ISC StormCast for Thursday, April 4th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 4 April 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, April 4, 2020, edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.6 | Today I played a little bit with Anthony Weems backdoor implementation, X-C-Bot. |
| 0:19.3 | It implements the X-Eutilsdoor, and then XEBot is also a tool |
| 0:27.2 | that essentially simulates a tool that an attacker would use in order to connect to a backdoor |
| 0:32.0 | system. Now, one of the tricky parts here, of course, is that we don't have the key material that |
| 0:39.4 | the attacker would have used to connect to the original backdoor. |
| 0:43.0 | So the genius here of Anthony's implementation is that, well, you can just bring your own key, |
| 0:48.9 | and with that, just experiment how the backdoor would work. I took a quick step at it, and I didn't actually implement the backdoor would work. |
| 0:55.0 | I took a quick step at it and I didn't actually implement the backdoor part. |
| 0:59.0 | I really just wanted to see what happens if I use this client to connect to an SSH server |
| 1:06.0 | that's running perfectly fine that does not have the backdoor installed. |
| 1:10.0 | In my experiments, there was one specific error message that showed up an error in LipCrypto. |
| 1:18.0 | I did use standard Ubuntu 22 install. |
| 1:23.5 | May not have used the client quite correctly. |
| 1:26.8 | If anybody has any insight, any other experience with this client, |
| 1:31.8 | let me know, or if you saw any other error messages, |
| 1:35.3 | that would also be kind of helpful. |
| 1:37.8 | I also used to connect a username that was actually not allowed to connect a route in this case, |
| 1:43.4 | which is the default |
| 1:44.8 | user in Anthony's implementation. As far as the network traffic goes, I didn't really see anything |
| 1:51.4 | great here to pick up on or to use as a signature other than the fact that you have relatively |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

