Username: 
Password: 
Restrict session to IP 

I got a Backdoor instaled while in the server  Go to the Training: Warchall - The Beginning challenge

1 2
Global Rank: 5694
Totalscore: 2581
Posts: 3
Thanks: 0
UpVotes: 0
Registered: 12y 112d
Last Seen: 12y 105d
The User is Offline
I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
I tried to play this challenge, logged in to the server, and suddenly my computer started having strange behaviour. I made a scan and it found a backdoor

Backdoor:Win32/Sdbot.gen

I demand an explanation.
Global Rank: 228
Totalscore: 94562
Posts: 1695
Thanks: 1365
UpVotes: 929
Registered: 17y 9d




Last Seen: 1d 4h
The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
I highly doubt the sshd on the box is compromised and delivers exploits for putty (assuming you use putty).
I'd more guess your malware was already installed and got active when you connected.

I recommend you re-install your operating system.
If you like you can try to reproduce the infection.

Greetings
gizmore
The geeks shall inherit the properties and methods of object earth.
Global Rank: 228
Totalscore: 94562
Posts: 1695
Thanks: 1365
UpVotes: 929
Registered: 17y 9d




Last Seen: 1d 4h
The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!1Good Post!0Bad Post! link
Someone just recommended to check where you got your ssh client from.
Maybe that's the malware Smile
The geeks shall inherit the properties and methods of object earth.
Totalscore: 316909
Posts: 98
Thanks: 106
UpVotes: 105
Registered: 15y 222d







Last Seen: 157d 10h
The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate1Thank You!4Good Post!0Bad Post! link
I feel the biggest problem here is use of windows
https://www.revolutionelite.co.uk/
Global Rank: 5694
Totalscore: 2581
Posts: 3
Thanks: 0
UpVotes: 0
Registered: 12y 112d
Last Seen: 12y 105d
The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
I was using SSH Secure Shell. And the malware was installed day 8, when I connected to the server.
Global Rank: 30260
Totalscore: 0
Posts: 267
Thanks: 245
UpVotes: 182
Registered: 25y 92d
Last Seen: 1s
The User is Online
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
Or dloser was at it...again Drool
Global Rank: 1
Totalscore: 758677
Posts: 437
Thanks: 497
UpVotes: 470
Registered: 15y 213d












The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
LOL! I just reversed the polarity of his connection such that I could upload to his computer. n00bs.
Global Rank: 5694
Totalscore: 2581
Posts: 3
Thanks: 0
UpVotes: 0
Registered: 12y 112d
Last Seen: 12y 105d
The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
Yeah. Perhaps you would be able to do that if the backdoor was still installed.
Global Rank: 1
Totalscore: 758677
Posts: 437
Thanks: 497
UpVotes: 470
Registered: 15y 213d












The User is Offline
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
Why install one if you can install two for the double the price?
Global Rank: 30260
Totalscore: 0
Posts: 267
Thanks: 245
UpVotes: 182
Registered: 25y 92d
Last Seen: 1s
The User is Online
RE: I got a Backdoor instaled while in the server
Google/translate0Thank You!0Good Post!0Bad Post! link
Obviously the attacker is one of those above as he already removed the backdoor. Sad
1 2
Redknee, mihajatiana, tunelko, silenttrack, n0tHappy, nonfungiblesecurity, quangntenemy, TheHiveMind, Z, balicocat, Ge0, samuraiblanco, arraez, jcquinterov, hophuocthinh, alfamen2, burhanudinn123, Ben_Dover, stephanduran89, braddie0, SwolloW, dangarbri, csuquvq have subscribed to this thread and receive emails on new posts.
1 people are watching the thread at the moment.
This thread has been viewed 17910 times.