AlphaOne Technology Support Forums
Welcome, Guest. Please login or register.
December 02, 2008, 12:54:24 PM

Login with username, password and session length
Search:     Advanced search
1733 Posts in 827 Topics by 4756 Members
Latest Member: Uobeley
* Home Help Search Login Register
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.DFind Hack Tool 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] Go Down Print
Author Topic: Hacktool.DFind Hack Tool  (Read 1151 times)
Brad
SysAdmin
Tech Team
Hero Member
********
Offline Offline

Posts: 391



View Profile
Hacktool.DFind Hack Tool
« on: June 06, 2005, 12:37:50 AM »

Behavior
Hacktool.DFind is a utility used to scan for vulnerabilities on remote computers.

Symptoms
Your Symantec program detects Hacktool.DFind.

Transmission
This utility can be installed manually or by a back door.

technical details
File names: Varies

Hacktool.DFind allows an attacker to probe a range of IP addresses to determine whether a host whose address is in that range is vulnerable to specific exploits or is running certain legitimate services.

When Hacktool.DFind is run, it performs the following actions:

   1. Scans for the following vulnerabilities and services:

          o Open TCP and UDP ports.
          o HP Web JetAdmin
          o PSOProxy Server
          o HP Web Server
          o Microsoft Frontpage
          o Hacktool.Radmin
          o RealServer
          o Apache Servers
          o IIS servers
          o Windows Media Service
          o IPC$ shares without password protection.
          o Weak write permissions in Microsoft IIS web server.
          o Backdoor.OptixPro.10 and variants.
          o Dictionary attacks on SQL Servers
          o NULL/NTAuth/Passworded connections on Hacktool.Radmin
          o The CCBill webserver module
          o The PHPbb webserver module
          o The PHP-Nuke webserver module.
          o WebDav enabled on IIS5.0 webservers
          o The Microsoft Windows IIS Index Server ISAPI System-level Remote Access Buffer Overflow
            (Microsoft MS01-033)
          o The Microsoft SQL Server MDAC buffer overflow (Microsoft MS02-040).

REMOVAL INSTRUCTIONS
See: http://securityresponse.symantec.com/avcenter/venc/data/hacktool.dfind.html
Logged

Pages: [1] Go Up Print 
AlphaOne Technology Support Forums  |  IMPORTANT ANNOUNCEMENTS  |  Security Announcements  |  Windows-based Security Issues  |  Topic: Hacktool.DFind Hack Tool « previous next »
Jump to:  

Powered by MySQL Powered by PHP AlphaOne Technology Support Forums | Powered by SMF 1.0.7.
© 2001-2005, Lewis Media. All Rights Reserved.
Valid XHTML 1.0! Valid CSS!