// you’re reading...

Security

d3v1l-sh3ll RFI cmd

imagem-21For many months this was a really private cmd, but it’s already public and being used in many botnets.

It’s a pretty complete tool with a very detailed programming, you can check it by the use of comments on every step. I don’t know if there is a recent version of it but this is the one I caught.

When I was posting this, Amir told me that I also got this one on their servers but it was backdoored with iframes. I’m still checking out the code for more diff.

Discussion

One comment for “d3v1l-sh3ll RFI cmd”

  1. lol @ backdoored

    shell=backdoor

    /regards

    Posted by d3v1l | May 19, 2009, 10:23 pm

Post a comment