Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Remote PC Access

Thread Tools
 
Search this Thread
 
Old 25 September 2003, 10:04 AM
  #1  
king_tut
Scooby Regular
Thread Starter
 
king_tut's Avatar
 
Join Date: May 2003
Posts: 82
Likes: 0
Received 0 Likes on 0 Posts
Post

After the recent virus attacks, I am faced with having to clean up machines, most have VNC etc installed but some do not. Is there a 100% automated setup for it as i can connect remotely using other means ;-) but not take over the computer 100%.

Ideally im looking for an exe, size doesnt matter than can be run on the local computer and then install automatically including the password setup etc.
Old 25 September 2003, 10:13 AM
  #2  
rogp
Scooby Regular
 
rogp's Avatar
 
Join Date: Mar 2003
Posts: 455
Likes: 0
Received 0 Likes on 0 Posts
Post

I'm sure you can install VNC with an answer file to create the settings you need to connect in.

Roger
Old 25 September 2003, 10:20 AM
  #3  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

M$ have a tool for this.

Please note that if you are talking about the DCOM RPC exploit that the blaster and variants targeted, the original exploit was discovered weeks before this.

Many of the released code / progs dropped a shell (provisionally on port 4444, but later code included variable to select).

If you were subject to this, chances are your boxen have been rooted and you have much more to worry about than removing a worm.

If a full rebuild is not an option, make sure you monitor ALL out going packets for suspicious behavior

From the content of your post, it seems you are an admin of some sort. Might be worth setting up snort (if not aleady there) and stick in some new, strict rules.
Old 25 September 2003, 11:17 AM
  #4  
king_tut
Scooby Regular
Thread Starter
 
king_tut's Avatar
 
Join Date: May 2003
Posts: 82
Likes: 0
Received 0 Likes on 0 Posts
Post

Muhahahahaha ph34r |\/|y sk!lz

Got it working, cheers for the help guys but i had to go a bit hardcore on this one, I now officially should never have to leave my desk again

::kriss
Old 25 September 2003, 11:25 AM
  #5  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Post

Kriss,

You are going over a secure tunnel to get into your PC aren't you? Leaving VNC open accessible to all is a little bit risky...
Old 25 September 2003, 12:06 PM
  #6  
rogp
Scooby Regular
 
rogp's Avatar
 
Join Date: Mar 2003
Posts: 455
Likes: 0
Received 0 Likes on 0 Posts
Post

Gedi,

YHM at your NTL account.

Roger
Old 25 September 2003, 12:21 PM
  #7  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

Security doesn't seem top of the list

/me is raoming about king_tut's network as we speak....
...ohhh, these are some interesting files....
....we have a nice big outbound trunk.

wget gedi_bot
./configure_gedi_bot
make
make install

muawahaha
ph33r m3
Old 25 September 2003, 12:55 PM
  #8  
king_tut
Scooby Regular
Thread Starter
 
king_tut's Avatar
 
Join Date: May 2003
Posts: 82
Likes: 0
Received 0 Likes on 0 Posts
Post

I dont think u are browsing about my network Gedi, due to the fact that, I am a local admin :-) on the aberdeen plant, and to get access to us, you would have to come in through the firewall in houston.

Security is a concern, one of the main actually, hence why I am doing this remotley then testing everything an securing it all up.
Old 25 September 2003, 01:28 PM
  #9  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

was just a little joke. Appologies if this was taken the wrong way.

On another note, I have been in situations before where admins have gotten very nasty after I have pointed out vunerabilities in their networks. Luckily I was under 18 at the time of my heavy misbehaving.

Now I work for the other side of security, with the odd bit of misbehaving every now and again.....hehe. A very slightly dirty white hat.
Old 25 September 2003, 01:38 PM
  #10  
king_tut
Scooby Regular
Thread Starter
 
king_tut's Avatar
 
Join Date: May 2003
Posts: 82
Likes: 0
Received 0 Likes on 0 Posts
Post

Its cool, I look after about 200ish windows boxes so walking round them all is a pain, specially if its something stupid. I am really interested in Network Security things like penetration testing etc.

I take it from ure "make" script u use linux or unix.
Old 25 September 2003, 01:47 PM
  #11  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

I use pretty much all OS'
Linux, Windows, Solaris, HP-UX, BSD are the main ones.

If you are interested in security, you should consider getting some certs. I don't know how you are with networks, but a CCNA would be a good start as many security issues are down to poorly configured networks.

Then certs like CISSP, CISA and the new Security+ will push you forward into the world of security. CISSP is the best, but most difficult to obtain. Security+ is supposed to be the easiest (not done it yet, so can't comment) and the '+' certs are up and comming in the info world.

I now have a lab set up at home with around 9 machines to test, discover new exploits, try out new ideas and develop code. It keeps me out of prison as its all legal now....haha.
Old 25 September 2003, 02:22 PM
  #12  
rogp
Scooby Regular
 
rogp's Avatar
 
Join Date: Mar 2003
Posts: 455
Likes: 0
Received 0 Likes on 0 Posts
Question

Certification is definitely the way to go.

For the CISSP don't you need to be 'recommended' by someone who already has the cert?

Roger

Old 25 September 2003, 02:36 PM
  #13  
Gedi
Scooby Regular
 
Gedi's Avatar
 
Join Date: Jan 2003
Posts: 932
Likes: 0
Received 0 Likes on 0 Posts
Post

you are meant to be, but they don't always demand it. You also need to have been working in security for x (2 I think) amount of years. But there are exceptions to this too.
Old 25 September 2003, 02:45 PM
  #14  
rogp
Scooby Regular
 
rogp's Avatar
 
Join Date: Mar 2003
Posts: 455
Likes: 0
Received 0 Likes on 0 Posts
Post

Seems to be a well respected cert though, so well worth getting hold of.
Old 25 September 2003, 05:55 PM
  #15  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Arrow

They have upped the requirements for entry into CISSP now (longer time working in security etc). Details at isc2 I should be doing this very soon

Chris
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
JimBowen
ICE
5
02 July 2023 01:54 PM
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
TylerD529
General Technical
2
09 October 2015 01:53 AM



Quick Reply: Remote PC Access



All times are GMT +1. The time now is 05:09 AM.