Aphex's Remote Packet Sniffer 0.3.2
(Trojan.Spy.RemoteSniffer.030 for EditServer)
(Backdoor.Asniffer.032 for server)

by Aphex

Written in Delphi

Released in june 2002

more versions


ASniffer 0.3.2
-
You must install winpcap on the target computer first!
-
0.3.2 - fixed the bug that prevented packets with null characters (ie AIM) from being
        displayed correctly (I really wish I wasn't the only one finding bugs)
0.3.1 - you can sniff all traffic easily by using 'sniffer all on'
        you can turn on and off the ascii and hexadecimal views
0.3.0 - another rebuild, server uses TCP and is now command line based
        fixed the bug that caused repeated server crashes
0.2.0 - complete rebuild, easier interface and comes with a server editor
0.1.2 - adapters are now always listed in the correct order
0.1.1 - first release
-
sniffer all [on|off] - sniffs all traffic
sniffer hex [on|off] - turn on and off the hexadecimal view
sniffer asc [on|off] - turns on and off the ascii view
sniffer adapters list - lists all available adpaters for sniffing
sniffer ips add [ip] - adds a ip to the watch list
sniffer ips del [#] - deletes an ip from the watch list
sniffer ips clear - clears the ip watch list
sniffer ips list - lists all ips being watched
sniffer ports add [port] - adds a port to the watch list
sniffer ports del [#] - deletes a port from the watch list
sniffer ports clear - clears the port watch list
sniffer ports list - lists all ports being watched
sniffer strings add [string] - adds a string to the watch list
sniffer strings del [#] - deletes a string from the watch list
sniffer strings clear - clears the string watch list
sniffer strings list - lists all strings being watched
sniffer start [#] - starts the sniffer on the specified numbered adapter
sniffer stop - stops the sniffer
sniffer restart - restarts the server
sniffer remove - removes the server
sniffer port [port] - changes the current server port
sniffer help - displays the online help
-
Shouts to nip, Apple-Jacks, Stan, karia, freedumb, PACh, flair, ^Syke^, DeD, Loxy, qroject
M_R, ryan, everyone else you know who you are.

Aphex


Server:
C:\WINDOWS\SYSTEM\Packet16.exe 

size: 492.032 bytes

port: 9090 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run 

MegaSecurity