Re: Internet SSH scans

[email protected] Tue, 21 Mar 2006 20:14:26 -0500
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
On Tue, 21 Mar 2006 16:20:46 -0200, Adriano Carvalho said:

> 2) Hide ssh service. How ? Try SAdoor
> (http://packetstormsecurity.org/UNIX/penetration/rootkits/index6.html)
> 
> From packetstorm:
> "SADoor is a non-listening remote administration tool for Unix systems. It
> sets up a listener in non-promiscuous mode for a specific sequence of packets
> arriving to the interface before allowing command mode. The commands are sent
> Blowfish encoded in the TCP payload and decoded and passed on to system(3)."
> 
> Its cool, and good to hide some services...

Of course, if the password is ever compromised, you'll then be left wondering
how things are getting run, because you forgot you installed it. :)
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFEIKTycC3lWbTT17ARArazAKCJfEjSiekWBIWftOhgZDbfric4jwCcDI7l
cMD5OkuxtSK4LDRz/cFLAYY=
=V8mO
-----END PGP SIGNATURE-----