your right to security
Showing 101 - 125 of 335 RSS Feed

Files

ssheater-1.1.tar.gz
Posted Apr 6, 2006
Authored by Carlos Barros | Site gotfault.net

SSHeater is a program that infects the OpenSSH daemon in run-time in order to log all future sessions and implement a backdoor where a single password, chosen by the user, can log into all accounts in the system. There's a log parser included in the package that can display authentication information about sessions as well as play the session just like TTYrec/play.

tags | tool, rootkit
systems | unix
MD5 | 584353ff41ac6ad6a59f87eaa8b05340
r57-pid-check.txt
Posted Apr 6, 2006
Authored by x97Rang | Site rst.void.ru

pid-check is a perl script that uses the kill() and setpriority() system calls to find hidden processes.

tags | tool, perl, rootkit
systems | unix
MD5 | 62427ef3574ea99ba8cad2d1ce2f38c9
Guru-Antilog.sh
Posted Apr 4, 2006
Authored by SoFy

A bash script to wipe or exchange your IP in unix log files. Also wipes out /root/.bash_history.

tags | tool, root, rootkit, bash
systems | unix
MD5 | f2407e8a4ccbde89d7ec768992803526
SpoofMe_backdoor.tar.bz2
Posted Apr 4, 2006
Authored by LOTFREE TEAM | Site lotfree.next-touch.com

SpoofMe Backdoor - The backdoor is composed of 3 parts. The client, the server, and a php script. The client is used to send spoofed udp packets to the victim. Theses packets contains the commands encrypted with the base64 algorithm. The server listens on a UDP port. When it receives a command, it decrypts it, executes it and encodes the output in base64. The result is sent in a HTTP (POST) packet to the php script called shell_output.php.

tags | tool, web, udp, spoof, php, rootkit
systems | unix
MD5 | 771abfe12e9767314a332871bef6102d
anti-antirootkit.pl.txt
Posted Mar 13, 2006
Authored by saic | Site saic.sapht.com

A perl script to backdoor chkrootkit rendering it useless. Tested on chkrootkit version 0.44 running on Red Hat enterprise 3.

tags | tool, perl, rootkit
systems | linux, redhat, unix
MD5 | cb59ccee74aca48a68c149f2ec848d4d
nabi2.c
Posted Mar 9, 2006
Authored by x90c

Nabi version 2.0 - Advanced /var log wiper for Linux.

Changes: One bug fixed, Added program arguments parser.
tags | tool, rootkit
systems | linux, unix
MD5 | 3785e854541c919e0b4838dfb49496ee
enyelkm.en.v1.1.tar.gz
Posted Feb 20, 2006
Authored by RaiSe | Site enye-sec.org

LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry handlers, so it does not modify sys_call_table, or IDT content. It hide files, directories, and processes. Hides chunks inside of files, gives remote reverse_shell access, local root, etc.

Changes: Version 1.1
tags | tool, remote, x86, kernel, local, root, rootkit
systems | linux, unix
MD5 | 89340215b6cfceb3a176c4a30e34f5c6
pshell.pl.txt
Posted Feb 16, 2006
Authored by grimR | Site crypt.cc

perl shell: a simple perl backdoor script that listens for a plantext password and can run a shell. .

tags | tool, shell, perl, rootkit
systems | unix
MD5 | 07262d9d9943338dfc0bcb4db4e45e90
override.tar.bz
Posted Jan 27, 2006
Authored by Amir Alsbih | Site informatik.uni-freiburg.de

The override Rootkit: A LKM Linux 2.6 rootkit that uses patched systemcalls. Features - Hides pids and automatically hides the pids of child processes - Hides network ports - Hides files which begin with a user-defined prefix - Can show the hidden pids.

tags | tool, rootkit
systems | linux, unix
MD5 | 31a9eb52f4907924ba9fb22287b44996
bluediving-0.3.tgz
Posted Jan 21, 2006
Authored by Bastian Ballmann | Site sourceforge.net

Bluediving is a Bluetooth penetration testing suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++, BlueSmack, and has features such as Bluetooth address spoofing.

Changes: FreeBSD port and minor bug fixes.
tags | tool, spoof, rootkit
systems | unix
MD5 | 5d81db69b3cec316fd758ca5573fd58b
nabi.c
Posted Jan 15, 2006
Authored by x90c

Nabi version 1.0 - Advanced /var log wiper for Linux.

tags | tool, rootkit
systems | linux, unix
MD5 | 884583c27ac9e10d07d6cb6a577a6240
bluediving-0.2.tgz
Posted Dec 31, 2005
Authored by Bastian Ballmann | Site sourceforge.net

Bluediving is a Bluetooth penetration testing suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++, BlueSmack, and has features such as Bluetooth address spoofing.

tags | tool, spoof, rootkit
systems | unix
MD5 | 7d94ecb535c7af9b4b65e7a222240077
bluediving.tgz
Posted Dec 29, 2005
Authored by Bastian Ballmann | Site sourceforge.net

Bluediving is a Bluetooth penetration testing suite. It implements attacks like Bluebug, BlueSnarf, BlueSnarf++, BlueSmack, and has features such as Bluetooth address spoofing.

tags | tool, spoof, rootkit
systems | unix
MD5 | 7a7211935db1965f3ca5c7822a1497d5
phalanx-b6.tar.bz2
Posted Dec 27, 2005
Authored by rebel

Phalanx is a self-injecting kernel rootkit designed for the Linux 2.6 branch that does not use the now-disabled /dev/kmem device. Features include file hiding, process hiding, socket hiding, a tty sniffer, a tty connectback-backdoor, and auto injection on boot.

