@BEGIN_FILE_ID.DIZ*      Miami / AmiTCP/IP Trojan       *
*                                     *
*  This statement originally written  *
*    by Miami author Holger Kruse     *
@END_FILE_ID.DIZ
   
   
   
   
                   
                                  ·_   _·            ::: :  ::
                               _ __\   /__ _         ::: :  ::
                            _ _)\\  \ /  //(_ _      ::: :  ::
                       --  -\   __\° X °/__   /-  -- ::: :  ::
                    _ __ ___ ___)  \/_\/  (___ ___ __:_: :  ::
            (·(--  -\\\_\\__\\__  _ /¦\ _  __//__//_///- --)·)
                       _.      \__)_¯_¯_(__/      ._ ::: :  ::    
           __          \|_       | | | | |       _|/ ::: :  ::__
         __\ ___ _/\____\/__ __ _| | | | |_ __ __\/____/\_ ___ /__
      (_/   \  (_)  \_  \/  /_/\\| |_|_| |//\_\  \/  _/: (_)::/   \_)
       |                    \_\/ | | | | | \/_/      ::: :  ::     |
      _|___                   __ | | | | | __        ::: :  ::  ___|_
   ]-»\|__//->              \ \/_| | | | |_\/ /      ::: :  :<-\\__|/«-[
       |                     · _)  ¯_¯_¯  (_ ·       ::: :  ::     |
       |  ·H2o!·              \\___ \ / ___//        ::: :  ::     |
       ¯\_______________________ _)  Y  (_ _______________________/¯
             __                  \___ ___/           ::: :  __
      - - <->\   fR¦ENDS 0NlY! ><-  (_)  ->< fR¦ENDS 0NlY!   /<-< - -
                                                     ::: :  ::
                                                     ::: :  ::
                                                     ::: :  ::
     
    
    

------------------------
Miami / AmiTCP/IP Trojan


This statement originally written by Miami author Holger Kruse;
It has come to my attention that an Internet-based Trojan has recently 
been distributed via pirate IRC channels and pirate ftp/bbs systems. 
This program claims to be an (illegal) keyfile generator of some kind, 
but is really quite dangerous:

It installs a backdoor on your Amiga, and allows anyone on the Internet 
to get shell access to your machine. It does this by first copying some 
files into l:, c: and devs:, masquerading as system software, and 
surviving reboots. It then establishes a TCP listening socket and waits 
for incoming connections when you start Miami or AmiTCP/IP, connecting 
the incoming TCP stream to a shell. 0nce someone has connected to your 
Amiga he can steal keyfiles, beta versions, personal files, commercial 
software and other things from your Amiga.
I urgently advise everyone to check your systems for this kind of Trojan. 
The easiest way to do this is by typing
MiamiNetStat -a

The output lists all TCP listening sockets on your system, indicated 
by state=LISTEN). Watch out for any non-standard port-numbers. 0ne of 
the ports that is reportedly used by the Trojan is 1599. There may be 
others though.

As a rule, you should only have listening sockets for the services 
enabled in Miami's INetD, plus listening sockets for any servers you 
start without INetD (e.g. 80/http for a web server, 21/ftp for an 
ftp server, or 23/telnet for a telnet server). If you find listening 
sockets on any non-standard ports, in particular ports in the 
range 1025-5000, then chances are your system has been infected.
If that is the case then treat this as you would any other virus or trojan:
Power down your machine.

Boot from a clean, write-protected original Workbench disk.
Format your system partition and reinstall all system files 
from the original Workbench disk.
Download and install any tools you need from Aminet. D0 N0T
execute ANY binaries on your existing partition. There is generall 
no way to tell if they are infected.
Let me take this opportunity to remind you that software distributed 
by cracker groups is N0T to be trusted (regardless of whether this is 
an obviously illegal program, such as a keyfile maker, or a supposedly 
legal program, like a telnet client).

By stealing keyfiles, beta versions and other things off users' 
harddisks cracker groups have clearly demonstrated their disregard 
for any kind of trustworthy and honorable behavior, not only towards 
software companies, as in the past, but now also towards honest users. 
It seems unlikely that the same people who go to great lengths to steal 
other users' property should suddenly turn around and distribute legal 
software that is safe to use.
In particular: if you value the software brought to you by honest and 
legal software companies, then you should also boycott any software 
released by known cracker groups, e.g. anything distributed 
under the label "DC" (Digital Corruption), including "DCTelnet". 
Who knows what kind of side effects, time bombs, etc. such 
software contains...
If piracy cannot be completely stopped at the "supply" side then maybe 
 we can at least slow it down on the "demand" side. Every user should 
know that running *any* kind of software distributed by cracker 
groups may be very harmful to the Amiga market, to you personally 
and to your Amiga, now more than ever.

    
    
    
    
    
      .---------------------!SPEED  OPTIMIZED!---.
      | .---.
      `-----'          -> f R ¦ E N D S  O N L Y <-
                          ¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯                    
                            ONE OF THE FASTEST                .-----.     
                                                              `---' |
                        `---!SPEED  OPTIMIZED!----------------------'
    
    
     
    
