60
1 Information Weapon: Concepts, Means, Methods …
1.6 Typical Examples of Viruses and Trojans
1.6.1 NetBus Virus
NetBus is a backdoor virus. Viruses of this type, attacking the victim’s computer
and infecting it, reserve a port for themselves and get added to autoload, provided
they are programmed for it. Then the attacker (client or command center hunter)
can connect to this computer (IP address and, in some cases, server password are
required) and do whatever he wants with it (the possibilities are limited only by the
virus capabilities). Thus, the server becomes the “eyes” and “hands” on the victim’s
computer.
NetBus is easier to use than Back Orifice, which we will consider in more detail
below.
The original NetBus package contains the following files:
• NetBus.exe—client (control center).
• Patch.exe—server. It is written in Inprise Delphi.
• NetBus.rtf—NetBusˆ description by the author.
To infect the victim’s computer, a NetBus server (Patch.exe) shall be run on it.
It can be run as a regular console program or as a CGI application (from a web
browser). For this purpose, the following keys can be used:
• /noadd—for one-time use of NetBus. The server only loads into RAM, is not
copied to the Windows folder, and does not add its key to the registry;
• /port: x—indicates a port to take (12345 by default), where x is the port number.
This key appeared in version 1.7;
• /pass’-x—assigns a password to access the server, where x is the password;
• /remove—removes the server from RAM and the key in the registry for
autoloading (the server itself is not removed from the Windows folder).
After running Patch.exe, the server creates its own copy in the Windows folder
(NetBus is written for Windows NT/9x), as well as a Patch.ini configuration file and
a KeyHook. dll file. Then the server adds the key to the registry for its autostart at the
Windows start-up.
Key: [HKEY_CURRENT_USER\Software\Microsoft\Wmdows\Current\fersion
\Run]
Parameter: Patch
Parameter value: C:\Windows\Patch.exe/nomsg
It is worth noting that if the server had a different name (for instance, cool.exe),
then, accordingly, the files in the Windows folder will change to cool. The registry
key’s value name will be cool, too! Remember that if you run the server without
keys (/port or/pass), a key is created in the registry to match the server name (for
example, HKEY_CURRENT_USER\PATCH\). If the server is run with keys, then
the Patch.ini configuration file is created (containing information on the password,
port, etc.).
Précédent

- 82/839

Suivant