<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Chinese hackers turn PCs into zombies with MS08-067</title>
	<atom:link href="http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/</link>
	<description></description>
	<lastBuildDate>Sat, 24 Dec 2011 19:52:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: jumper</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1453</link>
		<dc:creator>jumper</dc:creator>
		<pubDate>Fri, 14 Nov 2008 19:24:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1453</guid>
		<description>There are separate checkboxes for TCP and SYN.  They are for scanning port 445 for windows boxes that might be vulnerable.  TCP is for full connect and SYN is for half open.

The site field is where the pwn3d machine will download a backdoor from.  This tool doesn&#039;t give you a shell or anything it uses a download and execute payload.

The exploit was ripped from the Ph4nt0m code which you can find on milw0rm.  You can use your own shellcode.  The Ph4nt0m exploit just has a bind shell payload from metasploit.

The author of the tool has removed it from his website without any explanation.  Hopefully someone will post something to the boards tonight so we can figure out why.</description>
		<content:encoded><![CDATA[<p>There are separate checkboxes for TCP and SYN.  They are for scanning port 445 for windows boxes that might be vulnerable.  TCP is for full connect and SYN is for half open.</p>
<p>The site field is where the pwn3d machine will download a backdoor from.  This tool doesn&#8217;t give you a shell or anything it uses a download and execute payload.</p>
<p>The exploit was ripped from the Ph4nt0m code which you can find on milw0rm.  You can use your own shellcode.  The Ph4nt0m exploit just has a bind shell payload from metasploit.</p>
<p>The author of the tool has removed it from his website without any explanation.  Hopefully someone will post something to the boards tonight so we can figure out why.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CBRP1R8</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1449</link>
		<dc:creator>CBRP1R8</dc:creator>
		<pubDate>Fri, 14 Nov 2008 14:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1449</guid>
		<description>TCP SYN is probably a tcp syn flood attack scan which is why its setting the 800 thread threshhold to attempt. A lot of attack tools do utilize the syn flood attack scan. 

The site field is kinda handy though.....I just built out another linux server in our lab I think i&#039;ll load apche on it and make a fake website to serve this out on (if i can find it) within our lab see how and if our systems can be compromised and what other mitigation factors I can take with it since we have nokia firewalls in place too in the simlab I can test this from an outside environment look to get a feel for attack methodology.

cheers for this find though, i&#039;ll keep an eye out for this to try to download.</description>
		<content:encoded><![CDATA[<p>TCP SYN is probably a tcp syn flood attack scan which is why its setting the 800 thread threshhold to attempt. A lot of attack tools do utilize the syn flood attack scan. </p>
<p>The site field is kinda handy though&#8230;..I just built out another linux server in our lab I think i&#8217;ll load apche on it and make a fake website to serve this out on (if i can find it) within our lab see how and if our systems can be compromised and what other mitigation factors I can take with it since we have nokia firewalls in place too in the simlab I can test this from an outside environment look to get a feel for attack methodology.</p>
<p>cheers for this find though, i&#8217;ll keep an eye out for this to try to download.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jumper</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1441</link>
		<dc:creator>jumper</dc:creator>
		<pubDate>Thu, 13 Nov 2008 16:06:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1441</guid>
		<description>The page link is just a discussion about the program.  I think you have to get it from the author for now.  It will eventually show up on all of the other tools sites though.

It is pretty easy to figure out how to use it.

Start IP:  11.22.33.44
End IP  44.33.22.11

Number of Threads:  800  Port:  445

Scan Type:  TCP   SYN

Site to download trojan from:  http://www.google.cn/server.exe

===========================
800 threads seems like a lot to me but I&#039;m sure that is what that field is for.  Under scan type, TCP probably means a full connect scan and SYN is half-open.</description>
		<content:encoded><![CDATA[<p>The page link is just a discussion about the program.  I think you have to get it from the author for now.  It will eventually show up on all of the other tools sites though.</p>
<p>It is pretty easy to figure out how to use it.</p>
<p>Start IP:  11.22.33.44<br />
End IP  44.33.22.11</p>
<p>Number of Threads:  800  Port:  445</p>
<p>Scan Type:  TCP   SYN</p>
<p>Site to download trojan from:  <a href="http://www.google.cn/server.exe" rel="nofollow">http://www.google.cn/server.exe</a></p>
<p>===========================<br />
800 threads seems like a lot to me but I&#8217;m sure that is what that field is for.  Under scan type, TCP probably means a full connect scan and SYN is half-open.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CBRP1R8</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1440</link>
		<dc:creator>CBRP1R8</dc:creator>
		<pubDate>Thu, 13 Nov 2008 14:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1440</guid>
		<description>to bad this isn&#039;t available in english. I wouldn&#039;t mind testing this out in my lab environment. I can&#039;t read anything on the page link :(</description>
		<content:encoded><![CDATA[<p>to bad this isn&#8217;t available in english. I wouldn&#8217;t mind testing this out in my lab environment. I can&#8217;t read anything on the page link <img src='http://www.thedarkvisitor.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heike</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1424</link>
		<dc:creator>Heike</dc:creator>
		<pubDate>Wed, 12 Nov 2008 04:00:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1424</guid>
		<description>Jumper,

Try &lt;a href=&quot;http://www.tuhigh.com/group/revertTopic/348/2682&quot; rel=&quot;nofollow&quot;&gt; this address&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Jumper,</p>
<p>Try <a href="http://www.tuhigh.com/group/revertTopic/348/2682" rel="nofollow"> this address</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heike</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1423</link>
		<dc:creator>Heike</dc:creator>
		<pubDate>Wed, 12 Nov 2008 03:41:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1423</guid>
		<description>Good luck with that invite...I&#039;ll try to find another download site.  ;)</description>
		<content:encoded><![CDATA[<p>Good luck with that invite&#8230;I&#8217;ll try to find another download site.  <img src='http://www.thedarkvisitor.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jumper</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1422</link>
		<dc:creator>jumper</dc:creator>
		<pubDate>Wed, 12 Nov 2008 02:05:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1422</guid>
		<description>Thanks for tracking it down.  I just need an invite to the VIP area of the site to DL it.

If you controlled 100,000 computers, what would you install on them besides lolcats?</description>
		<content:encoded><![CDATA[<p>Thanks for tracking it down.  I just need an invite to the VIP area of the site to DL it.</p>
<p>If you controlled 100,000 computers, what would you install on them besides lolcats?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heike</title>
		<link>http://www.thedarkvisitor.com/2008/11/chinese-hackers-turn-pcs-into-zombies-with-ms08-067/comment-page-1/#comment-1421</link>
		<dc:creator>Heike</dc:creator>
		<pubDate>Tue, 11 Nov 2008 20:53:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.thedarkvisitor.com/?p=729#comment-1421</guid>
		<description>Jumper,

You should have an e-mail with the download site for the program in your inbox.  Happy hunting!

Uhmmm, you&#039;re kidding about the photo-rotating kitten thingy, right?!?  RIGHT?!! :)</description>
		<content:encoded><![CDATA[<p>Jumper,</p>
<p>You should have an e-mail with the download site for the program in your inbox.  Happy hunting!</p>
<p>Uhmmm, you&#8217;re kidding about the photo-rotating kitten thingy, right?!?  RIGHT?!! <img src='http://www.thedarkvisitor.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