tags | tool, kernel, rootkit
systems | linux, unix
MD5 | 3d0ef3793579cd846e43a034d147ecd0
enyelkm.en.v1.0.tar.gz
Posted Nov 30, 2005
Authored by RaiSe | Site enye-sec.org

LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry handlers, so it does not modify sys_call_table, or IDT content. It hide files, directories, and processes. Hides chunks inside of files, gives remote reverse_shell access, local root, etc.

tags | tool, remote, x86, kernel, local, root, rootkit
systems | linux, unix
MD5 | 5896fe3e8a333c4e1e52daedc3422363
rsh-v2.c
Posted Oct 31, 2005
Authored by rotor | Site c1zc0.com

Unix log cleaner that also checks to see if root is logged in.

tags | tool, root, rootkit
systems | unix
MD5 | e2e7e8f9bb27e7b5dd66041ebd4d3766
suckit2priv.tar.gz
Posted Oct 13, 2005
Authored by sd | Site sd.g-art.nl

SucKIT Rootkit v2.0-devel-rc2. Easy-to-use, Linux-i386 kernel-based rootkit. The code stays in memory through /dev/kmem trick, without help of LKM support nor System.map or such things. Everything is done on the fly. It can hide PIDs, files, tcp/udp/raw sockets and sniff TTYs.

tags | tool, kernel, udp, tcp, rootkit
systems | linux, unix
MD5 | 3bb82c1fddcc47456efee6f3687e4f51
SInAR-0.3.tar.bz2
Posted Oct 6, 2005
Authored by Archim

SInAR Solaris rootkit version 0.3. Invisible kernel based rootkit for Solaris 8, 9, and 10. Special TAX release.

tags | tool, kernel, rootkit
systems | unix, solaris
MD5 | 544f71c02bf24ee9c0dc4e4c696abf3b
httpbd.pl.txt
Posted Sep 23, 2005
Authored by rav3n

httpbd.pl is a small backdoor written in perl that poses as httpd. It can spawn a shell and transfer files.

tags | tool, shell, perl, rootkit
systems | unix
MD5 | e96c0debb82cfb8f22165e943001f0ba
doorman-0.81.tgz
Posted Sep 7, 2005
Authored by Bruce Ward | Site doorman.sourceforge.net

The Doorman is a port-knocking listener daemon which helps users secure private servers. It allows a Unix server to run invisibly, with all TCP ports closed.

Changes: Fixed the silent doorman problem.
tags | tool, tcp, rootkit
systems | unix
MD5 | f0f30132a541122fa46f4d6d321260d9
twlib.tar.gz
Posted Jul 21, 2005
Authored by tracewar

Simple replacement binaries for netstat, ls, and ps that enable an attacker or administrator to hide specific strings.

tags | tool, rootkit
systems | unix
MD5 | 9bf250eeebe0f27e6d5c7cfaf84ccb21
szapper.c
Posted Mar 22, 2005
Authored by topolb

StealthZapper is a less-detectable log wiper. It attempts to leave wtmp and utmp "cleaner" looking by not simply leaving a blank hole where the offending data was deleted from.

tags | tool, rootkit
systems | unix
MD5 | 68b0a251468d22b367074c1059d7b280
silentdoor.tar.gz
Posted Mar 17, 2005
Authored by doctor raid

SilentDoor is a connectionless, PCAP-based backdoor for linux that uses packet sniffing to bypass netfilter. It sniffs for UDP packets on port 53, runs each packet against a decryption scheme, if the packet validates than it runs a command. Can be masked to look like any other process. Remote command utility included.

tags | tool, remote, udp, rootkit
systems | linux, unix
MD5 | 5a8f02eb1e1d7ca1ff8e7a30603286a3
backd00r.c
Posted Mar 15, 2005
Authored by darkXside

Unix bindshell backdoor that acts as psybnc if the password fails.

tags | tool, rootkit
systems | unix
MD5 | fd338c62f08e87b4b033bc88a47f9b9c
SInAR-0.2.tar.bz2
Posted Feb 18, 2005
Authored by Archim

SInAR Solaris rootkit v0.2. Invisible kernel based rootkit for Solaris 8, 9, and 10.

tags | tool, kernel, rootkit
systems | unix, solaris
MD5 | 6e5dc76977f8b3fed2fd9f21ffc375dd
Page 5 of 14
Back34567Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
New SpyEye Plugin Takes Control Of Webcam And Microphone
Posted May 24, 2012

tags | headline, privacy, malware, trojan, botnet
Attack Of The Clones: Researcher Pwns SecureID Token System
Posted May 24, 2012

tags | headline, hacker, flaw, science, rsa
Yahoo! Leaks! Private! Key! In! Axis! Chrome! Debut!
Posted May 24, 2012

tags | headline, flaw, yahoo, cryptography
Comcast Phishing Site Contains Valid TRUSTe Seal
Posted May 24, 2012

tags | headline, cybercrime, flaw, scam, phish
Armenia Jails Bredolab Botmaster For 4 Years
Posted May 24, 2012

tags | headline, government, cybercrime, botnet, fraud
Police Given 350 Mobile Fingerprint Scanners For Olympics
Posted May 24, 2012

tags | headline, government, privacy, britain
Researcher Needles Oracle Over Java Security
Posted May 24, 2012

tags | headline, flaw, oracle, java
35,000 Passwords Reset After BigPond GameArena Hacked
Posted May 24, 2012

tags | headline, hacker, data loss, password
Indian SMBs Facing Advanced Attack Threats
Posted May 23, 2012

tags | headline, hacker, india, denial of service, symantec
Jailed Facebook Hack Brit Targeted Justin Bieber's Girlfriend
Posted May 23, 2012

tags | headline, hacker, britain, facebook, social
View More News →
packet storm

© 2012 Packet Storm. All rights reserved.

close