun I had playing with malware on my own computer during the mid-to-late 90's. Being quite ignorant about the whole thing allowed me to look and find things that would not be considered safe. Hacker websites (like the old cult of the dead cow folks), exploits, etc. I remember downloading the LOIC and wondering what the hell it was.

Of course, I wanted to be a "hacker". You know, make ATM's spit out cash so my brother could buy a more powerful engine for his mustang. That kind of thing. Never really meant or even did harm, because my limited knowledge back then kept me out of trouble.

I did however get to do something very important while looking for people to "hack" (not really) on ICQ. I met my wife. Wonderful things happen by serendipity.

Re: Have you ever chatted with a hacker within a virus?

#77

Earlier quoted context omitted.

You can't? Here's a MacRuby script that can take a photo with your webcam: https://github.com/pioz/snappy .

Now, given the content of the article a moment ago, the question becomes: "Should I trust science_robot? Or is this a trojan?"

Well, just learn ruby and read the source code of snappy, then write your own camera activation code -> no problem. If you don't trust your link, go to the well known github website and search for the project yourself.

"With growing wish for self responsibility comes growing need for power."

Re: Have you ever chatted with a hacker within a virus?

#78

Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .…

Ahhh, so you were the guy that used to keep sending me messages on ICQ that just contained random URLs pointing to .exe files..

I should have probably turned my auto discoverable options off but it was actually a good way to meet chicks.

Re: Have you ever chatted with a hacker within a virus?

#79
post #18

Earlier quoted context omitted.

Except when he went on record opposing the addition of raw-sockets to Windows XP saying it would help hackers and spell the end of the world. I remember clutching my Redhat CD, just in case raw sockets were banned ;-) http://www.theregister.co.uk/2001/06/25/steve_gibson_really_...

And then you know they banned them with a nonremovable patch, right? http://seclists.org/nmap-hackers/2005/4

The limitations are listed here: http://msdn.microsoft.com/en-us/library/windows/desktop/ms74...

- TCP data cannot be sent over raw sockets.

- UDP datagrams with an invalid source address cannot be sent over raw sockets. The IP source address for any outgoing UDP datagram must exist on a network interface or the datagram is dropped. This change was made to limit the ability of malicious code to create distributed denial-of-service attacks and limits the ability to send spoofed packets (TCP/IP packets with a forged source IP address).

- A call to the bind function with a raw socket for the IPPROTO_TCP protocol is not allowed. Note: The bind function with a raw socket is allowed for other protocols (IPPROTO_IP, IPPROTO_UDP, or IPPROTO_SCTP, for example).

Also, the "half open connections" limit has been removed as of Vista.

Re: Have you ever chatted with a hacker within a virus?

#80
post #60

Earlier quoted context omitted.

How did you embed the exe client into a jpg (rather than just changing the icon)?

IIRC, Sub7 had a tool which did this. You could also 'pack' the executable. My infection vector of choice was embedding it into fake resumes and sending it to job ads...ahh, the memories...

You can add the contents of the .exe to the JPG but when the computer opens it then it isn't going to try and execute the code (it will try and render it as a graphic and probably fail) unless there is some unpatched exploit in the image viewer.
Post reply on HN