The target
will be immediately shut down.
*Note: Remember that this tool can be installed remotely and, from the list of options
available to an attacker, you can plainly see just how much control an attacker
would have over the target.
534 Practical Hacking Techniques and Countermeasures
Lab 78: Trojan
Unauthorized Access and Control: NetBus
Prerequisites: None
Countermeasures: Secure ACLs, Bastion servers/workstations, Trojandetection
software, updated antivirus
Description: The NetBus Trojan, similar to the famous Back Orifice (BO)
Trojan, is designed to hide itself inside a target host. It allows the installing
user access to the system at a later time without using normal authorization
or vulnerability exploitation. NetBus allows the remote user to do
most of the functions BO can do, as well as open or close the CD-ROM
drive, send interactive dialogs to chat with the compromised system,
listen to the system??™s microphone (if it has one), and a few other features.
Procedure: Install the server and client parts, and execute against the
target.
On the Target (Server)
Verify the target IP address by typing ipconfig.
Wireless 535
Double-click on the nbpro210.exe icon to start the installation.
The NetBus Pro Welcome screen is displayed. Click Next.
536 Practical Hacking Techniques and Countermeasures
Read the Information screen. Click Next.
Accept the default installation directory. Click Next.
Wireless 537
From the Select Components screen select the NetBus Pro Server and
Additional Components.
Pages:
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188