[kwlug-disc] Mysterious filtered ports on a server

B.S. bs27975.2 at gmail.com
Wed Oct 26 16:27:58 EDT 2016


On 10/26/2016 02:59 PM, Andrew Kohlsmith (mailing lists account) wrote:
>> On Oct 26, 2016, at 2:53 PM, CrankyOldBugger
>> <crankyoldbugger at gmail.com> wrote: I was not aware that IRC could
>> carry the seeds of destruction...  But then again, I'm not a heavy
>> IRC user.  I'm surprised that you can run scripts in IRC.  I
>> thought it was bare bones text only, but I'll take your word for
>> it.
>
> It is. So is SMTP and HTTP, JSON calls are all (can be) just text
> blobs.
>
> you could use OTR and encrypt over IRC as well, or just ROT13 it all.
> Or Base64 or MIME-encode the data, but really you don’t need anything
> more than “ping $IP” or “ddos $TARGET”…


To Papa:

I am at internal IP a.b.c.d. You can tell my public ip. Please tell me 
my name, and what command you would like me to execute.

xox


To Child4567:

Execute: encrypt -key 765476978698765 --in-place *.*

(Don't forget to let the dog out.)



It's all just data travelling over packets, over any ol' port. Embed a 
busybox within yourself, and all kinds of functionality, like ping, is 
present - regardless of whether the usual binaries for such are installed.

"Bad guys need to eat too."

<sigh>





More information about the kwlug-disc mailing list