Back in the days I used to do this. I would stay up better part of the night adding random people to MSN or ICQ and sending the Trojan saying it was my picture. So before sending it I would describe myself as someone they'd want to see, to drive up their curiosity, basically I'll be what they'd want me to be. This was very successful. I never maintained a big list of zombied boxes, I'd infect remove on a per night basis depending on how bored I was.
I also saw the progression of hiding IP's in MSN connections. At first they would make a direct connection, later they only made a direct connection while transferring files bigger than a certain size. They completely removed it after some point, don't remember very well.
After I got to know more about networking how things are connected, I realized that my ISP allowed to initiate NULL sessions to other customers. I remember how excited I was to find this. I would place the RATs everywhere with curious names in hopes for them to click or just test exploits on them.
Another interesting thing I found was I was able to invite anyone, even random emails (Hotmail) while having a group chat. I had so much fun doing that back then.
After infection it was basically just chatting, messing with the LED's, CD-ROM's.. people were more interested in finding out how I did it and just chat rather than being mad. I remember one time when I did this to a friend he got scared and ripped of the cable breaking the wall socket.
It was really easy to evade anti-virus programs at the time. I usually just split the file into half, run the scanner on it, split again until I narrowed down to the signature and would just change a value or two.
It was interesting to see how many times people change the text before hitting send while chatting. Obviously I was too naive to know and respect privacy back then.
Comments
Back in the days I used to do this. I would stay up better part of the night adding random people to MSN or ICQ and sending the Trojan saying it was my picture. So before sending it I would describe myself as someone they'd want to see, to drive up their curiosity, basically I'll be what they'd want me to be. This was very successful. I never maintained a big list of zombied boxes, I'd infect remove on a per night basis depending on how bored I was.
I also saw the progression of hiding IP's in MSN connections. At first they would make a direct connection, later they only made a direct connection while transferring files bigger than a certain size. They completely removed it after some point, don't remember very well.
After I got to know more about networking how things are connected, I realized that my ISP allowed to initiate NULL sessions to other customers. I remember how excited I was to find this. I would place the RATs everywhere with curious names in hopes for them to click or just test exploits on them.
Another interesting thing I found was I was able to invite anyone, even random emails (Hotmail) while having a group chat. I had so much fun doing that back then.
After infection it was basically just chatting, messing with the LED's, CD-ROM's.. people were more interested in finding out how I did it and just chat rather than being mad. I remember one time when I did this to a friend he got scared and ripped of the cable breaking the wall socket.
It was really easy to evade anti-virus programs at the time. I usually just split the file into half, run the scanner on it, split again until I narrowed down to the signature and would just change a value or two.
It was interesting to see how many times people change the text before hitting send while chatting. Obviously I was too naive to know and respect privacy back then.