Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .exe file. You could also provide an ICQ account number that would get a message any time the client comes online, with the relevant IP:port to connect to. These were in the days before anti-virus or firewalls were prevalent, so it was pretty easy to trick people into opening an infected .exe.
I think I ended up having around 80 people infected, so there was always someone online. I never did anything malicious with it, just chatting and opening/closing CD-ROM drives mostly (and juvenile things like sending my friend's browser to bigboobs.com ... unfortunately his dad was standing behind him at the time). I had dial-up so the webcam viewing wasn't feasible. If someone was freaked out and wanted me to go away I could remotely destroy the trojan. Come to think of it, most people were just curious about what was going on and didn't seem to mind the chat very much (but obviously they usually wanted me to remove it / delete it afterward). Then again, I infected people by random selection on ICQ, so maybe they were just chatty people.
I used to do the same stuff, we didn't even see it as malicious back then, just a "prank" really. Most the people we "infected" were via IRC and ICQ, embedding the exe client into a JPG (or just changing the exe icon to a JPG one) and DCC'ing it to them.
Once infected, we'd screw around, make errors pop up on their screen like "Computer Is Low On Coffee, Please Insert Coffee Cup" then make CD tray eject, etc. Then we'd chat to them, and they usually had a good laugh, and we'd tell them how to not get infected in the future, then self-destruct the client.
We didn't really investigate it much or ponder the deeper implications behind it, so it took us a fair while to realise the level of maliciousness that was possible, which scared us off, so we stopped messing with it (we'd already been in trouble for other stuff so didn't want to push it!)
The fake resume idea is brilliant. How could I have overlooked that back in the days. All I did as a script kiddie was scanning IP ranges and playing with infected accounts. Good times.
You can add the contents of the .exe to the JPG but when the computer opens it then it isn't going to try and execute the code (it will try and render it as a graphic and probably fail) unless there is some unpatched exploit in the image viewer.
It would create a .exe file that was a simple image viewer and give it the standard .jpg icon. You would name it something like picture003.jpg.exe and most people's computer would conveniently hide the true file extension.
> so it was pretty easy to trick people into opening an infected .exe.
I remember telling this guy it was a fake virus (the jokes you could download on internet before) and that he had to turn off his anti virus to launch it. It worked.
Does anyone know if all webcams have the activity light hardwired in-line with the webcam itself. I have always wondered if the light is a definitive indicator whether the cam is on, or if the light can be deactivated. Sorry, I guess this only applies to non-Mac, mostly Win, machines as something so plebeian as an indicator light would never make it into a Mac.
The idea is for the light to be definitive, but I am not sure how secure they are. Also, as far as I can tell/remember all Macs have indicator lights on their cameras.
Comments
Well, back in my pre-teen script kiddie days of using BO2K/Netbus and early Sub7 builds I was on the other side of the screen. Sub7 I recall distinctly had all the listed features and a lot more - keylogging, chat client, webcam viewing, screen capture, open/closing CD tray, etc. There was a GUI interface that would let you select any of the above features that would create a payload that could be injected into any .exe file. You could also provide an ICQ account number that would get a message any time the client comes online, with the relevant IP:port to connect to. These were in the days before anti-virus or firewalls were prevalent, so it was pretty easy to trick people into opening an infected .exe.
I think I ended up having around 80 people infected, so there was always someone online. I never did anything malicious with it, just chatting and opening/closing CD-ROM drives mostly (and juvenile things like sending my friend's browser to bigboobs.com ... unfortunately his dad was standing behind him at the time). I had dial-up so the webcam viewing wasn't feasible. If someone was freaked out and wanted me to go away I could remotely destroy the trojan. Come to think of it, most people were just curious about what was going on and didn't seem to mind the chat very much (but obviously they usually wanted me to remove it / delete it afterward). Then again, I infected people by random selection on ICQ, so maybe they were just chatty people.
I used to do the same stuff, we didn't even see it as malicious back then, just a "prank" really. Most the people we "infected" were via IRC and ICQ, embedding the exe client into a JPG (or just changing the exe icon to a JPG one) and DCC'ing it to them.
Once infected, we'd screw around, make errors pop up on their screen like "Computer Is Low On Coffee, Please Insert Coffee Cup" then make CD tray eject, etc. Then we'd chat to them, and they usually had a good laugh, and we'd tell them how to not get infected in the future, then self-destruct the client.
We didn't really investigate it much or ponder the deeper implications behind it, so it took us a fair while to realise the level of maliciousness that was possible, which scared us off, so we stopped messing with it (we'd already been in trouble for other stuff so didn't want to push it!)
How did you embed the exe client into a jpg (rather than just changing the icon)?
IIRC, Sub7 had a tool which did this. You could also 'pack' the executable.
My infection vector of choice was embedding it into fake resumes and sending it to job ads...ahh, the memories...
The fake resume idea is brilliant. How could I have overlooked that back in the days. All I did as a script kiddie was scanning IP ranges and playing with infected accounts. Good times.
You can add the contents of the .exe to the JPG but when the computer opens it then it isn't going to try and execute the code (it will try and render it as a graphic and probably fail) unless there is some unpatched exploit in the image viewer.
It would create a .exe file that was a simple image viewer and give it the standard .jpg icon. You would name it something like picture003.jpg.exe and most people's computer would conveniently hide the true file extension.
I was reading that article thinking "I remember all of those features (and more) being in Sub7 about 12-13 years ago". Not so advanced, really.
Did BO2K/Sub7 allowed to be notified when being debugged ? Maybe it's an easy 'plugin' to write when you have a flexible payload generator I guess.
> so it was pretty easy to trick people into opening an infected .exe.
I remember telling this guy it was a fake virus (the jokes you could download on internet before) and that he had to turn off his anti virus to launch it. It worked.
I remember the joys of LAN gaming with friends. "Oi, who rotated my screen!"
Ahhh, so you were the guy that used to keep sending me messages on ICQ that just contained random URLs pointing to .exe files..
I should have probably turned my auto discoverable options off but it was actually a good way to meet chicks.
Does anyone know if all webcams have the activity light hardwired in-line with the webcam itself. I have always wondered if the light is a definitive indicator whether the cam is on, or if the light can be deactivated. Sorry, I guess this only applies to non-Mac, mostly Win, machines as something so plebeian as an indicator light would never make it into a Mac.
Nice try with the jab at Apple—MacBook Pros have a small green light to indicate whether the camera is in use or not.
Yeah, you can just take a quick pic using the camera; the light flashes for barely a second and you won't notice. Metasploit has a stager for exactly this purpose: http://www.metasploit.com/modules/payload/osx/x86/isight/rev...
There's always a bit of black cardboard and tape. Try to take a picture now. :)
Lol, I actually have a bit of duct tape over my eeePC web cam.
The idea is for the light to be definitive, but I am not sure how secure they are. Also, as far as I can tell/remember all Macs have indicator lights on their cameras.
A GUI interface, eh? :P