Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Backdoor.Redkod

From: Fab Siciliano <fsiciliano(at)optiumcorp.com>
Date: Thu Feb 27 2003 - 15:07:27 EST


Hey Roger...

Like I was saying to HC:

WFP can be disabled...it's not a good practice, b/c im "sure" that it will break things...

I quote myself:

"> > Editing
> > HKEY_Local_Machine\Software\Microsoft\Windows

All the trojan needs is access to that key, reboot, access the box, overwrite netstat.exe. Either way....once the trojan is there..."overwriting netstat.exe" should be the least of worries.

Thanks,

Fab

Do you need help?X

> -----Original Message-----
> From: Grimes, Roger [mailto:RogerG@GoldKeyresorts.com]
> Sent: Thursday, February 27, 2003 2:45 PM
> To: 'Fab Siciliano'; 'H C'; focus-virus@securityfocus.com
> Subject: RE: Backdoor.Redkod
Received on Thu Feb 27 15:29:46 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:38 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library