![]() |
|
[SIMPLE] Backdooring a box after you gain root - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: [SIMPLE] Backdooring a box after you gain root (/Thread-SIMPLE-Backdooring-a-box-after-you-gain-root) |
[SIMPLE] Backdooring a box after you gain root - superMAUS - 04-27-2014 Backdooring a box after you gain root Using backdoors such as Jynx (http://www.blackhatlibrary.net/Jynx) is really not advisable considering the speed at which rkhunter or anyother rootkit hunter that searches for known rootkits will find it. Infact its probably better to just backdoor a daemon/service that is already running on the box and then replace the legitimate one with the backdoored one. Ill demonstrate this with OpenSSH as its opensource and probably THE most commong ssh daemon. All Im going to do is download the source code (http://www.openssh.com/) and modify the authentication code. Lets take this example for instance: Code: if (pw->pw_uid == 0 && options.permit_root_login != PERMIT_YES)
ok = 0;Now if you C illiterate this will basically check whether or not the uid of the user that is logging in is 0 (root) and if it is and it isnt allowed then it will tell it that its not ok. Now the function that this is in is called auth_passwd and so if we simple return at this point our backdoor will function well if we simply try and login as root. Now just compile the code (./configure; make; sudo make install) and copy the binary to your home directory as whatever (cp <path to sshd> /home/sshdoor). Then on a victim machine wget it and then replace the sshd with it. Anyway this is very basic stuff but thanks to Reiko for suggesting the idea of backdooring an SSH daemon.Also bear in mind this can be applicable to basically any opensource service.Also you probably want to poke some more around yourself before allowing anyone to login as root because root is the most targetted user and youll get alot of intruders, I didnt want to spoonfeed too much :3 RE: [SIMPLE] Backdooring a box after you gain root - Reiko - 04-27-2014 rkhunter finds this immediately too ![]() You can update the rkhunter database after installation and that'll buy you a few days though RE: [SIMPLE] Backdooring a box after you gain root - Alan Turing - 04-27-2014 nice tutorial bby, good as always RE: [SIMPLE] Backdooring a box after you gain root - superMAUS - 04-28-2014 (04-27-2014, 07:59 PM)Reiko Wrote: rkhunter finds this immediately too aw... really? what update rkhunter on the other box? how does rkhunter find it? Does it compare the installed openssh to the fake one? (04-27-2014, 08:44 PM)Kosaki Wrote: nice tutorial bby, good as always How very kind ;3 RE: [SIMPLE] Backdooring a box after you gain root - Pheonix - 04-28-2014 I enjoyed the read, good work. RE: [SIMPLE] Backdooring a box after you gain root - Reiko - 04-28-2014 (04-28-2014, 12:54 AM)vegimite Wrote: aw... Compares known good string dumps and md5 (or sha, depending on how new the rkhunter is and how its configured) hashes RE: [SIMPLE] Backdooring a box after you gain root - superMAUS - 04-28-2014 (04-28-2014, 01:28 AM)Pheonix Wrote: I enjoyed the read, good work. Cheers ;3 (04-28-2014, 01:48 AM)Reiko Wrote: Compares known good string dumps and md5 (or sha, depending on how new the rkhunter is and how its configured) hashes Oh well, Im sure they dont check all the daemons do they? |