Quote:
Originally Posted by BestXXXPorn
LOL it appears a crack for VirtuaGirl contains a trojan specifically designed to DOS attack, YOU! LOL... although you're probably not laughing...
The real question you need to answer is whether this trojan is preset or it's drawing instructions from a remote box...
The only way to do that is download the trojan and reverse engineer it. Get a clean os install, disable all unnecessary services... Download Wireshark, shut down all other programs... install the trojan and monitor the packets coming across the wire. Record the IP and port...
That will most likely lead you to a compromised box somewhere... so... you can try hacking in yourself or get the hosting company to put you in contact with the owner of the box...
Once you're in you'll need to take a look at all services and see what is listening on the port the trojan is communicating with... Then take a look at that script that's listening and determine if it also listens for an admin... or if there's another service running on a separate port that listens for an admin.
If there is you'll need to setup some monitoring so whenever that port is accessed you record the IP address...
From there it'll be a series of hops back to the hacker (if he's even half way decent) and you'll have to gain access to the box or get the host to give you the logged IPs... of course... if the box is already compromised it's likely there's no logging for specific IPs...
So there ya go, have fun with that one... $2k isn't much for all the work that's involved... read, weeks... and even then it's highly unlikely you'll actually catch the guy.
Frustrating as hell isn't it?
|
thanks for a (not very optimistic) but great post. right now we're working at dodging/filtering the attack hopping we can move faster than him. $2k is just to find tracks he might have left elswere in the past, the two other guys involved seemed unlikely too till they made a few small mistakes. that's for the trojan info, that's real big help.