Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.3
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jul 29th, 2010, 4:02pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Noob Series Trojans?
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Noob Series Trojans?  (Read 1328 times)
Jamming
Stole All the Forum Stars
********



Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2040
Noob Series Trojans?
« on: Feb 25th, 2002, 1:47pm »
Quote Quote  Modify Modify

Are the Noob Series Trojans protected on the list?  
Noob3.0
Noob3.1
Noob4.0
I did a search for the Trojan Noob4 and came up with the previous rules as well.  I don't see any specific rules that cover them, but does some other rule cover them?
 
The Author's Moniker is "SHADOW"
IP Logged

Team Z Charter Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca

I was born an American; I live an American; I shall die an American!
- Daniel Webster

There are many things that are worse than war. They all begin with defeat.
- Aeschylus

People who bite the hand that feeds them usually lick the boot that kicks them.
- Eric Hoffer
Magnus
Administrator
*****



Ad astra per aspera.

   
WWW  

Posts: 4346
Re: Noob Series Trojans?
« Reply #1 on: Feb 25th, 2002, 5:38pm »
Quote Quote  Modify Modify

The Noob trojan is malicious HTML code that writes some specially crafted script code to the scripting files of an IRC client called mIRC (IRC is a large text-based chat system with its own servers). This is actually a very general problem with the mIRC client because the author has built powerful scripting capabilities into it. If someone puts some specially crafted code into its scripting files then he can do some pretty nasty things to that user's machine.
 
The Noob issue can only affect a user if he visits an "infected" HTML page and clicks Yes in the security warning dialog box that pops up which alerts the user that a potentially harmful ActiveX object in the page wishes to execute. Furthermore, the installed malicious scripting commands cannot be exploited by any means unless the user then starts up mIRC and connects to an IRC server.
 
It would be very possible to add detection in TrojanHunter for the script files, but the problem with mIRC script files is a much larger one because malicious script files can be created in many different ways. I have had thoughts about creating a generic mIRC script file analyzer to protect mIRC users from such scripts but that will not make it into TrojanHunter until version 3.0 at the earliest. Unfortunately I can't elaborate on that technology here, for what I hope are obvious reasons.
 
In short, the Noob trojan is not a remote access trojan per se but rather a piece of mIRC scripting code. The trojan does not create any Windows executable files nor does it run as a process. The malicious scripting code can only be exploited if the user has the mIRC IRC client installed and it is not possible to exploit it unless a user is connected to an IRC server.
IP Logged

Follow me on Twitter: http://twitter.com/mmischel
Jamming
Stole All the Forum Stars
********



Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2040
Re: Noob Series Trojans?
« Reply #2 on: Mar 12th, 2002, 6:38am »
Quote Quote  Modify Modify

HTTPPOST.EXE  is this the same type of exploit or nearly the same?  Or is this one you do protect against?
IP Logged

Team Z Charter Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca

I was born an American; I live an American; I shall die an American!
- Daniel Webster

There are many things that are worse than war. They all begin with defeat.
- Aeschylus

People who bite the hand that feeds them usually lick the boot that kicks them.
- Eric Hoffer
Magnus
Administrator
*****



Ad astra per aspera.

   
WWW  

Posts: 4346
Re: Noob Series Trojans?
« Reply #3 on: Mar 13th, 2002, 11:13am »
Quote Quote  Modify Modify

I'd really need a copy of the file to be able to tell you if it's a trojan. If it is, and is not already covered, it will most definitely go into the next update. Do you have any references to where this file was found?
IP Logged

Follow me on Twitter: http://twitter.com/mmischel
Jamming
Stole All the Forum Stars
********



Remember when a Trojan was just for protection.

   


Gender: male
Posts: 2040
Re: Noob Series Trojans?
« Reply #4 on: Mar 15th, 2002, 6:38am »
Quote Quote  Modify Modify

Try a Search in the past two weeks for HTTPPOST.EXE , I don't remember the exact location in the Security Forum of DSLreports.
 
 Embarassed
IP Logged

Team Z Charter Member

Servare cives, major est virtus patriae patri.
- Lucius Annaeus Seneca

I was born an American; I live an American; I shall die an American!
- Daniel Webster

There are many things that are worse than war. They all begin with defeat.
- Aeschylus

People who bite the hand that feeds them usually lick the boot that kicks them.
- Eric Hoffer
Magnus
Administrator
*****



Ad astra per aspera.

   
WWW  

Posts: 4346
Re: Noob Series Trojans?
« Reply #5 on: Mar 21st, 2002, 6:41pm »
Quote Quote  Modify Modify

I was unable to find any reference to an actual file that could be found online. The only httppost.exe I've located so far resided on a Japanese server, and it wasn't a trojan. At any rate, if you should find the file that was discussed, I'd be happy to have a look at it.
IP Logged

Follow me on Twitter: http://twitter.com/mmischel
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register