plan for the worst
Showing 1 - 1 of 1 RSS Feed

Files

Rial.c
Posted Dec 3, 2000
Authored by Technok | Site pkcrew.org

RIAL is a lkm based rootkit which can hide processes, files, directories, LKMs, connections and file parts. While some of these are present in a large number of lkms, connections and file-parts hiding are new ideas, or at least i couldn't find any lkm which had them. All the processes, files, directories and lkms containing in their name the string defined in HIDE are hidden. Reading from /proc/net/tcp is intercepted and read data is filtered to hide some connections.

tags | tool, tcp, rootkit
systems | unix
MD5 | 3bb687667a69ddc3cd274eb1ffac0719
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close