Rooting an app in Windows XP

Locked
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Rooting an app in Windows XP

Post by Foo »

This question might be a tad beyond this forum for reasons that'll be obvious to anyone who can answer it for me:

Can anyone outline a process to get an exe file running under root on a windows XP machine? I specifically need to run a program that will be invisible to a process running under a regular administrator account, and this is the only method I know to accomplish this.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

In other words, I would like to learn how to deliberately rootkit my own PC with an application of my choosing.
"Maybe you have some bird ideas. Maybe that’s the best you can do."
― Terry A. Davis
^misantropia^
Posts: 4022
Joined: Sat Mar 12, 2005 6:24 pm

Post by ^misantropia^ »

You might want to take a look at http://www.rootkit.com/
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

^misantropia^ wrote:You might want to take a look at http://www.rootkit.com/
Thanks, been digging around there for a while. Looks like I'll need to roll my own from some of the supplied.
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

if it's corporate espionage you're looking to detect, what you really need is an inline usb keylogger.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

Not at all. I rolled my own solution, and it worked pretty well.

I wanted to do some packet inspection on warrock, but since punkbuster is part of it you have to go a bit further to do it. I guess from the position I'm in now I could probably also inject packets, but I'm not so interested in that.
"Maybe you have some bird ideas. Maybe that’s the best you can do."
― Terry A. Davis
User avatar
raw
Posts: 2741
Joined: Tue Nov 16, 1999 8:00 am

Post by raw »

I would have created a system service using srvany.exe (Windows Resource Kit) and ran it under the System account.
^misantropia^
Posts: 4022
Joined: Sat Mar 12, 2005 6:24 pm

Post by ^misantropia^ »

Correct me if I'm wrong, but that wouldn't be invisible to an administrator account, would it?
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

^misantropia^ wrote:Correct me if I'm wrong, but that wouldn't be invisible to an administrator account, would it?
No, but if you use a common name then it will most likely be overlooked.
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Post by AmIdYfReAk »

zomg32 process :)
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

Foo wrote:Not at all. I rolled my own solution, and it worked pretty well.

I wanted to do some packet inspection on warrock, but since punkbuster is part of it you have to go a bit further to do it. I guess from the position I'm in now I could probably also inject packets, but I'm not so interested in that.
I smell horse shit. Why would you not want it visible to administrator on your own PC? Simple packet inspection can be done with ethereal or just about anything, for that matter. Yeah it's pretty obvious, you fucking hacking piece of dung beetle offal.
Last edited by Underpants? on Mon Aug 14, 2006 6:29 pm, edited 1 time in total.
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

I'm emailing your work. I know right where it is, I saw a picture of it once.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

Underpants? wrote:
Foo wrote:Not at all. I rolled my own solution, and it worked pretty well.

I wanted to do some packet inspection on warrock, but since punkbuster is part of it you have to go a bit further to do it. I guess from the position I'm in now I could probably also inject packets, but I'm not so interested in that.
I smell horse shit. Why would you not want it visible to administrator on your own PC? Simple packet inspection can be done with ethereal or just about anything, for that matter. Yeah it's pretty obvious, you fucking hacking piece of dung beetle offal.
Once more for the slow ones:
Foo wrote:I wanted to do some packet inspection on warrock, but since punkbuster is part of it you have to go a bit further to do it.
User avatar
Foo
Posts: 13840
Joined: Thu Aug 03, 2000 7:00 am
Location: New Zealand

Post by Foo »

Underpants? wrote:I'm emailing your work. I know right where it is, I saw a picture of it once.
NOES!!!! :drool:
Locked